Security in MTS 14th May2013 SIG Report

Slides:



Advertisements
Similar presentations
International Standards for Software & Systems Documentation Ralph E. Robinson R 2 Innovations.
Advertisements

SECURITY SIG IN MTS 28 TH JANUARY 2015 PROGRESS REPORT Fraunhofer FOKUS.
Symmetric Key Management Books Development Plan Daniel Fischer (ESA) Ignacio Aguilar Sanchez (ESA) CCSDS Spring Meeting 2010 | Portsmouth, VA.
SQA System Overview Chapter 4. Where we have been so far, Where we are going Where do software errors come from? What is quality? How can quality be measured?
Standards to be Revised During S2ESC Management Board July 29, 2008 Revised July 18, 2008 Dave Schultz Malia Zaman.
COM606 Software Process Engineering and on the Portal Introduction.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All ICT Accessibility Standardization Dr. Jim Carter, ISACC Document No: GSC16-PLEN-57r2 Source: ISACC.
Project Scope Management Information Technology Project Management, Fifth Edition Note: some slides have been removed from the author’s original presentation.
1 HARMONIZATION OF ISO/IEC AND IEEE STD 1219 Thomas M. Pigoski Paul R. Croll IEEE Computer Society Montreal, May 2003.
Progress report for ISO/IEC DTR Metadata Mapping Procedure(MMP) October, 2012 Tae-Sul Seo and Sung-Joon Lim 1.
SC7 - IEEE CS Activity Status Report – T. Doran 6 November 2007 To: J. Walz IEEE CS SAB
Doc.: IEEE r Submission April 2007 Michael Lynch, Nortel 22 March Agenda Opening comments and attendance Schedule of meetings/deadlines.
Statistical Data and Metadata Exchange SDMX Metadata Common Vocabulary Status of project and issues ( ) Marco Pellegrino Eurostat
19th January 2012 Don Wells (Hess)
Middle Fork Project Relicensing Process Plan April 25, 2006.
SAB Sponsor Progress Report Paul R. Croll Software and Systems Engineering Standards Committee (S2ESC) February 3, 2016.
ITIL Project Change Management Workshop 7 February 2007
Work Item “Patterns in Test Development (PTD)” Re-start Meeting 17 March, Berlin Helmut Neukirchen Institute for.
Automated Test Design ™ © 2011 Conformiq, Inc. CONFORMIQ DESIGNER MBT Working Meeting Report Stephan Schulz MTS#56, Göttingen.
SECURITY SIG IN MTS Fraunhofer FOKUS Tallinn, 4-5 October 2011 Berlin, 15 December 2011 update.
SECURITY SIG IN MTS 02 ND OCTOBER 2013 PROGRESS REPORT Fraunhofer FOKUS.
Jürgen Großmann, Fraunhofer FOKUS
ISA-SP99: Security for Industrial Automation and Control Systems
Security SIG#6‘ in MTS 26th November 2012 Agenda & report
August ICA Agenda Time Topic 8:00 – 8:15
James W. Moore Liaison Representative IEEE Computer Society June 2004
ISO/IEC JTC 1/SC 7 Working Group 42 - Architecture Johan Bendz
Software Verification and Validation
Computerized Systems in Clinical Research
CONFORMIQ DESIGNER 2012 MTS #55 Meeting.
Security SIG in MTS 05th November 2013 DEG/MTS RISK-BASED SECURITY TESTING Fraunhofer FOKUS.
Automated Interoperability Testing
Security SIG in MTS Fraunhofer FOKUS Tallinn, 4-5 October 2011.
Automated Interoperability Testing
22 March Agenda Opening comments and attendance
Status Report November 2007
Berlin, 15 December 2011 update
DEPLOYMENT OF MODEL-BASED AUTOMATED TESTING INFRASTRUCTURE IN A CLOUD
Sophia Antipolis, 25 January 2012
Draft Article 8 MSFD assessment guidance
Security in MTS 19th September 2012 SIG Report
ETSI NFV ISG IM/DM Modelling progress Report
Quality assurance : state of progress
Security SIG in MTS Fraunhofer FOKUS Tallinn, 4-5 October 2011.
IEEE 802 Process for Interactions with ISO/IEC JTC 1/SC 6
Berlin, 15 December 2011 update
Berlin, 15 December 2011 update
CTI Update on LIBSIP and TTCN-3.org
Security SIG#4 in MTS 10th August 2012
Security SIG#4 in MTS 10th August 2012 Report
Security SIG#5 in MTS 19th September 2012 Agenda
IEEE /15 Regulatory SC Warsaw Meeting Plan and Agenda
TOP project – status update for mts#72
Security SIG#7 in MTS 18th January 2013 draft Agenda
IEEE 802 Process for Interactions with ISO/IEC JTC 1/SC 6 & 7
Security SIG in MTS 27th January 2016 Progress Report
ETSI TC MTS TDL SC meeting Reports
Security SIG#6 in MTS 19th November 2012 draft Agenda
UPDATE on SVN & MANTIS Upgrade
Water Directors’ Meeting Working Group D (Reporting) activities
UPDATE on PICS GUIDE (EG ) REVIEW
MTS WG TST STATUS Axel Rennoch MTS#74, Sophia-Antipolis, May 24, 2018.
UPDATE on SVN & MANTIS Upgrade
Axel Rennoch MTS#74, Sophia-Antipolis, May 24, 2018
ETSI MTS#76 Meeting 23-Jan-2019
Accredited Standards Committee C63® - EMC
Axel Rennoch MTS#73, Munich, January 23, 2017
Security in MTS 19th September 2012 SIG Report
UPDATE on PICS GUIDE (EG ) REVIEW
Project Name Here Kick-off Date
Presentation transcript:

