Information Security Management Framework for Web Applications Development

被引:0
|
作者
Soares, Cleberton Carvalho [1 ]
da Silva, Paulo Caetano [2 ]
Soares, Natanael Dantas [3 ]
机构
[1] Fed Inst Sergipe, Aracaju, Sergipe, Brazil
[2] Univ Salvador, UNIFACS, Salvador, BA, Brazil
[3] Borges de Mendonca Coll, Law, Florianopolis, SC, Brazil
来源
关键词
Information security management; Web applications; framework; software engineering;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information is an influential variable in corporate environment, potentially rich and fundamental for strategic planning. Therefore, it should not be exposed to risks of improper access and unauthorised changes. Among the information technologies that manipulate and exchange information, Web technologies represent a paradigm of software development increasingly used, which make use of the internet as a means of communication for informations exchange. The Internet is, admittedly, an inhospitable and unmanaged environment. However, in addition to issues of internet-related insecurity issues, the neglect or malpractice of system analysts and programmers can be decisive for delivering software products that do not properly exploit the use of information security mechanisms, making attacks on information succeed. This article aims to propose an information security management framework in order to support professionals and companies that develop Web applications for them to adopt, institutionalize and train in good practices on the use of encryption, digital signature, digital certificate and access control. The adoption of this proposed framework is expected to contribute for Web applications to get higher levels of information protection.
引用
收藏
页码:98 / 108
页数:11
相关论文
共 50 条
  • [1] Security Testing Framework for Web Applications
    Alrawais, Layla Mohammed
    Alenezi, Mamdouh
    Akour, Mohammad
    [J]. INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2018, 6 (03) : 93 - 117
  • [2] A FRAMEWORK FOR INFORMATION SECURITY MANAGEMENT
    Angheluta, Dragos-Ionut
    Lupu, Luminita-Mihaela
    [J]. FROM MANAGEMENT OF CRISIS TO MANAGEMENT IN A TIME OF CRISIS, 2016, : 2 - 16
  • [3] A framework for the management of information security
    Leiwo, J
    Zheng, YL
    [J]. INFORMATION SECURITY, 1998, 1396 : 232 - 245
  • [4] Framework for the development of web applications
    Mathkour, H
    Shah, A
    [J]. WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL 1, PROCEEDINGS: INFORMATION SYSTEMS DEVELOPMENT, 2001, : 480 - 485
  • [5] An Ontological Framework for Healthcare Web Applications Security
    Alenezi, Mamdouh
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (06) : 511 - 516
  • [6] Web based Integrated Framework for Security Applications
    Veeraraghavan, Sampathkumar
    Panetta, Karen
    Agaian, Sos
    [J]. IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS (SMC 2010), 2010,
  • [7] Implementation of Security Framework for Multiple Web Applications
    Patil, Anita
    Pandit, Rakesh
    Patel, Sachin
    [J]. 2014 INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND INFORMATICS (ICCCI), 2014,
  • [8] A conceptual framework for information security management
    Finne, T
    [J]. COMPUTERS & SECURITY, 1998, 17 (04) : 303 - 307
  • [9] A framework for the management of information security risks
    Jones, A.
    [J]. BT TECHNOLOGY JOURNAL, 2007, 25 (01) : 30 - 36
  • [10] An Integrated Framework for Information Security Management
    Ma, Qingxiong
    Schmidt, Mark B.
    Pearson, J. Michael
    [J]. REVIEW OF BUSINESS, 2009, 30 (01): : 58 - 69