2021
DOI: 10.1007/s10664-021-09971-7
|View full text |Cite
|
Sign up to set email alerts
|

Security assurance cases—state of the art of an emerging approach

Abstract: Security Assurance Cases (SAC) are a form of structured argumentation used to reason about the security properties of a system. After the successful adoption of assurance cases for safety, SAC are getting significant traction in recent years, especially in safety-critical industries (e.g., automotive), where there is an increasing pressure to be compliant with several security standards and regulations. Accordingly, research in the field of SAC has flourished in the past decade, with different approaches being… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
4
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
2
1

Relationship

0
7

Authors

Journals

citations
Cited by 13 publications
(4 citation statements)
references
References 64 publications
0
4
0
Order By: Relevance
“…An assurance case approach is recommended, and constructing these assurance arguments is expected to help identify the requirements for the types of evidence needed to complete the assurance claims. However, recent surveys indicate that the practical implementation of cybersecurity cases remains relatively immature (Mohamad et al, 2021).…”
Section: Discussionmentioning
confidence: 99%
See 1 more Smart Citation
“…An assurance case approach is recommended, and constructing these assurance arguments is expected to help identify the requirements for the types of evidence needed to complete the assurance claims. However, recent surveys indicate that the practical implementation of cybersecurity cases remains relatively immature (Mohamad et al, 2021).…”
Section: Discussionmentioning
confidence: 99%
“…The draft standard (ISO/SAE, 2021) that is currently being developed to accompany Regulation 155 suggests the use of a cybersecurity case, which is analogous to the safety case approach already used to document automotive functional safety (MISRA, 2019), to provide assurance that the cybersecurity risks of using the vehicle are acceptable. Although the concept for a cybersecurity assurance case is not new (Armstrong et al, 2011), the results of a recent survey (Mohamad et al, 2021) over a wide range of application domains demonstrate that the practical implementation of cybersecurity cases remains relatively immature.…”
Section: Challenges For Cybersecurity and Safety Assurancementioning
confidence: 99%
“…Early in the software development process, proper assurance measures with security assurance must be implemented to prevent future problems in critical systems domains (Kabir, 2021;Khan & Khan, 2018b;Mohamad et al, 2021). Research studies conducted on security assurance are (Marshall, et al, 2019;Mohamad et al, 2021;Maksimov et al, 2019;Jahan et al, 2020;Lin et al, 2020;Calinescu et al, 2017;Bloomfield et al, 2017). However, the benefit of adding the security assurance for security requirements will raise confidence and enhance the integrity of software.…”
Section: Table 1 Sre Approaches and Their Security Criteria With Requ...mentioning
confidence: 99%
“…(Jahan, Pasco, et al, 2019). The use of security requirement assurance is increasing in the development of secure critical systems, especially in industries such as transportation systems, medical devices, financial systems, military systems, healthcare, and automotive (Mohamad et al, 2021). Therefore, one of the primary reasons for the success of the threats and attacks is lack of attention to the elicitation and analysis of security requirements (Anderson, 2020), and cannot be neglected any longer (Rehman et al, 2018).…”
Section: Introductionmentioning
confidence: 99%