• DocumentCode
    2059144
  • Title

    A Methodological Tool for Asset Identification in Web Applications: Security Risk Assessment

  • Author

    Romero M, B.D. ; Haddad, Hisham M. ; Molero A, J.E.

  • Author_Institution
    Gen. Formation & Sci. Dept., Simon Bolivar Univ., Sartenejas, Venezuela
  • fYear
    2009
  • fDate
    20-25 Sept. 2009
  • Firstpage
    413
  • Lastpage
    418
  • Abstract
    Security risk assessment in Web Engineering is an emerging discipline, where security is given a special attention, allowing software engineers to develop high quality and secure Web based applications. A preliminary study revealed that asset identification (and evaluation) is an essential phase in risk assessment practices. This phase represents a degree of complexity and is the primary activity in the assessment process. This work focuses on asset identification and contributes to security risk assessment, which is essential part of software security. Specifically, the research goal is to design a methodological tool (instrument) for asset identification in web applications for the purpose of risk assessment. The proposed tool helps identify assets with security risks in Web applications. The tool involves direct observations and survey questionnaires as data collection techniques used for this work. The research methodology is based on qualitative and quantitative analysis of a case study that focused on Web based application for student opinion survey coordination (EOE) developed in Simoacuten Boliacutevar University, Venezuela. The data analysis required the use of cross case analysis supported by the software application MAXQDA2007, which helps identify assets according to categories, such as environment, software, hardware, information and networks. Under this work, students, faculty, staff, and software developers at Simoacuten Boliacutevar University have participated in this study.
  • Keywords
    Internet; computer aided analysis; risk management; security of data; software engineering; MAXQDA2007 software; Simoacuten Boliacutevar University project; Web Engineering; asset identification; case study quantitative analysis; cross case analysis; direct observation method; methodological tool design; secure Web based application; security risk assessment; software security; student opinion survey coordination; Application software; Computer security; Data analysis; Data security; Hardware; Information analysis; Information security; Instruments; Risk management; Software engineering; Computer Security; Risks Assessment; Web Applications; Web Engineering;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering Advances, 2009. ICSEA '09. Fourth International Conference on
  • Conference_Location
    Porto
  • Print_ISBN
    978-1-4244-4779-4
  • Electronic_ISBN
    978-0-7695-3777-1
  • Type

    conf

  • DOI
    10.1109/ICSEA.2009.66
  • Filename
    5298880