首页> 外文OA文献 >Self assessment framework for detecting vulnerability in web applications
【2h】

Self assessment framework for detecting vulnerability in web applications

机译:用于评估Web应用程序中漏洞的自我评估框架

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Security Assessment is widely used to audit the security protection of web applications. However, it is often performed by outside security experts or third party that has been appointed by the company. The problem appears when the assessment involves highly confidential areas that might impact company’s privacy data which directly reveal the important information to the third party. Even though they might have signed an agreement of non-disclosure information, but as they have already had the information on the infrastructure and architecture regardless of the confidential data, it has to be considered as a high risk. It is important to keep the information within the project members to protect the confidential data used by the system. Therefore, due to confidentiality level of the system, we proposed Self- Assessment framework to conduct security assessment internally to ensure the safety of all the assets of the organization. The main objective of this paper is to discuss the activities and processes involve in conducting security assessment.
机译:安全评估广泛用于审核Web应用程序的安全保护。但是,它通常由公司任命的外部安全专家或第三方执行。当评估涉及高度机密的区域,可能会影响公司的隐私数据,从而直接向第三方泄露重要信息时,就会出现问题。尽管他们可能已经签署了保密信息协议,但是由于他们已经拥有有关基础结构和体系结构的信息,而与机密数据无关,因此必须将其视为高风险。将信息保留在项目成员中以保护系统使用的机密数据非常重要。因此,由于系统的机密性,我们提出了自我评估框架以在内部进行安全评估,以确保组织所有资产的安全。本文的主要目的是讨论进行安全评估所涉及的活动和过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号