This is not the document you are looking for? Use the search form below to find more!

Report home > Technology

The Systems Security Engineering Capability Maturity Model

0.00 (0 votes)
Document Description
The Systems Security Engineering Capability Maturity Model (SSE-CMM) was developed with the objective of advancing security engineering as a defined, mature and measurable discipline. The model and its accompanying appraisal method are currently available tools for evaluating the capability of providers of security engineering products, systems, and services as well as for guiding organizations in defining and improving their security engineering practices. The SSE-CMM Project began over three years ago as a joint effort between government and industry to develop a CMM for security engineering. The SSE-CMM is rapidly becoming the de facto standard for security engineering practices. Providers of systems, products, and services are now using the model to assess their current practices, identify potential process improvements, and distinguish themselves from competitors. Government acquisition agencies have already begun to use the model to evaluate potential suppliers.
File Details
Submitter
  • Name: johanna
Embed Code:

Add New Comment




Related Documents

SOFTWARE ENGINEERING INSTITUTE CAPABILITY MATURITY MODEL ISSUE PAPER

by: shayan, 6 pages

In 1984, the Software Engineering Institute (SEI) was established by the government to address DoD's need for improved software because it was apparent that many software developers did not have a ...

Introduction - IT Architecture Capability Maturity Model

by: tomas, 19 pages

he Operating Units of the Department of Commerce (DoC) have made a heavy investment in the development of enterprise-wide IT Architectures. We need to ensure that the Department continues to build ...

An Evolutionary Software Project Management Maturity Model for ...

by: cerys, 20 pages

Software project management is a relatively recent discipline that emerged during the second half of the 20th century (Kwak, 2003). Many of the software project management methodologies available ...

Business Development Capability Maturity Model

by: matthew, 152 pages

THIS MATERIAL IS FURNISHED BY BUSINESS DEVELOPMENT INSTITUTE INTERNATIONAL (BD-INSTITUTE) ON AN "AS-IS" BASIS. BD-INSTITUTE MAKES NO WARRANTIES OF ANY KIND, EITHER EXPRESSED OR IMPLIED, AS ...

Measuring Process Maturity: The Business Process Maturity Model

by: jansen, 24 pages

Dr. John W. Alden Managing Partner Capability Measurement, LLC Measuring Process Maturity: The Business Process Maturity Model ...

New Version of the Guide to the Systems Engineering Body of Knowledge Available

by: ieeecomputersociety, 1 pages

The latest version of the Guide to the Systems Engineering Body of Knowledge (SEBoK) is now available at http://www.sebokwiki.org.

Mobile Malware Evolution and the Android Security Model

by: beert, 17 pages

Mobile Malware Evolution and the Android Security Model

The LinkedData Value Chain: A Lightweight Model for Business Engineers

by: simone, 8 pages

Linked Data is as essential for the Semantic Web as hypertext has been for the Web. For this reason, the W3Ccommunity project Linking Open Data has been facilitating the transformation of publicly ...

Askeland English Version The Science And Engineering Of Materials

by: serge, 428 pages

Askeland English Version The Science And Engineering Of Materials

Chapter14: Information systems security and control

by: giovanni, 44 pages

14 INFORMATION SYSTEMS SECURITY AND CONTROL Chapter Why are information systems so vulnerable to destruction, error, abuse, and system quality problems? ...

Content Preview
Tutorial: The Systems Security Engineering Capability Maturity Model


Karen Ferraiolo

Arca Systems, Inc.

8229 Boone Blvd., Suite 750

Vienna, VA 22182

Phone: 703-734-5611

FAX: 703-790-0385

ferraiolo@arca.com
Tutorial Description


The Systems Security Engineering Capability Maturity Model (SSE-CMM) was developed with
the objective of advancing security engineering as a defined, mature and measurable discipline.
The model and its accompanying appraisal method are currently available tools for evaluating the
capability of providers of security engineering products, systems, and services as well as for
guiding organizations in defining and improving their security engineering practices.


The SSE-CMM Project began over three years ago as a joint effort between government and industry
to develop a CMM for security engineering. The SSE-CMM is rapidly becoming the de facto
standard for security engineering practices. Providers of systems, products, and services are now
using the model to assess their current practices, identify potential process improvements, and
distinguish themselves from competitors. Government acquisition agencies have already begun to use
the model to evaluate potential suppliers.


This tutorial describes the SSE-CMM and its appraisal method. A brief introduction to process
improvement and CMMs is provided. In addition, a discussion of the application of the SSE-
CMM looks at issues as they present themselves throughout a system acquisition, from RFP,
through development, and to system operation. The outline of the tutorial is as follows:

• History & the Need
• SSE-CMM Project Status
• Process Improvement and CMMs
• SSE-CMM Overview
• Using the SSE-CMM
• Current Applications

The Systems Security Engineering
Capability Maturity Model
Karen Ferraiolo
Arca Systems, Inc.
October 7, 1998

Topics
History & the Need
SSE-CMM Project Status
Process Improvement and CMMs
SSE-CMM Overview
Using the SSE-CMM
Current Applications

History and the Need

What is security engineering?
Security engineering, or aspects thereof,
attempts to:
establish a balanced set of security needs
transform security needs into security guidance
establish confidence in the correctness and
effectiveness of security mechanisms
judge that operational impacts due to residual
security vulnerabilities are tolerable
integrate all aspects into a combined
understanding of the trustworthiness of a system

Where are we now?
Security products come to market through:
lengthy and expensive evaluation
no evaluation
Results:
technology growth more rapid than its assimilation
unsubstantiated security claims
Causes?

What is needed?
continuity
repeatability
efficiency
assurance

One Potential Solution
Can knowing something about the
organization or individual provide a solution?
Examples:
ISO 9000
Certification of Information System Security
Professionals (CISSP)
Capability Maturity Model (CMM)
Malcolm Baldridge National Quality Award
Past Performance

Why was the SSE-CMM developed?
Objective
advance security engineering as a defined, mature, and
measurable discipline
Project Goal
Develop a mechanism to enable:
selection of appropriately qualified security engineering providers
focused investments in security engineering practices
capability-based assurance
Why the CMM approach?
accepted way of improving process capability
increasing use in acquisition as indicator of process capability

The SSE-CMM Project

Document Outline

  • Tutorial Description
    • Slides
  • Table of Contents

Download
The Systems Security Engineering Capability Maturity Model

 

 

Your download will begin in a moment.
If it doesn't, click here to try again.

Share The Systems Security Engineering Capability Maturity Model to:

Insert your wordpress URL:

example:

http://myblog.wordpress.com/
or
http://myblog.com/

Share The Systems Security Engineering Capability Maturity Model as:

From:

To:

Share The Systems Security Engineering Capability Maturity Model.

Enter two words as shown below. If you cannot read the words, click the refresh icon.

loading

Share The Systems Security Engineering Capability Maturity Model as:

Copy html code above and paste to your web page.

loading