Skip to content

We Need Assurance!

Today I stumbled across a paper on security and assurance by Brian Snow of the NSA. It presents an interesting point of view on this.
You can download it from http://www.acsa-admin.org/2005/papers/Snow.pdf.

Here is the abstract:


When will we be secure? Nobody knows for sure – but it cannot happen before commercial security products and services possess not only enough functionality to satisfy customers’ stated needs, but also sufficient assurance of quality, reliability, safety, and appropriateness for use. Such assurances are lacking in most of today’s commercial security products and services. I discuss paths to better assurance in Operating Systems, Applications, and Hardware through better development environments, requirements definition, systems engineering, quality certification, and legal/regulatory constraints. I also give some examples.

Categories: Security.

Tags: , ,

Comment Feed

No Responses (yet)



Some HTML is OK

or, reply to this post via trackback.