SECURITY ENGINEERING

Developed and Presented By Dr. Mehrdad S SharbafCSUDHComputer Science Department

http://csc.csudh.edu/

The some of the materials are excerpted from Ian Sommerville’s Book, and Ross Anderson’s Book

http://www.csudh.edu/univadv/dateline/archives/20080725/facstaffnews/branding_03.jpg

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

SECURITY ENGINEERING

DEFINING SECURITY BY FUNCTION

RISK AVOIDANCE

DETERRENCE

PREVENTION

DETECTION

RECOVERY

DEFINITION

DEFINITION

APPLICATION/INFRASTRUCTURE SECURITY

SYSTEM LAYERS

30

SECURITY CONCEPTS

EXAMPLES OF SECURITY CONCEPTS

SECURITY THREATS

SECURITY CONTROLS

SECURITY RISK MANAGEMENT

PRELIMINARY RISK ASSESSMENT

30

ASSET ANALYSIS

THREAT AND CONTROL ANALYSIS

SECURITY REQUIREMENTS

LIFE CYCLE RISK ASSESSMENT

EXAMPLES OF DESIGN DECISIONS

TECHNOLOGY VULNERABILITIES

30

KEY POINTS