DocumentCode :
1065714
Title :
Risk analysis in software design
Author :
Verdon, Denis ; McGraw, Gary
Volume :
2
Issue :
4
fYear :
2004
Firstpage :
79
Lastpage :
84
Abstract :
Risk analysis is, at best, a good general-purpose yardstick by which we can judge our security design´s effectiveness. Because roughly 50 percent of security problems are the result of design flaws, performing a risk analysis at the design level is an important part of a solid software security program. Taking the trouble to apply risk-analysis methods at the design level for any application often yields valuable, business-relevant results. The risk analysis process is continuous and applies to many different levels, at once identifying system-level vulnerabilities, assigning probability arid impact, arid determining reasonable mitigation strategies. The paper looks at how, by considering the resulting ranked risks, business stakeholders can determine how to manage particular risks and what the most cost-effective controls might be.
Keywords :
risk analysis; security; software engineering; design-level analysis; good judgement call; impacts; probability; risk analysis; software design; threats; vulnerabilities; Acceleration; Computer security; Costs; Cryptography; Data security; Hardware; Life testing; Probability; Risk analysis; Software design; 65; abuse cases; misuse cases; software design; software development;
fLanguage :
English
Journal_Title :
Security & Privacy, IEEE
Publisher :
ieee
ISSN :
1540-7993
Type :
jour
DOI :
10.1109/MSP.2004.55
Filename :
1324606
Link To Document :
بازگشت