• DocumentCode
    1065714
  • Title

    Risk analysis in software design

  • Author

    Verdon, Denis ; McGraw, Gary

  • Volume
    2
  • Issue
    4
  • fYear
    2004
  • Firstpage
    79
  • Lastpage
    84
  • Abstract
    Risk analysis is, at best, a good general-purpose yardstick by which we can judge our security design´s effectiveness. Because roughly 50 percent of security problems are the result of design flaws, performing a risk analysis at the design level is an important part of a solid software security program. Taking the trouble to apply risk-analysis methods at the design level for any application often yields valuable, business-relevant results. The risk analysis process is continuous and applies to many different levels, at once identifying system-level vulnerabilities, assigning probability arid impact, arid determining reasonable mitigation strategies. The paper looks at how, by considering the resulting ranked risks, business stakeholders can determine how to manage particular risks and what the most cost-effective controls might be.
  • Keywords
    risk analysis; security; software engineering; design-level analysis; good judgement call; impacts; probability; risk analysis; software design; threats; vulnerabilities; Acceleration; Computer security; Costs; Cryptography; Data security; Hardware; Life testing; Probability; Risk analysis; Software design; 65; abuse cases; misuse cases; software design; software development;
  • fLanguage
    English
  • Journal_Title
    Security & Privacy, IEEE
  • Publisher
    ieee
  • ISSN
    1540-7993
  • Type

    jour

  • DOI
    10.1109/MSP.2004.55
  • Filename
    1324606