Information and Media Technologies
Online ISSN : 1881-0896
ISSN-L : 1881-0896
Information Systems and Applications
A Threat Model for Security Specification in Security Evaluation by ISO/IEC 19791
Guillermo Horacio Ramirez CaceresYoshimi Teshigawara
著者情報
ジャーナル フリー

2013 年 8 巻 4 号 p. 1243-1250

詳細
抄録

ISO/IEC TR 19791 is an international standard that must be used as the basis for the security evaluation of operational systems. This standard has been recently developed, and the first version was made available in May 2006. ISO/IEC TR 19791 is intended to be an extension of ISO/IEC 15408, known as “Common Criteria” (CC). In order to evaluate an IT product or system using CC or ISO/IEC TR 19791, developers must create a Security Target (ST), or a System Security Target (SST). However, a problem encountered in creating these is the determination of the Security Problem Definitions (SPDs), because the SPDs fall outside of the scope of CC. Neither ISO/IEC 15408 nor ISO/IEC TR 19791 provides a framework for risk analysis or the specification of threats. In this paper, we propose a threat model based on multiple international standards and evaluated ST information, and describe a Web application that can be used for security specifications in the production of STs and SSTs which are to be evaluated by CC and ISO/IEC TR 19791, respectively.

著者関連情報
© 2013 Information Processing Society of Japan
前の記事 次の記事
feedback
Top