Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Risk-based assessment of the surety of information systems

Technical Report ·
DOI:https://doi.org/10.2172/285501· OSTI ID:285501

When software is used in safety-critical, security-critical, or mission-critical situations, it is imperative to understand and manage the risks involved. A risk assessment methodology and toolset have been developed which are specific to software systems and address a broad range of risks including security, safety, and correct operation. A unique aspect of this methodology is the use of a modeling technique that captures interactions and tradeoffs among risk mitigators. This paper describes the concepts and components of the methodology and presents its application to example systems.

Research Organization:
Sandia National Labs., Albuquerque, NM (United States)
Sponsoring Organization:
USDOE, Washington, DC (United States)
DOE Contract Number:
AC04-94AL85000
OSTI ID:
285501
Report Number(s):
SAND--96-2027; ON: DE96014165
Country of Publication:
United States
Language:
English