Reference Hub9
Towards a More Systematic Approach to Secure Systems Design and Analysis

Towards a More Systematic Approach to Secure Systems Design and Analysis

Simon Miller, Susan Appleby, Jonathan M. Garibaldi, Uwe Aickelin
Copyright: © 2013 |Volume: 4 |Issue: 1 |Pages: 20
ISSN: 1947-3036|EISSN: 1947-3044|EISBN13: 9781466631113|DOI: 10.4018/jsse.2013010102
Cite Article Cite Article

MLA

Miller, Simon, et al. "Towards a More Systematic Approach to Secure Systems Design and Analysis." IJSSE vol.4, no.1 2013: pp.11-30. http://doi.org/10.4018/jsse.2013010102

APA

Miller, S., Appleby, S., Garibaldi, J. M., & Aickelin, U. (2013). Towards a More Systematic Approach to Secure Systems Design and Analysis. International Journal of Secure Software Engineering (IJSSE), 4(1), 11-30. http://doi.org/10.4018/jsse.2013010102

Chicago

Miller, Simon, et al. "Towards a More Systematic Approach to Secure Systems Design and Analysis," International Journal of Secure Software Engineering (IJSSE) 4, no.1: 11-30. http://doi.org/10.4018/jsse.2013010102

Export Reference

Mendeley
Favorite Full-Issue Download

Abstract

The task of designing secure software systems is fraught with uncertainty, as data on uncommon attacks is limited, costs are difficult to estimate, and technology and tools are continually changing. Consequently, experts may interpret the security risks posed to a system in different ways, leading to variation in assessment. This paper presents research into measuring the variability in decision making between security professionals, with the ultimate goal of improving the quality of security advice given to software system designers. A set of thirty nine cyber-security experts took part in an exercise in which they independently assessed a realistic system scenario. This study quantifies agreement in the opinions of experts, examines methods of aggregating opinions, and produces an assessment of attacks from ratings of their components. The authors show that when aggregated, a coherent consensus view of security emerges which can be used to inform decisions made during systems design.

Request Access

You do not own this content. Please login to recommend this title to your institution's librarian or purchase it from the IGI Global bookstore.