Chapter 26 System Evaluation and Assurance

Chapter 26 System Evaluation and Assurance

ID:40056439

大?。?91.25 KB

頁數(shù):32頁

時間:2019-07-18

Chapter 26 System Evaluation and Assurance_第1頁
Chapter 26 System Evaluation and Assurance_第2頁
Chapter 26 System Evaluation and Assurance_第3頁
Chapter 26 System Evaluation and Assurance_第4頁
Chapter 26 System Evaluation and Assurance_第5頁
資源描述:

《Chapter 26 System Evaluation and Assurance》由會員上傳分享,免費在線閱讀,更多相關內容在學術論文-天天文庫

1、CHAPTER26SystemEvaluationandAssuranceIfit’sprovablysecure,itprobablyisn’t.—LarsKnudsenIthinkanytimeyouexposevulnerabilitiesit’sagoodthing.—AttorneyGeneralJanetReno[1068]OpensourceisgoodforsecuritybecauseitpreventsyoufromeventryingtoviolateKerckhoffs’sLaw.—EricRaymond26.1IntroductionIvecoveredalo

2、tofmaterialinthisbook,someofitquitedif?cult.ButIveleftthehardestpartstothelast.Thesearethequestionsofassurancewhetherthesystemwillworkandevaluationhowyouconvinceotherpeopleofthis.Howdoyoumakeadecisiontoshiptheproduct,andhowdoyousellthesafetycasetoyourinsurers?Assurancefundamentallycomesdowntothe

3、questionofwhethercapablemotivatedpeoplehavebeatuponthesystemenough.Buthowdoyoude?neenough?Andhowdoyoude?nethesystem?Howdoyoudealwithpeoplewhoprotectthewrongthing,becausetheirmodeloftherequirementsisout-of-dateorplainwrong?Andhowdoyouallowforhumanfailures?Therearemanysystemswhichcanbeoperatedjust

4、?nebyalertexperiencedprofessionals,butareun?tforpurposebecausetheyretootrickyforordinaryfolktouseorareintolerantoferror.Butifassuranceishard,evaluationisevenharder.Itsabouthowyouconvinceyourboss,yourclientsand,inextremis,ajurythatthesystem857858Chapter26■SystemEvaluationandAssuranceisindeed?tfor

5、purpose;thatitdoesindeedwork(orthatitdidworkatsomeparticulartimeinthepast).Thereasonthatevaluationisbothnecessaryandhardisthat,often,oneprincipalcarriesthecostofprotectionwhileanothercarriestheriskoffailure.Thiscreatesanobvioustension,andthird-partyevaluationschemessuchastheCommonCriteriaareofte

6、nusedtomakeitmoretransparent.26.2AssuranceAworkingde?nitionofassurancecouldbeourestimateofthelikelihoodthatasystemwillfailinaparticularway.Thisestimatecanbebasedonanumberoffactors,suchastheprocessusedtodevelopthesystem;theidentityofthepersonorteamwhodevelopedit;particulartechnicalassessments,suc

7、hastheuseofformalmethodsorthedeliberateintroductionofanumberofbugstoseehowmanyofthemarecaughtbythetestingteam;andexperi-encewhichultimatelydependsonhavingamodelofhowreliabilitygrows(ordecays)overtimeasasystemissubjectedtotes

當前文檔最多預覽五頁,下載文檔查看全文

此文檔下載收益歸作者所有

當前文檔最多預覽五頁,下載文檔查看全文
溫馨提示:
1. 部分包含數(shù)學公式或PPT動畫的文件,查看預覽時可能會顯示錯亂或異常,文件下載后無此問題,請放心下載。
2. 本文檔由用戶上傳,版權歸屬用戶,天天文庫負責整理代發(fā)布。如果您對本文檔版權有爭議請及時聯(lián)系客服。
3. 下載前請仔細閱讀文檔內容,確認文檔內容符合您的需求后進行下載,若出現(xiàn)內容與標題不符可向本站投訴處理。
4. 下載文檔時可能由于網絡波動等原因無法下載或下載錯誤,付費完成后未能成功下載的用戶請聯(lián)系客服處理。