Visible to the public Cybersecurity Certification for Agile and Dynamic Software Systems – a Process-Based Approach

TitleCybersecurity Certification for Agile and Dynamic Software Systems – a Process-Based Approach
Publication TypeConference Paper
Year of Publication2020
AuthorsLotz, Volkmar
Conference Name2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
KeywordsAgile development, certification, composability, computer security, Dynamical Systems, IEC standards, ISO standards, Predictive Metrics, process control, pubcrawl, Resiliency, security, Software, Standards organizations
AbstractIn this extended abstract, we outline an approach for security certification of products or services for modern commercial systems that are characterized by agile development, the integration of development and operations, and high dynamics of system features and structures. The proposed scheme rather evaluates the processes applied in development and operations than investigates into the validity of the product properties itself. We argue that the resulting claims are still suitable to increase the confidence in the security of products and services resulting from such processes.
DOI10.1109/EuroSPW51379.2020.00021
Citation Keylotz_cybersecurity_2020