首页> 外文OA文献 >Risk-Based Measurement and Analysis: Application to Software Security
【2h】

Risk-Based Measurement and Analysis: Application to Software Security

机译:基于风险的度量和分析:在软件安全中的应用

摘要

For several years, the software engineering community has been working to identify practices aimed at developing more secure software. Although some foundational work has been performed, efforts to measure software security assurance have yet to materialize in any substantive fashion. As a result, decision makers (e.g., development program and project managers, acquisition program offices) lack confidence in the security characteristics of their software-reliant systems. The CERT® Program at Carnegie Mellon Universityu27s Software Engineering Institute (SEI) has chartered the Software Security Measurement and Analysis (SSMA) Project to advance the state-of-the-practice in software security measurement and analysis. The SSMA Project is exploring how to use risk analysis to direct an organizationu27s software security measurement and analysis efforts. The overarching goal is to develop a risk-based approach for measuring and monitoring the security characteristics of interactively complex software-reliant systems across the life cycle and supply chain. To accomplish this goal, the project team has developed the SEI Integrated Measurement and Analysis Framework (IMAF) and refined the SEI Mission Risk Diagnostic (MRD). This report is an update to the technical note, Integrated Measurement and Analysis Framework for Software Security (CMU/SEI-2010-TN-025), published in September 2010. This report presents the foundational concepts of a risk-based approach for software security measurement and analysis and provides an overview of the IMAF and the MRD.
机译:几年来,软件工程界一直在努力确定旨在开发更安全的软件的实践。尽管已经进行了一些基础性工作,但是衡量软件安全性保证的努力还没有以任何实质性的方式实现。结果,决策者(例如,开发程序和项目经理,采购程序办公室)对他们依赖软件的系统的安全特性缺乏信心。卡内基梅隆大学软件工程学院(SEI)的CERT®计划已批准了软件安全度量和分析(SSMA)项目,以推进软件安全度量和分析的最新实践。 SSMA项目正在探索如何使用风险分析来指导组织的软件安全性度量和分析工作。总体目标是开发一种基于风险的方法,用于测量和监视整个生命周期和供应链中依赖于交互的复杂软件系统的安全特性。为了实现此目标,项目团队开发了SEI集成测量和分析框架(IMAF),并完善了SEI任务风险诊断(MRD)。本报告是对2010年9月发布的软件安全集成度量和分析框架技术说明(CMU / SEI-2010-TN-025)的更新。此报告介绍了基于风险的软件安全方法的基本概念。测量和分析,并提供IMAF和MRD的概述。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号