...
首页> 外文期刊>International Journal of Computer Network and Information Security >IT Risk Management Based on ISO 31000 and OWASP Framework using OSINT at the Information Gathering Stage (Case Study: X Company)
【24h】

IT Risk Management Based on ISO 31000 and OWASP Framework using OSINT at the Information Gathering Stage (Case Study: X Company)

机译:基于ISO 31000和OWASP框架的IT风险管理在信息收集阶段使用oveSint(案例研究:X公司)

获取原文
   

获取外文期刊封面封底 >>

       

摘要

The major IT developments lead to speed and mobility elevation of information access. One of them is using the website to share and gather information. Therefore, the mobility and information disclosure create a harmful vulnerability. Which is the leakage of information, whether organizational or sensitive information, such as bank accounts, phone number and many more. Security testing is necessarily needed on website usage. One of the website security testing method is penetration testing. Supporting framework that can be used in this method is OWASP Testing Guide Version 4. OTG Version 4 has 11 stages cover all aspects of website protection and security. Security testing is nicely done using tools / software. Tools with the concept of OSINT (Open Source Intelligence) are used to get better access and availability by using the characteristics of open source. The IT risk assessment analysis carried out by ISO 31000 framework and based on the results that have been obtained through penetration testing with OWASP framework. Significance & values of this research is finding the best and effective way to making IT risk management guidelines along with the combination of with OWASP & ISO 31000 framework, by doing website security assessment with penetration testing method based on OWASP framework to get the system vulnerabilities and analyze the risks that appears with the ISO 31000 framework. Also, the IT risk management guidelines consist of system improvement recommendations along with evaluation report which obtained from the collaboration analysis the OSINT concept, penetration testing methods, OWASP and ISO 31000 framework.
机译:主要的IT发展导致信息访问的速度和移动性高度。其中一个是使用该网站分享和收集信息。因此,移动性和信息披露产生了有害的脆弱性。这是信息泄漏,无论是组织或敏感的信息,如银行账户,电话号码等等。网站使用情况需要安全测试。其中一个网站安全测试方法是渗透测试。支持框架可以在此方法中使用的是OWASP测试指南4. OTG版本4有11个阶段涵盖网站保护和安全的所有方面。安全测试使用工具/软件进行了很好的完成。使用开源的特性,使用具有ove of opsint(开源智能)概念的工具来获得更好的访问和可用性。 ISO 31000框架进行的IT风险评估分析,并基于通过通过渗透测试获得的结果。本研究的意义和价值观是通过使用基于OWASP框架的穿透测试方法进行网站安全评估来找到最佳和有效的方法以及与OWASP&ISO 31000框架的组合。通过基于OWASP框架来获得系统漏洞和分析ISO 31000框架中出现的风险。此外,IT风险管理指南由系统改进建议组成,以及从协作分析中获得的评估报告,从协作分析中获取over概念,渗透测试方法,OWASP和ISO 31000框架。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号