System Analysis and Design Using Secure Software Development Life Cycle Based On ISO 31000 and STRIDE. Case Study Mutiara Ban Workshop

Lintang Yuniar Banowosari, Bio Abidzar Gifari · 2019 Fourth International Conference on Informatics and Computing (ICIC) · 2019

Nowadays there are many security problems encountered in information systems. Mutiara Ban Workshop makes a safe system using the SSDLC (Secure Software Development Lifecycle) method. SSDLC is a model used by organizations to build safe applications. The SSDLC process determines how to integrate security into the software development process. ISO 31000 risk management and STRIDE are processes in SSDLC that handle security issues. In ISO 3100 risk management the existing processes establish context, risk identification, risk analysis, risk evaluation, risk care and communication that have their respective functions in overcoming security issues. Then, STRIDE is a process of classifying security issues divided into six classes, namely spoofing, destruction, rejection, information disclosure, denial of service, increase in privileges. The purpose of this study is to analyze and evaluate software published by Mutiara Ban's workshop using SSDLC (Secure Software Development Life Cycle) method and analyze STRIDE threat modeling. The results of the study is system design with information technology consisting of a list of risks and factors that contribute to information technology in Mutiara Ban Workshop and the design can be implemented.

Read the paper · More papers on PaperTik