首页> 外文会议>Annual Pacific northwest software quality conference >Moving up the Product Security Maturity Model
【24h】

Moving up the Product Security Maturity Model

机译:提出产品安全成熟度模型

获取原文

摘要

The world has become a global village, and it is being ruled and prominently controlled by technology and electronics in particular. This results to consistent increase in the availability of personal, corporate, and financial information in cyberspace. This creates enormous opportunities for cyber attackers to access the data and misuse it through hacking tools and tutorials. One such recent example is the intellectual property theft in the Xbox One gaming console and Xbox Live. The hacking of Target and Home Depot networks lead to the leakage of sensitive data such as email-ids and credit card details. Another example is the data breach of 4.2 million individuals in the US Government Office of Personnel Management (OPM). These incidents clearly emphasize the necessity to deliver a comprehensive secure product. For organizations, the goal must be to adopt a better strategy and protect the data and resources in a more proactive manner. Organizations span the spectrum when it comes to the maturity around creating secure products. Some organizations have a well-defined process that ensures the delivery of highly secure products whereas some organizations want to improve the security maturity model but lack management support. Some organizations are not even aware of product security and they are not sure from where to start. This paper defines a multi-layered security approach that can be applied to any platform, product, and programming language. The multi-layered security helps the product teams that having little knowledge of product security to uncover the low hanging security defects. As the team gains expertise they become Evangelist and Champions of secure software development. Since the threat types and attack vectors are evolving at a rapid pace, creating a security maturity model for the product that can provide up-to-date protection and realign its capability to handle the latest security challenges are vital.
机译:世界已成为一个全球村庄,它尤其是技术和电子的统治和突出控制。这导致网络空间中个人,企业和财务信息的可用性持续增加。这为网络攻击者提供了巨大的机会来访问数据并通过黑客工具和教程滥用它。最近一个这样的示例是Xbox一个游戏控制台和Xbox Live中的知识产权盗用。目标和Home Depot网络的黑客攻击导致敏感数据(如电子邮件ID和信用卡详细信息)的泄漏。另一个例子是美国政府人员管理办公室(OPM)的420万个人的数据违约。这些事件明确强调提供全面的安全产品的必要性。对于组织来说,目标必须是通过更好的策略并以更积极主动的方式保护数据和资源。组织在涉及到创新时涵盖创建安全产品时跨越频谱。有些组织具有明确的过程,可确保提供高度安全的产品,而一些组织希望改善安全成熟度模型但缺乏管理支持。有些组织甚至没有意识到产品安全性,并且他们不确定从哪里开始。本文定义了一种多层安全方法,可应用于任何平台,产品和编程语言。多层安全性有助于产品团队对产品安全性知之甚少,以揭示低悬挂安全缺陷。随着团队获得专业知识,他们成为安全软件开发的福音师和冠军。由于威胁类型和攻击向量正在以快速的节奏发展,因此为可以提供最新保护的产品创建安全成熟度模型,并重新调整其处理最新的安全挑战的能力是至关重要的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号