Stakeholder Value Driven Threat Modeling for Off the Shelf Based Systems

  • Authors:
  • Yue Chen

  • Affiliations:
  • University of Southern California, Los Angeles, USA

  • Venue:
  • ICSE COMPANION '07 Companion to the proceedings of the 29th International Conference on Software Engineering
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

As the trend of the usage of third party Commercial-Off-The-Shelf (COTS) and open source software continuously increases [2], COTS security has become a major concern for many organizations whose daily business extensively relies upon a healthy IT infrastructure. But, according to the 2006 CSI/FBI computer criminal survey, 47% of the surveyed organizations only spent no more than 2% of the IT budget in security. Often, competing with limited IT resources and the fast changing internet threats, the ability to prioritize security vulnerabilities and address them efficiently has become a critical success factor for every security manager.