This paper explores generating and conveying confidence in enterprise security. An enterprise assurance framework provides a structure enterprise assurance evidence that strengthens and clarifies the overall enterprise assurance argument. The structure and components of these arguments are defined and then applied to an enterprise. Finally, standards of evidence and evidence trade-offs are mentioned. This paper is largely based on a recent NIST internal report called "A Framework for Reasoning about Assurance."
Douglas J. Landoll, Jeffrey R. Williams