Security Risk Management in E-commerce Systems: A Threat-driven Approach
Abasi-amefon Obot Affia, Raimundas Matulevičius, Alexander Nolte · Baltic Journal of Modern Computing · 2020
E-commerce has transformed the commerce industry as we know it, introducing better purchasing, shipping, and customer services.These business services generate and utilise sensitive information such as customer purchases, financial and personal information which are of high value to attackers.Securing e-commerce systems demands security risk management conscious of evolving security threats.This research work proposes and analyses a threat-driven approach that explores the use of a security threat analysis method -STRIDE to support a selected security risk management method -ISSRM (Information System Security Risk Management) in managing security risk in an e-commerce system.Results of this approach present e-commerce asset identification, threat analysis, and risk identification, with security risk treatment decisions.We discuss these results presenting the benefits of the STRIDE and ISSRM combination.