Towards agile security risk management in RE and beyond

V. N. Franqueira, Zornitza Bakalova, T. Tun, M. Daneva
{"title":"Towards agile security risk management in RE and beyond","authors":"V. N. Franqueira, Zornitza Bakalova, T. Tun, M. Daneva","doi":"10.1109/EmpiRE.2011.6046253","DOIUrl":null,"url":null,"abstract":"Little attention has been given so far to the process of security risk management at the early stages of system development. Security has been addressed by isolated security assurance practices, some of which consider risks and mitigations but they do not provide an overview of the overall security state of the system being developed. This paper takes the position that (1) these isolated security assurance practices should be fully integrated and should be embedded in short iterations of risk assessment, treatment and acceptance, providing input for updating security requirements and for security risk management, and that (2) available empirical data from public catalogs and databases should be used as a source of expertise, to leverage past experiences, and therefore reduce, although not eliminate, subjectivity of human judgment. Borrowing from the agile software development and project management philosophy, we introduce the idea of a light weight, agile approach to security risk management integrated to the development life cycle.","PeriodicalId":128168,"journal":{"name":"Workshop on Empirical Requirements Engineering (EmpiRE 2011)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-10-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Workshop on Empirical Requirements Engineering (EmpiRE 2011)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EmpiRE.2011.6046253","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

Little attention has been given so far to the process of security risk management at the early stages of system development. Security has been addressed by isolated security assurance practices, some of which consider risks and mitigations but they do not provide an overview of the overall security state of the system being developed. This paper takes the position that (1) these isolated security assurance practices should be fully integrated and should be embedded in short iterations of risk assessment, treatment and acceptance, providing input for updating security requirements and for security risk management, and that (2) available empirical data from public catalogs and databases should be used as a source of expertise, to leverage past experiences, and therefore reduce, although not eliminate, subjectivity of human judgment. Borrowing from the agile software development and project management philosophy, we introduce the idea of a light weight, agile approach to security risk management integrated to the development life cycle.
在可再生能源及其他领域实现敏捷安全风险管理
到目前为止,人们对系统开发初期的安全风险管理过程关注甚少。安全性已经通过孤立的安全保证实践得到了解决,其中一些实践考虑了风险和缓解措施,但它们没有提供正在开发的系统的整体安全状态的概述。本文的立场是:(1)这些孤立的安全保证实践应该完全集成,并且应该嵌入到风险评估、处理和接受的短迭代中,为更新安全需求和安全风险管理提供输入,(2)来自公共目录和数据库的可用经验数据应该用作专业知识的来源,以利用过去的经验,因此减少,尽管不是消除,人类判断的主观性。借鉴敏捷软件开发和项目管理理念,我们引入了一种轻量级、敏捷的方法,将安全风险管理集成到开发生命周期中。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信