Abstract | ||
---|---|---|
In order to obtain evidence about the security strength in products we need automated information security analysis, validation, evaluation and testing approaches. Unfortunately, no widely accepted practical approaches are available. Information security testing of software-intensive and telecommunications systems typically relies heavily on the experience of the security professionals. In this study, we argue that security requirements are within the focus of the information security testing process. Information security requirements can be based on iterative risk, threat and vulnerability analyses, and technical and architectural information. We discuss security testing process, security objectives and security requirements from the basis of the experiences of a security testing case study project. |
Year | DOI | Venue |
---|---|---|
2007 | 10.1109/AICT.2007.37 | Morne |
Keywords | Field | DocType |
traditional paper-and-pencil annotation,telecommunications software,case study,computer-based annotation system,wide range,annotation system,practical security testing,security testing,protocols,risk analysis,software testing,manufacturing industries,computer bugs,information security,system testing,information analysis | Security convergence,Security testing,Computer security,Computer science,Software security assurance,Asset (computer security),Risk analysis (engineering),Security service,Cloud computing security,Security information and event management,Computer security model | Conference |
ISBN | Citations | PageRank |
0-7695-2843-0 | 0 | 0.34 |
References | Authors | |
4 | 2 |
Name | Order | Citations | PageRank |
---|---|---|---|
Reijo Savola | 1 | 318 | 35.00 |
Kaarina Karppinen | 2 | 33 | 5.62 |