Abstract
Security evaluation according to ISO 15408 (Common Criteria) is a resource and time demanding activity, as well as being costly. For this reason, only few companies take their products through a Common Criteria evaluation. To support security evaluation, the European Telecommunications Standards Institute (ETSI) has developed a threat, vulnerability, risk analysis (eTVRA) method for the Telecommunication (Telco) domain. eTVRA builds on the security risk management methodology CORAS and is structured in such a way that it provides output that can be directly fed into a Common Criteria security evaluation. In this paper, we evaluate the time and resource efficiency of parts of eTVRA and the quality of the result produced by following eTVRA compared to a more pragmatic approach (Protection Profile-based checklists). We use both approaches to identify and analyze risks of a new SIM card currently under joint development by a small hardware company and a large Telco provider. The new SIM card should comply with Evaluation Assurance Level 4 or 4+ according to Common Criteria.
| Original language | English |
|---|---|
| Place of Publication | Enschede |
| Publisher | Centre for Telematics and Information Technology (CTIT) |
| Number of pages | 10 |
| Publication status | Published - 10 Oct 2008 |
Publication series
| Name | CTIT Technical Report Series |
|---|---|
| Publisher | Centre for Telematics and Information Technology, University of Twente |
| No. | 10/TR-CTIT-08-62 |
| ISSN (Print) | 1381-3625 |
Keywords
- SCS-Cybersecurity
Fingerprint
Dive into the research topics of 'Extended eTVRA vs. Security Checklist: Experiences in a Value-Web'. Together they form a unique fingerprint.Research output
- 1 Conference contribution
-
Extended eTVRA vs. Security Checklist: Experiences in a Value-Web
Morali, A., Zambon, E., Houmb, S. H., Sallhammar, K. & Etalle, S., 26 Jan 2009, 31st International Conference on Software Engineering - Companion Volume. Los Alamitos: IEEE, p. 130-140 11 p.Research output: Chapter in Book/Report/Conference proceeding › Conference contribution › Academic › peer-review
File1 Link opens in a new tab Citation (Scopus)207 Downloads (Pure)
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver