Aerospace and Electronic Systems Magazine November 2017 - 9

Asgari et al.
scenario can be completed successfully and practically, and realized according to the scale specified in SecRAM. The SecRAM
scoring is subjective and depends on definition of scales, best practices, intuition, and the security experts' knowledge. This method
is opinion based but it is still one of the main methods to access
the impact and likelihood by accounting for various real-world parameters. According to the SecRAM, the likelihood is built from a
split into exposure or frequency of occurrence of the threat source
and potentiality, the probability that once the threat source occurs,
the threat scenario sequence is completed successfully. Once both
likelihood layers have been evaluated, the likelihood is obtained
from the average of both values rounded up to the next integer.
Once the likelihood and impact of each threat has been assessed, the level of risk is calculated according to the SecRAM recommendation. Treatment actions or security controls are defined
to protect SA. They are a collection of measures for managing
risks and to ensure the security objectives are met. They include,
but are not limited to, procedures, policies, more robust technical
solutions, and management actions. The security objective level
comes from the definition of the impact area such as performance,
economic, etc. A security need is defined whether a risk should be
treated or not; when the level of a risk is higher than the security

NOVEMBER 2017

objective of an SA (i.e. the lowest security objective) it is targeting,
a treatment shall be applied.
The risk treatment option should be selected from the actions,
i.e., tolerate, reduce, avoid, or transfer. Here, we choose the "tolerate" option for the threats with 'low' risk level and the "reduce"
option in combating threats with 'medium' and 'high' risk levels to
meet security objective levels. In defining the security controls, it
is important to take into account the three parameters (i.e., likelihood, impact, and risk level). For example, if the likelihood has a
high value and impact has a low value, but risk level is high, the
security control should be primarily defined to counter the likelihood and it could overlook the impact.
Once the type of treatment has been evaluated (e.g. for reduction of the risk), a strategy of protection for SA is applied in order
to choose the best set of security controls. The strategy proposed by
SESAR offers two approaches for combined security control: "defense in depth" and "strength of control." Defense in depth relies on a
multilayered set of unrelated controls acting together to provide protection to a supporting asset. The multilayered approach to controls
means that if one control is compromised then another control should
act as the next layer of defense. Strength of control relies on improving the performance of one "type" of control (e.g., rigorous access

IEEE A&E SYSTEMS MAGAZINE

9



Table of Contents for the Digital Edition of Aerospace and Electronic Systems Magazine November 2017

No label
Aerospace and Electronic Systems Magazine November 2017 - No label
Aerospace and Electronic Systems Magazine November 2017 - Cover2
Aerospace and Electronic Systems Magazine November 2017 - 1
Aerospace and Electronic Systems Magazine November 2017 - 2
Aerospace and Electronic Systems Magazine November 2017 - 3
Aerospace and Electronic Systems Magazine November 2017 - 4
Aerospace and Electronic Systems Magazine November 2017 - 5
Aerospace and Electronic Systems Magazine November 2017 - 6
Aerospace and Electronic Systems Magazine November 2017 - 7
Aerospace and Electronic Systems Magazine November 2017 - 8
Aerospace and Electronic Systems Magazine November 2017 - 9
Aerospace and Electronic Systems Magazine November 2017 - 10
Aerospace and Electronic Systems Magazine November 2017 - 11
Aerospace and Electronic Systems Magazine November 2017 - 12
Aerospace and Electronic Systems Magazine November 2017 - 13
Aerospace and Electronic Systems Magazine November 2017 - 14
Aerospace and Electronic Systems Magazine November 2017 - 15
Aerospace and Electronic Systems Magazine November 2017 - 16
Aerospace and Electronic Systems Magazine November 2017 - 17
Aerospace and Electronic Systems Magazine November 2017 - 18
Aerospace and Electronic Systems Magazine November 2017 - 19
Aerospace and Electronic Systems Magazine November 2017 - 20
Aerospace and Electronic Systems Magazine November 2017 - 21
Aerospace and Electronic Systems Magazine November 2017 - 22
Aerospace and Electronic Systems Magazine November 2017 - 23
Aerospace and Electronic Systems Magazine November 2017 - 24
Aerospace and Electronic Systems Magazine November 2017 - 25
Aerospace and Electronic Systems Magazine November 2017 - 26
Aerospace and Electronic Systems Magazine November 2017 - 27
Aerospace and Electronic Systems Magazine November 2017 - 28
Aerospace and Electronic Systems Magazine November 2017 - 29
Aerospace and Electronic Systems Magazine November 2017 - 30
Aerospace and Electronic Systems Magazine November 2017 - 31
Aerospace and Electronic Systems Magazine November 2017 - 32
Aerospace and Electronic Systems Magazine November 2017 - 33
Aerospace and Electronic Systems Magazine November 2017 - 34
Aerospace and Electronic Systems Magazine November 2017 - 35
Aerospace and Electronic Systems Magazine November 2017 - 36
Aerospace and Electronic Systems Magazine November 2017 - 37
Aerospace and Electronic Systems Magazine November 2017 - 38
Aerospace and Electronic Systems Magazine November 2017 - 39
Aerospace and Electronic Systems Magazine November 2017 - 40
Aerospace and Electronic Systems Magazine November 2017 - 41
Aerospace and Electronic Systems Magazine November 2017 - 42
Aerospace and Electronic Systems Magazine November 2017 - 43
Aerospace and Electronic Systems Magazine November 2017 - 44
Aerospace and Electronic Systems Magazine November 2017 - 45
Aerospace and Electronic Systems Magazine November 2017 - 46
Aerospace and Electronic Systems Magazine November 2017 - 47
Aerospace and Electronic Systems Magazine November 2017 - 48
Aerospace and Electronic Systems Magazine November 2017 - 49
Aerospace and Electronic Systems Magazine November 2017 - 50
Aerospace and Electronic Systems Magazine November 2017 - 51
Aerospace and Electronic Systems Magazine November 2017 - 52
Aerospace and Electronic Systems Magazine November 2017 - 53
Aerospace and Electronic Systems Magazine November 2017 - 54
Aerospace and Electronic Systems Magazine November 2017 - 55
Aerospace and Electronic Systems Magazine November 2017 - 56
Aerospace and Electronic Systems Magazine November 2017 - 57
Aerospace and Electronic Systems Magazine November 2017 - 58
Aerospace and Electronic Systems Magazine November 2017 - 59
Aerospace and Electronic Systems Magazine November 2017 - 60
Aerospace and Electronic Systems Magazine November 2017 - 61
Aerospace and Electronic Systems Magazine November 2017 - 62
Aerospace and Electronic Systems Magazine November 2017 - 63
Aerospace and Electronic Systems Magazine November 2017 - 64
Aerospace and Electronic Systems Magazine November 2017 - Cover3
Aerospace and Electronic Systems Magazine November 2017 - Cover4
http://www.brightcopy.net/allen/aesm/34-2s
http://www.brightcopy.net/allen/aesm/34-2
http://www.brightcopy.net/allen/aesm/34-1
http://www.brightcopy.net/allen/aesm/33-12
http://www.brightcopy.net/allen/aesm/33-11
http://www.brightcopy.net/allen/aesm/33-10
http://www.brightcopy.net/allen/aesm/33-09
http://www.brightcopy.net/allen/aesm/33-8
http://www.brightcopy.net/allen/aesm/33-7
http://www.brightcopy.net/allen/aesm/33-5
http://www.brightcopy.net/allen/aesm/33-4
http://www.brightcopy.net/allen/aesm/33-3
http://www.brightcopy.net/allen/aesm/33-2
http://www.brightcopy.net/allen/aesm/33-1
http://www.brightcopy.net/allen/aesm/32-10
http://www.brightcopy.net/allen/aesm/32-12
http://www.brightcopy.net/allen/aesm/32-9
http://www.brightcopy.net/allen/aesm/32-11
http://www.brightcopy.net/allen/aesm/32-8
http://www.brightcopy.net/allen/aesm/32-7s
http://www.brightcopy.net/allen/aesm/32-7
http://www.brightcopy.net/allen/aesm/32-6
http://www.brightcopy.net/allen/aesm/32-5
http://www.brightcopy.net/allen/aesm/32-4
http://www.brightcopy.net/allen/aesm/32-3
http://www.brightcopy.net/allen/aesm/32-2
http://www.brightcopy.net/allen/aesm/32-1
http://www.brightcopy.net/allen/aesm/31-12
http://www.brightcopy.net/allen/aesm/31-11s
http://www.brightcopy.net/allen/aesm/31-11
http://www.brightcopy.net/allen/aesm/31-10
http://www.brightcopy.net/allen/aesm/31-9
http://www.brightcopy.net/allen/aesm/31-8
http://www.brightcopy.net/allen/aesm/31-7
https://www.nxtbookmedia.com