Product Incremental Security Risk Assessment Using DevSecOps Practices


연구 분야: Software Development



학회: European Symposium on Research in Computer Security


초록

Security risk assessment is often a heavy manual process, making it expensive to perform. DevOps, that aims at improving software quality and speed of delivery, as well as DevSecOps that augments DevOps with the automation of security activities, provide tools and procedures to automate the risk assessment. We propose a solution to integrate risk assessment with DevSecOps activities and processes in order to make the risk assessment more continuous and automated. The solution is illustrated on a use case where the firewall of a robot vehicles is updated while risk assessment is done in an iterative manner. This approach aims at facilitating assessment (and certification such as EUCC) processes.


Author Profile
Sébastien Dupont

CETIC Charleroi Belgium

Belgium
Author Profile
Artsiom Yautsiukhin

CNR Rome Italy

Italy
Author Profile
Guillaume Ginis

CETIC Charleroi Belgium

Belgium

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 Italy, Belgium
사이트 Springer
좋아요 수 0

연관 논문 목록 (152건)