60 likes | 166 Views
Introduction. CIS583, CSE 583. What is Systems Assurance?. First, what do we mean by systems? What do we mean by assurance?. What’s a System?. Holistic concept We do not just mean computer systems Communications, transportation, utilities, … Not just about technology: Includes the users
E N D
Introduction CIS583, CSE 583
What is Systems Assurance? • First, what do we mean by systems? • What do we mean by assurance?
What’s a System? • Holistic concept • We do not just mean computer systems • Communications, transportation, utilities, … • Not just about technology: • Includes the users • Policy (including management) • Public policy (what’s legal?)
What’s Assurance? • NSA says: availability, integrity, authentication, confidentiality, and nonrepudiation. • Let’s break that down:
Fundamental Concepts • Availability • There when you need it • Integrity • Still “pure” • Authentication • We know who each other are • Confidentiality • Secrets stay secret • Nonrepudiation • Can’t deny an action
Assurance Means Different Things to Different People • US Military • Banks (large multinational vs. local) • IBM • The Federal Communications Commission • My home computer • Syracuse University No two of these users have the same view of Systems Assurance!