Applying composable security properties to assessment of information systems | IEEE Conference Publication | IEEE Xplore