首页> 外文会议>IEEE International Workshop on Empirical Requirements Engineering >Security triage: A report of a lean security requirements methodology for cost-effective security analysis
【24h】

Security triage: A report of a lean security requirements methodology for cost-effective security analysis

机译:安全分类:用于成本有效的安全分析的精益安全需求方法的报告

获取原文

摘要

Poste Italiane is a large corporation offering integrated services in banking and savings, postal services, and mobile communication. Every year, it receives thousands of change requests for its ICT services. Applying to each and every request a security assessment “by the book”is simply not possible. We report the experience by Poste Italiane of a lean methodology to identify security requirements that can be inserted in the production cycle of a normal company. The process is based on surveying the overall IT architectures (Security Survey) and then a lean dynamic process (Security Triage) to evaluate individual change requests, so that important changes get the attention they need, minor changes can be quickly implemented, and compliance and security obligations are met.
机译:Poste Italiane是一家大型公司,提供银行和储蓄,邮政服务和移动通信方面的集成服务。每年,它收到有关其ICT服务的成千上万的变更请求。根本不可能“按需”对每个请求进行安全评估。我们报告了P​​oste Italiane精益方法论的经验,该方法可识别可以插入到正常公司的生产周期中的安全要求。该流程基于对整个IT架构的调查(安全调查),然后是精益的动态流程(安全分类),以评估各个变更请求,以便重要变更得到他们所需的关注,较小的变更可以快速实施,并且合规性和履行了安全义务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号