A Relationship Between Products Evaluation and IT Systems Assurance

IT systems consist on very many components and very complex, so the implementation of the security countermeasures needs more critical considerations. Indeed, IT systems contain many subsystems, and most of subsystems consist of one or more IT products. In this hierarchy structure, the security characteristics of each IT product may affect the total assurance of the IT systems. Therefore, the security should be considered at the base level of the IT systems, in other words, IT product the base of the IT systems. For this work, this paper presents our research results about the security and assurance relationship between IT products and IT systems.