Management of Information Security and Risk: Assurance Cases

Bachelor's degree

In Islington

Price on request

Description

  • Type

    Bachelor's degree

  • Location

    Islington

Assurance cases, as a generalisation of safety case to security and dependability, are a powerful approach to justifying and communicating the trustworthiness of a complex system.  We have defined an assurance case as: "a documented body of evidence that provides a convincing and valid argument that a system is adequately dependable for a given application in a given environment". Assurance cases are based on the key concept of claims, arguments and evidence. There is a need for methods to define and structure claims (e.g. that the security properties are satisfied, that hazards have been mitigated, that vulnerabilities have been addressed, and that business continuity is being supported), and show how these are discharged with compelling arguments commensurate with the criticality of the system being assessed, while providing supporting evidence (such as from testing, analysis). Assurance cases are often embedded within a safety and security management process and often within a regulatory or licensing process that provides for independent challenge and review. Assurance cases can play a pivotal role in audits and reviews, as well as in incident management and investigation, where they can play a role in on-going processes, as well as use evidence from previous incident occurrences in the context of new assurance cases. It is important to understand the range of standards that can be applied and their role and limitations.

The module will be delivered in block mode consisting of two blocks:

Thursday: 5pm-9pm Friday: 9am-5pm Saturday: 9am-5pm

The second block is delivered 6 weeks after the first block.  

This module is taken from the MSc in Management of Information Security and Risk.

Course Information Start DateStart TimeDurationCostCourse CodeApply Thursday 12 February 2015 Thursday 17:00-21:00; Friday 9:00-17:00; Saturday 9:00-17:00 Two blocks comprising...

Facilities

Location

Start date

Islington (London)
See map
Northampton Square, EC1V 0HB

Start date

On request

Questions & Answers

Add your question

Our advisors and other users will be able to reply to you

Who would you like to address this question to?

Fill in your details to get a reply

We will only publish your name and question

Reviews

Subjects

  • Management
  • Risk
  • Security
  • IT
  • IT risk
  • IT Security
  • IT Management
  • Play

Course programme

What will I learn?
  • The nature of the assurance and evaluation problem for computer based systems
  • Deriving and structuring of claims in an assurance case; claim expansion from architecture; from dependability attributes.
  • The role of standards, policies and regulations in deriving claims and argument strategies
  • Evidence and arguments for different attributes
  • Reviewing and assessing cases; improving communication. Developing cases for a range of stakeholders - from "boardroom to back office"
  • Cases for specific classes of systems. Issues of scalability
  • The use of tools for assurance cases (e.g. ASCE).

Additional information

Teaching and Assessment

Assessment is coursework based consisting of a mixture of one or more of the following:

  • reports
  • essays
  • presentations
  • peer reviews
  • group work.

Management of Information Security and Risk: Assurance Cases

Price on request