首页> 外文期刊>International Journal of Computer Network and Information Security >Information Technology Risk Management Using ISO 31000 Based on ISSAF Framework Penetration Testing (Case Study: Election Commission of X City)
【24h】

Information Technology Risk Management Using ISO 31000 Based on ISSAF Framework Penetration Testing (Case Study: Election Commission of X City)

机译:信息技术风险管理使用ISO 31000基于ISSAF框架渗透检测(案例研究:X城选举委员会)

获取原文
           

摘要

Election Commission of X City is an institution that serves as the organizer of elections in the X City, which has a website as a medium in the delivery of information to the public and as a medium for the management and structuring of voter data in the domicile of X City. As a website that stores sensitive data, it is necessary to have risk management aimed at improving the security aspects of the website of Election Commission of X City. The Information System Security Assessment Framework (ISSAF) is a penetration testing standard used to test website resilience, with nine stages of attack testing which has several advantages over existing security controls against threats and security gaps, and serves as a bridge between technical and managerial views of penetration testing by applying the necessary controls on both aspects. Penetration testing is carried out to find security holes on the website, which can then be used for assessment on ISO 31000 risk management which includes the stages of risk identification, risk analysis, and risk evaluation. The main findings of this study are testing a combination of penetration testing using the ISSAF framework and ISO 31000 risk management to obtain the security risks posed by a website. Based on this research, obtained the results that there are 18 security gaps from penetration testing, which based on ISO 31000 risk management assessment there are two types of security risks with high level, eight risks of medium level security vulnerabilities, and eight risks of security vulnerability with low levels. Some recommendations are given to overcome the risk of gaps found on the website.
机译:X城市选举委员会是一个机构,作为X城的选举组织者,该机构有一个网站作为向公众提供信息的媒介,作为居住在住所的选民数据的媒介X城市。作为存储敏感数据的网站,有必要有风险管理,旨在改善X城市选举委员会网站的安全方面。信息系统安全评估框架(ISSAF)是用于测试网站弹性的渗透测试标准,患有九个攻击测试阶段,这对现有的威胁和安全差距具有若干优势,并且作为技术和管理视图之间的桥梁通过应用必要的控制对两个方面的渗透测试。进行渗透测试,以便在网站上找到安全漏洞,然后可以用于评估ISO 31000风险管理,包括风险识别,风险分析和风险评估的阶段。本研究的主要结果正在使用ISSAF框架和ISO 31000风险管理来测试渗透测试的组合,以获得网站提出的安全风险。基于这项研究,获得了渗透测试中有18个安全差距的结果,基于ISO 31000风险管理评估,有两种类型的安全风险具有高水平,中级安全漏洞的八种风险,以及八种安全风险漏洞低水平。提供了一些建议克服网站上发现的差距的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号