An Information System Security Evaluation Method Based on FCME Model

YAN Qiang,SHU Huaying,CHEN Zhong,DUAN Yunsuo
DOI: https://doi.org/10.3969/j.issn.1000-3428.2006.02.045
2006-01-01
Abstract:Security elements evaluation is a primary problem of information system security evaluation. However the security elements defined in evaluation standard GB 17859 are abstract and hard to measure directly. It has become an urgent task to establish an understandable and practicable evaluation method for security elements. Based on the research and development process of security evaluation tools, this paper introduces the factor-criteria-metrics-evidence (FCME) model, which is used in security elements evaluation process, and discusses the implementation of the model.
What problem does this paper attempt to address?