首页> 外文会议>International Conference on Technical Debt >Security Debt: Characteristics, Product Life-Cycle Integration and Items
【24h】

Security Debt: Characteristics, Product Life-Cycle Integration and Items

机译:安全债务:特点,产品生命周期集成和物品

获取原文

摘要

Industries from very diverse domains are realising that security should not be treated in a reactive way (e.g., once the cyberattack has happened). This way, security-related requirements and risks need to be continuously managed, and the need of integrating technical measures should be continuously assessed. In some cases, some decisions led, intentionally or unintentionally, to debt related to security aspects. This security debt is thus incurred when limited approaches or solutions are applied to reach the expected security levels of the system in operation. Identifying and making explicit security debt items is a challenge for companies. In this work, we analyse the literature on security debt to provide initial insights on the topic. Concretely, we discuss its definition, identify its most salient characteristics, present approaches for integrating its management in the product life-cycle, and to present categories and examples of security debt items.
机译:来自非常多样化的域的行业都意识到安全性不应以反应方式对待(例如,一旦发生网络攻击发生)。 这种方式,需要不断管理安全相关的要求和风险,并且应不断持续进行整合技术措施的需求。 在某些情况下,有意或无意地导致与安全方面有关的一些决定。 因此,当申请有限的方法或解决方案达到制度的预期安全级别时,因此发生了这种安全债务。 识别和制定明确的安全债务项目是公司的挑战。 在这项工作中,我们分析了安全债务的文献,为该专题提供了初步见解。 具体地,我们讨论其定义,确定其最突出的特征,将其在产品生命周期中整合其管理的现行方法,以及提供安全债务项目的类别和例子。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号