article Some security principles and their application to computer security Share on Authors: R. Stockton Gaines The Rand Corporation, Santa Monica, California The Rand Corporation, Santa Monica, CaliforniaView Profile , Norman Z. Shapiro The Rand Corporation, Santa Monica, California The Rand Corporation, Santa Monica, CaliforniaView Profile Authors Info & Claims ACM SIGOPS Operating Systems ReviewVolume 12Issue 3July 1978 pp 19–28https://doi.org/10.1145/775396.775398Online:01 July 1978Publication History 10citation1,024DownloadsMetricsTotal Citations10Total Downloads1,024Last 12 Months13Last 6 weeks1 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
An important problem area in providing security in computer systems is to avoid excessively costly and constraining security practices while providing an adequate level of security. In addition, there are problems in determining an appropriate level of investment in techniques and practices which enhance security and in the measurement of returns on those investments, i.e., to what degree is security improved by any given technique? The resolution of these problems depends on the development of a capability for identifying and evaluating the risks of storing and processing sensitive data in imperfectly secure computing environments. This paper provides background information on security assessment, surveys recent work and the present status of computer security assessment, and identifies the research needed to move this field forward.
The discussion during this session primarily centered around the paper “On Data Secure Computer Networks” by G.J. Popek. Popek suggested that the main security problems in computer networks involved the security of the host computers in the network and that techniques for securing general communications networks are satisfactory for dealing with the communication aspects of computer networks. The main problems which need to be addressed are the problems of authenticating processes in different computer systems in the network to each other and of providing the required degree of security in the computer systems in the network. There was no real dispute of Popek's claims by the attendees at the workshop.