Threat Mitigation, Monitoring and Management Plan - A New Approach in Risk Management

  • Authors:
  • Vandana Gandotra;Archana Singhal;Punam Bedi

  • Affiliations:
  • -;-;-

  • Venue:
  • ARTCOM '09 Proceedings of the 2009 International Conference on Advances in Recent Technologies in Communication and Computing
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

As we are aware that security environment for software system is changing constantly. Due to expanding connectivity and development of complex software systems risk management is posing serious challenges to the designers. This has become all the more difficult as the attackers are no longer random hackers. Their attacks are targeted, purposeful and organized to drive profit. In view of the increasing vulnerabilities and organized attacks by hackers, we are proposing a new approach to counter these new challenges. In our proposed approach named “Threat mitigation, Monitoring and Management Plan”, we have incorporated important features to meet the security risks at the design level itself. As a first step we have adopted multi-layered defense strategy to make the attacker’s job difficult. Furthermore actors have been associated to monitor the proactive strategy of mitigation. These actors will then manage the risk associated with the threat by taking appropriate actions. For better understanding, in our case study we have applied this new approach to mitigate, monitor and manage the threats to an online banking system.