Measuring Application Security

被引:0
|
作者
Horn, Christopher [1 ]
D'Amico, Anita [2 ]
机构
[1] Secure Decis, Clifton Pk, NY 12065 USA
[2] Code Dx, Northport, NY USA
关键词
Application security; Security management; Security metrics; Program management; Risk management; METRICS;
D O I
10.1007/978-3-319-94782-2_5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We report on a qualitative study of application security (AppSec) program management. We sought to establish the boundaries used to define program scope, the goals of AppSec practitioners, and the metrics and tools used to measure performance. We find that the overarching goal of AppSec groups is to ensure the security of software systems; this is a process of risk management. AppSec boundaries varied, but almost always excluded infrastructure-level system components. Seven top-level questions guide practitioner efforts; those receiving the most attention are Where are the application vulnerabilities in my software?, Where are my blind spots?, How do I communicate & demonstrate AppSec's value to my management?, and Are we getting better at building in security over time?. Many metrics are used to successfully answer these questions, but one challenge stood out: there is no good way to measure AppSec risk. No one metric system dominated observed usage.
引用
收藏
页码:44 / 55
页数:12
相关论文
共 50 条
  • [1] Models for Measuring Access Security of Web Application
    Thienne Colombo, Regina Maria
    Guerra, Ana Cervigni
    de Paula Pessoa, Marcelo Schneck
    [J]. 2013 ASE/IEEE INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING (SOCIALCOM), 2013, : 1030 - 1033
  • [2] Measuring Security
    Bilbao, Alfonso
    Bilbao, Enrique
    [J]. 2013 47TH INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2013,
  • [3] Measuring Security
    Stolfo, Sal
    Bellovin, Steven M.
    Evans, David
    [J]. IEEE SECURITY & PRIVACY, 2011, 9 (03) : 60 - 65
  • [4] Measuring job security
    Nardone, T
    Veum, J
    Yates, J
    [J]. MONTHLY LABOR REVIEW, 1997, 120 (06) : 26 - 33
  • [5] Measuring systems security
    Bayuk, Jennifer
    Mostashari, Ali
    [J]. SYSTEMS ENGINEERING, 2013, 16 (01) : 1 - 14
  • [6] Measuring Security Practices
    DeKoven, Louis F.
    Randall, Audrey
    Mirian, Ariana
    Akiwate, Gautam
    Blume, Ansel
    Saul, Lawrence K.
    Schulman, Aaron
    Voelker, Geoffrey M.
    Savage, Stefan
    [J]. COMMUNICATIONS OF THE ACM, 2022, 65 (09) : 93 - 102
  • [7] Measuring the level of security introduced by security patterns
    Fernandez, Eduardo B.
    Yoshioka, Nobukazu
    Washizaki, Hironori
    VanHilst, Michael
    [J]. FIFTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY: ARES 2010, PROCEEDINGS, 2010, : 565 - 568
  • [8] Measuring Security Practices and How They Impact Security
    DeKoven, Louis F.
    Randall, Audrey
    Mirian, Ariana
    Akiwate, Gautam
    Blume, Ansel
    Saul, Lawrence K.
    Schulman, Aaron
    Voelker, Geoffrey M.
    Savage, Stefan
    [J]. IMC'19: PROCEEDINGS OF THE 2019 ACM INTERNET MEASUREMENT CONFERENCE, 2019, : 36 - 49
  • [9] A THEORETICAL FRAMEWORK FOR MEASURING THE VALUE OF JOB SECURITY WITH AN APPLICATION TO THE CANADIAN-PUBLIC-SERVICE
    NEDZELA, M
    BALCER, Y
    [J]. INFOR, 1982, 20 (2-3) : 102 - 115
  • [10] Measuring Security: A Step Towards Enhancing Security of System
    Jaiswal, Shruti
    Gupta, Daya
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS IN THE SERVICE SECTOR, 2018, 10 (01) : 28 - 53