Security



Definition

Security
the quality factor representing the degree to which a system or component prevents, detects, reacts, and adapts to malicious harm to valuable assets caused by attackers
Attacker
The role played by a person or tool when performing an attack or probe
Malicious Harm
Unauthorized harm caused by an attack
Valuable Asset
those assets that are valuable to legitimate stakeholders of the system, whereby:

Classification

Security in the Inheritance Hierarchy

As illustrated in the preceding figure, Security is part of the following inheritance hierarchy:

Responsibilities

The typical responsibilities of Security are to:

Subfactors

As a kind of defensibility, security can be decomposed into the following two hierarchies of security subfactors:

The following figure illustrates the decomposition of defensibility and therefore security into the following two hierarchies of subfactors:


Defensibility Subfactors

The following figure illustrates some of the different kinds of harm to valuable assets:


Types of Harm

The following figure illustrates some of the different kinds of incidents:


Types of Incidents

The following figure illustrates some of the different kinds of dangers:


Dangers

The following figure illustrates some of the different kinds of risk:


Risks

Measures

Security is typically measured in terms of:

Mechanisms

Typical mechanisms for achieving security include:

Guidelines

The following guidelines have been found to be useful when producing security quality subfactors: