Home > Papers

 
 
An Architecture-Centric Approach for Security Technical Debt Quantification
Yang Jun 1 #,Rami Bahsoon 2,Liu Jiqiang 1 *
1.School of Computer Science and Information Technology, Beijing Jiaotong University, Beijing 100044
2.School of Computer Science, University of Birmingham, Birmingham, UK, B15 2TT
*Correspondence author
#Submitted by
Subject:
Funding: none
Opened online: 7 April 2016
Accepted by: none
Citation: Yang Jun,Rami Bahsoon,Liu Jiqiang.An Architecture-Centric Approach for Security Technical Debt Quantification[OL]. [ 7 April 2016] http://en.paper.edu.cn/en_releasepaper/content/4681192
 
 
Security managers and architects often have trouble in making decision among various security technologies when the budget is limited. At this time, a compromise between effective security technologies and limited budget may hurt the system's long-term health and introduce technology debt. This paper presents an architecture-centric cost-benefit method for quantifying technology debt caused by different security deployment solutions, in order to help security managers to manage technology debts and make decisions. The proposed method is an extension of the Security Attribute Evaluation Method (SAEM) to reason about the debt in secure architectures. A case study is adopted to exemplify the process of method. The result indicates that the method provides an angle of technology debt beyond the plain SAEM method to help security manager make choice and manage long-term benefit and cost.
Keywords:Information Security; Technology Debt; Security Architecture
 
 
 

For this paper

  • PDF (0B)
  • ● Revision 0   
  • ● Print this paper
  • ● Recommend this paper to a friend
  • ● Add to my favorite list

    Saved Papers

    Please enter a name for this paper to be shown in your personalized Saved Papers list

Tags

Add yours

Related Papers

Statistics

PDF Downloaded 60
Bookmarked 0
Recommend 0
Comments Array
Submit your papers