Security assurance aims to provide justified confidence that a system satisfies its security requirements under defined contextual conditions. In practice, assurance context is often handled implicitly, with assumptions, scope limitations, and boundary conditions embedded in documentation or expert judgment. This limits auditability, reproducibility, and governance, particularly in continuous assurance settings and workflows that rely on automation and AI-assisted reasoning. When reasoning operates over incomplete or underspecified context, implicit assumption formation can alter the basis of assurance conclusions. This paper introduces the Security Assurance Context Ontology (SACO), which reframes assurance context construction and evolution as explicit semantic and governance problems. SACO represents assurance-relevant context elements, their relationships, provenance, and epistemic status as authoritative semantic structures. Missing but required information is preserved as explicit semantic gaps that delimit when assurance claims may be authoritatively accepted. A strict separation between authoritative assurance context and advisory reasoning outputs constrains how automated or AI-assisted analysis may influence the assurance basis. The paper further presents a deterministic realization model for assurance context construction and evolution, where determinism applies to reconstructing authoritative context states from governed inputs.
Shao-Fang Wen (Tue,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: