
Recent Posts
-
The European project RASEN is launched
The European research project RASEN (Compositional Risk Assessment and Security Testing of Networked Systems) has now officially been launched.
The main objective of the project is to develop a tool-supported method for risk-based security testing. The method is intended help software developing organisations to improve the security of their software both from a business level and from a technical perspective. The business level risk assessment enables reasoning about non-technical aspects such as risks to business level assets and liability issues, whereas as the security testing at the technical level helps uncover security vulnerabilities which are difficult to identify at the business level alone.
Traditionally, security risk assessment and security testing has been conduced as isolated activities. However, their combination is mutually beneficial. On the one hand, going from the business level to the technical level, the security risk assessment can be used to guide the security testing by focusing the testing on the parts of the system that have the highest risk. On the other hand, going from the technical level to the business level, security test results can be used to verify the correctness of the risk picture, and analyzed in terms of impact on business-level risks.
The RASEN project will specifically target large scale systems by supporting (1) breaking the security assessment into smaller parts which can be carried out separately and later composed to form the global assessment; (2) reuse of security assessment results when performing security assessments continuously as part of an iterative business process.
In summary, the method that will be developed in the RASEN project is intended to help organisations that develop or operate software systems by:
- Guiding the security testing by business-level technical as well as non-technical considerations through systematic derivation of security test cases from risk assessment results.
- Helping decision makers understand what technical security test results mean in terms of risks and legal obligations by aggregating security test results to the risk assessment level.
- Offering a global view of the security of large scale systems through the combination of partial security assessments.
- Helping decision makers in showing that they are compliant with legal norms of relevance to security.
- Providing rapid and continuous security assessment and large scale systems.
The RASEN project started 1. October 2012 and is planned to last for 3 years. The RASEN consortium consists of seven partners from Norway, Germany, France and Romania, with expertise in the areas of risk assessment, software testing, and law. The project has been funded by the European Commission within the context of the Framework Program 7.
19 Dec 2012 / rasen_adm / Comments Off
Categories: News
RASEN kick-off meeting SASSI13 – Security Assessment for Systems, Services and Infrastructures
