Cristin-resultat-ID: 1336230
Sist endret: 9. mars 2016, 21:36
NVI-rapporteringsår: 2015
Resultat
Vitenskapelig artikkel
2015

Combining Security Risk Assessment and Security Testing Based on Standards

Bidragsytere:
  • Jürgen Großmann og
  • Fredrik Seehusen

Tidsskrift

Lecture Notes in Computer Science (LNCS)
ISSN 0302-9743
e-ISSN 1611-3349
NVI-nivå 1

Om resultatet

Vitenskapelig artikkel
Publiseringsår: 2015
Volum: 9488
Sider: 18 - 33

Importkilder

Scopus-ID: 2-s2.0-84951080799

Beskrivelse Beskrivelse

Tittel

Combining Security Risk Assessment and Security Testing Based on Standards

Sammendrag

Managing cyber security has become increasingly important due to the growing interconnectivity of computerized systems and their use in society. A comprehensive assessment of cyber security can be challenging as its spans across different domains of knowledge and expertise. For instance, identifying cyber security vulnerabilities requires detailed technical expertise and knowledge, while the assessment of organizational impact and legal implications of cyber security incidents may require expertise and knowledge related to risk and compliance. Standards like ISO 31000 and ISO/IEC/IEEE 29119 detail the relevant aspects of risk management and testing and thus provide guidance in these areas. However, both standards are not exclusively dedicated to the subject of security and do not cover the explicit integration between security risk assessment and security testing. We think however, that they provide a good basis for that. In this paper we show how ISO 31000 and ISO/IEC/IEEE 29119 can be integrated to provide a comprehensive approach to cyber security that covers both security risk assessment and security testing.

Bidragsytere

Jürgen Großmann

  • Tilknyttet:
    Forfatter
    ved Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V.

Fredrik Seehusen

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS
1 - 2 av 2