DocumentCode :
2059144
Title :
A Methodological Tool for Asset Identification in Web Applications: Security Risk Assessment
Author :
Romero M, B.D. ; Haddad, Hisham M. ; Molero A, J.E.
Author_Institution :
Gen. Formation & Sci. Dept., Simon Bolivar Univ., Sartenejas, Venezuela
fYear :
2009
fDate :
20-25 Sept. 2009
Firstpage :
413
Lastpage :
418
Abstract :
Security risk assessment in Web Engineering is an emerging discipline, where security is given a special attention, allowing software engineers to develop high quality and secure Web based applications. A preliminary study revealed that asset identification (and evaluation) is an essential phase in risk assessment practices. This phase represents a degree of complexity and is the primary activity in the assessment process. This work focuses on asset identification and contributes to security risk assessment, which is essential part of software security. Specifically, the research goal is to design a methodological tool (instrument) for asset identification in web applications for the purpose of risk assessment. The proposed tool helps identify assets with security risks in Web applications. The tool involves direct observations and survey questionnaires as data collection techniques used for this work. The research methodology is based on qualitative and quantitative analysis of a case study that focused on Web based application for student opinion survey coordination (EOE) developed in Simoacuten Boliacutevar University, Venezuela. The data analysis required the use of cross case analysis supported by the software application MAXQDA2007, which helps identify assets according to categories, such as environment, software, hardware, information and networks. Under this work, students, faculty, staff, and software developers at Simoacuten Boliacutevar University have participated in this study.
Keywords :
Internet; computer aided analysis; risk management; security of data; software engineering; MAXQDA2007 software; Simoacuten Boliacutevar University project; Web Engineering; asset identification; case study quantitative analysis; cross case analysis; direct observation method; methodological tool design; secure Web based application; security risk assessment; software security; student opinion survey coordination; Application software; Computer security; Data analysis; Data security; Hardware; Information analysis; Information security; Instruments; Risk management; Software engineering; Computer Security; Risks Assessment; Web Applications; Web Engineering;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Engineering Advances, 2009. ICSEA '09. Fourth International Conference on
Conference_Location :
Porto
Print_ISBN :
978-1-4244-4779-4
Electronic_ISBN :
978-0-7695-3777-1
Type :
conf
DOI :
10.1109/ICSEA.2009.66
Filename :
5298880
Link To Document :
بازگشت