首页> 外文会议>Annual Pacific northwest software quality conference >Moving up the Product Security Maturity Model
【24h】

Moving up the Product Security Maturity Model

机译:提升产品安全性成熟度模型

获取原文

摘要

The world has become a global village, and it is being ruled and prominently controlled by technology and electronics in particular. This results to consistent increase in the availability of personal, corporate, and financial information in cyberspace. This creates enormous opportunities for cyber attackers to access the data and misuse it through hacking tools and tutorials. One such recent example is the intellectual property theft in the Xbox One gaming console and Xbox Live. The hacking of Target and Home Depot networks lead to the leakage of sensitive data such as email-ids and credit card details. Another example is the data breach of 4.2 million individuals in the US Government Office of Personnel Management (OPM). These incidents clearly emphasize the necessity to deliver a comprehensive secure product. For organizations, the goal must be to adopt a better strategy and protect the data and resources in a more proactive manner. Organizations span the spectrum when it comes to the maturity around creating secure products. Some organizations have a well-defined process that ensures the delivery of highly secure products whereas some organizations want to improve the security maturity model but lack management support. Some organizations are not even aware of product security and they are not sure from where to start. This paper defines a multi-layered security approach that can be applied to any platform, product, and programming language. The multi-layered security helps the product teams that having little knowledge of product security to uncover the low hanging security defects. As the team gains expertise they become Evangelist and Champions of secure software development. Since the threat types and attack vectors are evolving at a rapid pace, creating a security maturity model for the product that can provide up-to-date protection and realign its capability to handle the latest security challenges are vital.
机译:世界已成为一个全球性的村庄,并且它尤其受到技术和电子的统治和控制。这导致网络空间中个人,公司和财务信息的可用性不断增加。这为网络攻击者通过黑客工具和教程提供了巨大的机会来访问数据并滥用数据。最近的一个例子是Xbox One游戏机和Xbox Live中的知识产权盗窃。入侵Target和Home Depot网络会导致敏感数据(例如电子邮件ID和信用卡详细信息)的泄漏。另一个例子是美国政府人事管理办公室(OPM)的420万个人的数据泄露。这些事件清楚地强调了交付全面安全产品的必要性。对于组织而言,目标必须是采用更好的策略并以更加主动的方式保护数据和资源。在涉及创建安全产品的成熟度方面,组织涉及范围很广。一些组织的定义明确的过程可确保交付高度安全的产品,而某些组织则希望改善安全成熟度模型,但缺乏管理支持。一些组织甚至不了解产品安全性,因此不确定从何处开始。本文定义了可应用于任何平台,产品和编程语言的多层安全性方法。多层安全性可帮助对产品安全性知之甚少的产品团队发现低级安全性缺陷。随着团队获得专业知识,他们成为安全软件开发的推广者和拥护者。由于威胁类型和攻击媒介的发展日新月异,因此为产品创建安全成熟度模型以提供最新保护并重新调整其应对最新安全挑战的能力至关重要。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号