错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security Assessment, Analysis, and Assurance

  • Joseph Migga Kizza

摘要

AsSecurityassessment computing technology becomes ubiquitous, the world is getting more and more interconnected. Major organization systems are interconnected to other systems through networks. The bigger the networks, the bigger the security problems involving the system resources on these networks. Many companies, businesses, and institutions whose systems work in coordination and collaboration with other systems, as they share each other’s’ resources and communicate with each other, face a constant security threatSecuritythreat from these systems, yet the collaboration must go on. The risks and potential of someone intruding into these systems for sabotage, vandalism, and resource theft are high. For security assuranceSecurityassurance of networked systems, such risks must be assessed to determine the adequacy of existing security measures and safeguards and also to determine if improvement in the existing measures is needed. Such an assessment process consists of a comprehensive and continuous analysis of the security threatSecuritythreat risk to the system that involves an auditingAuditing of the system, assessing the vulnerabilities of the system, and maintaining a creditable security policySecuritypolicy and a vigorous regime for the installation of patches and security updates. In addition, there must also be a standard process to minimize the risks associated with nonstandard security implementations across shared infrastructures and end systems. This chapter focuses on all these issues.