The security systems development life cycle (secsdlc), Computer Network Security

The Security Systems Development Life Cycle (SecSDLC)

The same phases which is used in traditional SDLC can be adapted to support specialized implementation of IS project,At its center, implementing information security includes Identifying of specific threats and creating special controls to counter them.

 Investigation

The investigation phase of SecSDLC starts with a directive from upper management, dictating or Identifies the process, goals, outcomes, budget and constraints of project. This phase begins with the enterprise information security policy that outlines the implementation of a security program within organization. Organizational feasibility analysis can be performed to determine whether the organization has resources and commitment required to conduct a successful security analysis and design.

Analysis

In analysis phase, the documents from investigation phase are studied properly. The development team conducts a preliminary analyzes existing security policies or programs, along with the documented current threats and connected controls. This phase includes analysis of relevant legal issues also which could impact design of the security solution. The risk management task begins from this stage.

 Logical Design

The logical design phase creates and develops blueprints for information security and examines and implements key policies which influence the decisions. The team plans the incident response actions to be taken in the event of the partial or catastrophic loss. The planning answers following questions:

•    Continuity planning – How will business they continue in the event of loss?
•    Incident response - What steps should be taken when the attack is observed?
•    Disaster recovery – What should be done to recover information and vital systems immediately when the disastrous event has occured?

 Physical Design


In physical design phase, the information security technology required to support the blueprint outlined in the logical design can be evaluated, alternative solutions generated, feasibility study and final design agree upon.

 Implementation

In implementation phase in of SecSDLC is similar to that of the traditional SDLC. The security solutions are acquired, tested, implemented, and tested again. Personal issues are evolved, and specific training and education programs are conducted. Finally, the whole tested package is presented to upper management for the final approval.

Maintenance and Change

In this phase, given the current ever changing threat environment. Reparation and restoration of information is a constant duel with the unseen adversary. Information security profile of the organization requires constant adaptation as new threats emerge and old threats expand.

Posted Date: 10/8/2012 5:33:37 AM | Location : United States







Related Discussions:- The security systems development life cycle (secsdlc), Assignment Help, Ask Question on The security systems development life cycle (secsdlc), Get Answer, Expert's Help, The security systems development life cycle (secsdlc) Discussions

Write discussion on The security systems development life cycle (secsdlc)
Your posts are moderated
Related Questions
Categories of Controls Controlling risk through mitigation, avoidance or transference is accomplished by implementing controls. There are 4 effective approaches to select the co

DATAGRAM REASSEMBLY Recreation of original datagram is known as reassembly. Ultimate receiver acts reassembly as given below.Fragments can reach out of order. Header bit check

Evaluations, Assessment, and Maintenance of Risk Controls When the control strategy has been implemented, it should be monitored and measured on an ongoing basis to determine ef

MAC Address The address for a machine as it is identified at the Media Access Control (MAC) layer in the network structure. MAC address is generally stored in ROM on the n

Question: (a) Which type of attacker represents the most likely and most damaging risk to your network? (b) What is the basic reason that social engineering attacks succeed?

IDS Intrusion is a attack on information assets in which instigator attempts to gain entry into or disrupt normal system with harmful intent Incident response is an identificatio

Question a) From the capture below: Give the datagram source IP address, upper layer protocol, Total length in decimal and header checksum in hexadecimal; the segment source po

Routers They transfer packets among multiple interconnected network machines (i.e. LANs of different kind). They perform in the data link, physical and network layers. They ha

Cipher Methods There are 2 methods of encrypting plaintext: • Bit stream method – every bit in the plaintext bit is transformed into a cipher bit one bit at a time. • Block cip

Describe the important features of application layer. The features of the application layer are as follows. 1. Efficient User Interface Design is explained below: Appli