New measurement method for web application security
Suhono Harso Supangkat, Hendro Gunawan · International Conference on Communications · 2006
This paper propose new measurement method also know as S-vector based on two security standards ISO 17799:2005 and SSE-CMM v3.0, which can be an assessment tool for web application security. S-vector consists of three components, there are procedural, structural and technical aspects. Result suggests that security controls outlined in ISO 17799:2005 can be incorporated into S-vector as procedural and structural components. ISO 17799 controls may be mapped to specific data, specific web applications, or across multiple systems. Eleven of SSE-CMM's security-related process areas can be implemented into an S-vector implementation by providing a framework in which to administer procedural components. The capability levels of SSE-CMM measure a process' maturity and can be integrated into S-vector if scoring objectives are to measure process maturity and not the quality of process output.