Twitter LinkedIn

Compositional Risk Assessment

and Security Testing of Networked Systems

  • Innovations
  • CRSTIP
  • Consortium
  • Events
  • Publications
  • Deliverables
  • Contact
 
Menu
  • Innovations
  • CRSTIP
  • Consortium
  • Events
  • Publications
  • Deliverables
  • Contact
 
 
 
 
 
Seventh Framework Programme

Recent Posts

  • ETSI Guide EG203251 Available
  • Year 3 Project Deliverables now Available
  • Security Testing and Risk Assessment for Large-Scale Networked Systems using ARIS
  • A RASEN Innovation for Security Pattern and Model-Based Vulnerability Testing
  • Artefacts supporting risk based security testing

PAGES

  • Innovations
  • CRSTIP
  • Consortium
  • Events
  • Publications
  • Deliverables
  • Contact
  • The European project RASEN is launched

    The European research project RASEN (Compositional Risk Assessment and Security Testing of Networked Systems) has now officially been launched.

    The main objective of the project is to develop a tool-supported method for risk-based security testing. The method is intended help software developing organisations to improve the security of their software both from a business level and from a technical perspective.  The business level risk assessment enables reasoning about non-technical aspects such as risks to business level assets and liability issues, whereas as the security testing at the technical level helps uncover security vulnerabilities which are difficult to identify at the business level alone.

    Traditionally, security risk assessment and security testing has been conduced as isolated activities. However, their combination is mutually beneficial. On the one hand, going from the business level to the technical level, the security risk assessment can be used to guide the security testing by focusing the testing on the parts of the system that have the highest risk. On the other hand, going from the technical level to the business level, security test results can be used to verify the correctness of the risk picture, and analyzed in terms of impact on business-level risks.

    The RASEN project will specifically target large scale systems by supporting (1) breaking the security assessment into smaller parts which can be carried out separately and later composed to form the global assessment; (2) reuse of security assessment results when performing security assessments continuously as part of an iterative business process.

    In summary, the method that will be developed in the RASEN project is intended to help organisations that develop or operate software systems by:

    • Guiding the security testing by business-level technical as well as non-technical considerations through systematic derivation of security test cases from risk assessment results.
    • Helping decision makers understand what technical security test results mean in terms of risks and legal obligations by aggregating security test results to the risk assessment level.
    • Offering a global view of the security of large scale systems through the combination of partial security assessments.
    • Helping decision makers in showing that they are compliant with legal norms of relevance to security.
    • Providing rapid and continuous security assessment and large scale systems.

    The RASEN project started 1. October 2012 and is planned to last for 3 years. The RASEN consortium consists of seven partners from Norway, Germany, France and Romania, with expertise in the areas of risk assessment, software testing, and law. The project has been funded by the European Commission within the context of the Framework Program 7.

    19 Dec 2012 / rasen_adm / Comments Off

    Categories: News

    RASEN kick-off meeting SASSI13 – Security Assessment for Systems, Services and Infrastructures

 

Recent Posts

  • ETSI Guide EG203251 Available
  • Year 3 Project Deliverables now Available
  • Security Testing and Risk Assessment for Large-Scale Networked Systems using ARIS
  • A RASEN Innovation for Security Pattern and Model-Based Vulnerability Testing
  • Artefacts supporting risk based security testing
  • Artefacts supporting planned security testing
  • Security testing – Continuous risk-based testing
  • Risk assessment – Real time assessment
  • Risk assessment – Check list assessment
  • Legal and compliance assessment – Systematic compliance assessment

Tag Cloud

Pages

  • Consortium
  • Contact
  • CRSTIP Web Tool
  • Deliverables
  • Detailed information regarding RASEN support for the key areas and levels below is available by selecting them. Supported areas have a blue background
  • Events
  • Home
  • Innovations
  • Publications
  • Statistics

Categories

  • crstipv2
    • Legal and compliance assessment
      • Ad-hoc compliance assessment
      • Check list based compliance assessment
      • Systematic and risk driven
      • Systematic compliance assessment
    • Risk assessment
      • Checklist assessment
      • Qualitative Assessment
      • Quantitative assessment
      • Real time assessment
    • Security testing
      • Continuous risk-based testing
      • Planned testing
      • Risk based testing
      • Unstructured testing
    • Tool support
      • Integrated
      • None
      • Partially Integrated
      • Stand Alone
  • News

Copyright © 2013 RASENTheme created by PWT. Powered by WordPress.org