Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Product Incremental Security Risk Assessment using DevSecOps Practices

Contributo in Atti di convegno
Data di Pubblicazione:
2022
Abstract:
Security risk assessment is often a heavy manual process, making it expensive to perform. DevOps, that aims at improving software quality and speed of delivery, as well as DevSecOps that augments DevOps with the automation of security activities, provide tools and procedures to automate the risk assessment. We propose a solution to integrate risk assessment with the DevSecOps activities and processes in order to make the risk assessment more continuous and automated. The solution is illustrated on a use case where a rewall is updated on robot vehicles while risk assessment is done in an iterative manner. This approach aims at making assessment (and certication such as EUCC) processes easier.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
risk assessment; DevOps; DevSecOps; certification; incremental security; cybersecurity; STRIDE; EUCC
Elenco autori:
Iadarola, Giacomo; Fagnano, Stefano; Martinelli, Fabio; Yautsiukhin, Artsiom
Autori di Ateneo:
MARTINELLI FABIO
YAUTSIUKHIN ARTSIOM
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/444147
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)