To main content

Risk-driven Security Testing versus Test-driven Security Risk Analysis

Abstract

It is important to clearly distinguish the combinations of security testing and security risk analysis depending on whether it is viewed from a security testing perspective or a security risk analysis perspective.
The main focus in the former view is security testing in which test objectives are to be achieved, while the main focus in the latter view is security risk analysis with the aim to fulfill risk acceptance criteria. The literature’s
lack of addressing this distinction is accompanied with the lack of addressing two immediate problems within this context, namely the gap between high-level security risk analysis models and low-level security test cases, and the consideration of investable effort. We present initial ideas for methods that address these problems followed by an industrial case study evaluation in which we have gathered interesting results.

Category

Academic article

Language

English

Author(s)

Affiliation

  • University of Oslo
  • SINTEF Digital / Sustainable Communication Technologies

Year

2012

Published in

CEUR Workshop Proceedings

ISSN

1613-0073

Volume

834

Page(s)

5 - 10

View this publication at Cristin