抽象的

SECURITY ASSURANCE THROUGH EFFICIENT EVENT LOG AND AUDIT TRIALS

S. K. Pandey, K. Mustafa

In current digital era, business organizations are using Information and Communications Technologies (ICT) for better support of their goals. There is no doubt to say that every function of the business modules is either dependent or going to be reliant on IT related tools and techniques. This facilitates organizations on one side but at the same time, it has some big challenges also from the security perspective. Insecure software is already proving to be a threat to the financial, defense, energy, and other critical important applications, which are increasing risk in direct or indirect way. To overcome these issues, a variety of methodologies have been deployed for developing secure software, but, on the other hand, attackers are continuously exploiting vulnerabilities to compromise security. Research studies reveal that security cannot be added in developed software rather it should be introduced right from the beginning in the Software Development Life Cycle (SDLC). To achieve this objective, security measures must be embedded throughout the SDLC phases and starting from the requirements phase itself. ‘Event Log and Audit Trails’ is globally accepted as one of the prominent security requirements. Appropriate level of this requirement may well enforce security features and hence, ensure security for deployed software. The paper proposes a checklist, which may enable the assessment of the appropriateness of ‘Event Log and Audit Trails’ and lead to counter/additional measures for security assurance.

索引于

谷歌学术
学术期刊数据库
打开 J 门
学术钥匙
研究圣经
引用因子
电子期刊图书馆
参考搜索
哈姆达大学
学者指导
国际创新期刊影响因子(IIJIF)
国际组织研究所 (I2OR)
宇宙

查看更多