The Experts below are selected from a list of 162231 Experts worldwide ranked by ideXlab platform

Shari Lawrence Pfleeger - One of the best experts on this subject based on the ideXlab platform.

M E Johnson - One of the best experts on this subject based on the ideXlab platform.

Rayford B. Vaughn - One of the best experts on this subject based on the ideXlab platform.

  • Information system security compliance to FISMA standard: a quantitative measure
    Telecommunication Systems, 2010
    Co-Authors: Elaine Hulitt, Rayford B. Vaughn
    Abstract:

    To ensure that safeguards are implemented to protect against a majority of known threats, industry leaders are requiring Information processing systems to comply with security standards. The National Institute of Standards and Technology Federal Information Risk Management Framework (RMF) and the associated suite of guidance documents describe the minimum security requirements (controls) for non-national-security federal Information systems mandated by the Federal Information Security Management Act (FISMA), enacted into law on December 17, 2002, as Title III of the E-Government Act of 2002. The subjective compliance assessment approach described in the RMF guidance, though thorough and repeatable, lacks the clarity of a standard quantitative metric to describe for an Information system the level of compliance with the FISMA-required standard. Given subjective RMF assessment data, this article suggests the use of Pathfinder networks to generate a quantitative metric suitable to measure, manage, and track the status of Information system compliance with FISMA.

  • Information system security compliance to FISMA standard: A quantitative measure
    Telecommunication Systems, 2010
    Co-Authors: Elaine Hulitt, Rayford B. Vaughn
    Abstract:

    To ensure that safeguards are implemented to protect against a majority of known threats, industry leaders are requiring Information processing systems to comply with security standards. The National Institute of Standards and Technology Federal Information Risk Management Framework (RMF) and the associated suite of guidance documents describe the minimum security requirements (controls) for non-national-security federal Information systems mandated by the Federal Information Security Management Act (FISMA), enacted into law on December 17, 2002, as Title III of the E-Government Act of 2002. The subjective compliance assessment approach described in the RMF guidance, though thorough and repeatable, lacks the clarity of a standard quantitative metric to describe for an Information system the level of compliance with the FISMA-required standard. Given subjective RMF assessment data, this article suggests the use of Pathfinder networks to generate a quantitative metric suitable to measure, manage, and track the status of Information system compliance with FISMA.

  • IMCSIT - Information system security compliance to FISMA standard: A quantitative measure
    2008 International Multiconference on Computer Science and Information Technology, 2008
    Co-Authors: Elaine Hulitt, Rayford B. Vaughn
    Abstract:

    To ensure that safeguards are implemented to protect against a majority of known threats, industry leaders are requiring Information processing systems to comply with security standards. The National Institute of Standards and Technology Federal Information Risk Management Framework (RMF) and the associated suite of guidance documents describe the minimum security requirements (controls) for non-national-security federal Information systems mandated by the Federal Information Security Management Act (FISMA), enacted into law on December 17, 2002, as Title III of the E-Government Act of 2002. The subjective compliance assessment approach described in the RMF guidance, though thorough and repeatable, lacks the clarity of a standard quantitative metric to describe for an Information system the level of compliance with the FISMA-required standard. Given subjective RMF assessment data, this article suggests the use of Pathfinder networks to generate a quantitative metric suitable to measure, manage, and track the status of Information system compliance with FISMA.

Kuo-sui Lin - One of the best experts on this subject based on the ideXlab platform.

  • New Cost-Consequence FMEA Model for Information Risk Management of Safe And Secure SCADA Systems
    Software Engineering Artificial Intelligence Networking and Parallel Distributed Computing, 2020
    Co-Authors: Kuo-sui Lin
    Abstract:

    Risk Priority Number (RPN) based Failure Mode and Effects Analysis (FMEA) can be used as a structured method to prioritize all possible vulnerable areas (failure modes) for review of safety and security in a supervisory control and data acquisition (SCADA) system. However, traditional RPN based FMEA has some inherent problems for Risk Management of Information system. Therefore, the main purpose of this study was to propose a new cost-consequence FMEA model. It not only can recover traditional RPN-based FMEA problems, but also can evaluate, prioritize and correct safety and security of a SCADA system’s failure modes. A numerical case study was conducted to demonstrate that the proposed cost-consequence FMEA model is not only capable of addressing FMEA’s inherent problems but also is best suited for balancing monetary cost and Risk consequence of failure modes in a SCADA system. It also facilitates to make better use of resources in optimizing cost and consequence of failure modes.

  • New Cost-Consequence FMEA Model for Information Risk Management of Safe And Secure SCADA Systems
    Software Engineering Artificial Intelligence Networking and Parallel Distributed Computing, 2020
    Co-Authors: Kuo-sui Lin
    Abstract:

    Risk Priority Number (RPN) based Failure Mode and Effects Analysis (FMEA) can be used as a structured method to prioritize all possible vulnerable areas (failure modes) for review of safety and security in a supervisory control and data acquisition (SCADA) system. However, traditional RPN based FMEA has some inherent problems for Risk Management of Information system. Therefore, the main purpose of this study was to propose a new cost-consequence FMEA model. It not only can recover traditional RPN-based FMEA problems, but also can evaluate, prioritize and correct safety and security of a SCADA system’s failure modes. A numerical case study was conducted to demonstrate that the proposed cost-consequence FMEA model is not only capable of addressing FMEA’s inherent problems but also is best suited for balancing monetary cost and Risk consequence of failure modes in a SCADA system. It also facilitates to make better use of resources in optimizing cost and consequence of failure modes.

E Goetz - One of the best experts on this subject based on the ideXlab platform.