Security Analysis, Assessment, and Assurance
Joseph Migga Kizza, Florence Migga Kizza
Abstract
Joseph Migga Kizza, Florence Migga Kizza
Abstract
In the previous chapter, we discussed the important role security policies play in the security of networks, in particular, and in the information communication technology (ICT) infrastructure, in general. The security policy should always be considered as the baseline security piece that dictates what other security mechanism are to be used and how. However, one must not forget that security policies are passive documents; they are lines of statements of what must be done and nothing more. A security policy will not physically stop a determined intruder, for example. To stop a determined intruder, or any other intruder for that matter, the security policy must be put into use. This chapter moves us into a new phase of the implementation of the security policies we discussed in the last chapter, starting with security assessment and analysis.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In the previous chapter, we discussed the important role security policies play in the security of networks, in particular, and in the information communication technology (ICT) infrastructure, in general. The security policy should always be considered as the baseline security piece that dictates what other security mechanism are to be used and how. However, one must not forget that security policies are passive documents; they are lines of statements of what must be done and nothing more. A security policy will not physically stop a determined intruder, for example. To stop a determined intruder, or any other intruder for that matter, the security policy must be put into use. This chapter moves us into a new phase of the implementation of the security policies we discussed in the last chapter, starting with security assessment and analysis.
Key concepts: Security policy, Computer security, Network security policy, Security through obscurity, Information security standards, Security convergence, Computer security model, Security service