From the course: Developing Secure Software (2015)

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Software security risk management

Software security risk management

From the course: Developing Secure Software (2015)

Start my 1-month free trial

Software security risk management

- Acknowledging the fact that there's no perfect software security is the first step in mastering software security. The most practical way to handle software security is to manage software security as you have to do when dealing with chronic illness. This is why risk management plays a crucial role in coping with the challenges of software security. Probability and consequences are how risk manifests itself. Probability indicates how possible for a software vulnerability to be exploited by a threat. Consequences measure the extent to which a software security incident can be damaging. For example, we can ask this question: What is the risk of Denial-of-service attack compared to a phishing attack? To answer this question, the first thing to think about is how probable the Denial-of-service and phishing attacks are. The second thing to consider is the consequences of the Denial-of-service and phishing attacks. Therefore, managing software security is the process of managing risks…

Contents