Security in MTS 14th May2013 SIG Report Fraunhofer FOKUS

Agenda (14.5.) 4 Participants: I. Bryant, A. Takanen, P. Schmitting, A. Rennoch, (supported by E. Chaulot-Talmon) ISO SC27 & ETSI Security workshop presentation 26th April Idea: MTS & SC27/WG3 Liaison TODO: send request (with current working documents) Discussion of draft document

SC27 WG3 liaison (to be decided) ISO/IEC 24759 Test requirements for cryptographic modules ISO/IEC 30127: Detailing software penetration testing under ISO/IEC 15408 and ISO/IEC 18045 vulnerability analysis ISO/IEC TR 20004 Refining software vulnerability analysis under ISO/IEC 15408 and ISO/IEC 18045 for ETSI 101583 (Terminology) for ETSI 201581 (Security guidelines) WG3 is interested in ETSI 101582 (case studies)

SC27 WG4 liaison (to be decided) ISO/IEC 27034-4 Application security validation for ETSI 201581 (Security guidelines)

WI status and schedules Terminology and Concepts (Ari): 3rd draft (word document) considered comments and updates -> need to be reviewed (CTI or E2NA) Case studies (Ari/Jürgen):  Plan: early draft with two case studies (Diamonds) 2-3 more case studies expected September (from Diamonds and Spacios)

WI status and schedules Design guide V&V (Scott/Ian): -> new draft available with new input from Ian and Scott (still early draft) Plan: stable draft and review in September. Security Testing Methodology (Scott): Plan: results to be integrated in V&V

„Terminology“ (3rd draft) 3 Definitions, symbols and abbreviations 4 Introduction to security testing 4.1 Types of security testing 4.2 Penetration testing tools 4.3 Test verdicts in security testing 5 Security test requirements 6 Functional security testing 7 Performance testing for security 8 Fuzz testing 9 Security Testing activities mapped to SDLC

„Case studies“ (1st draft) Project case studies from: DIAMONDS project G&D Banking (available) Accurate (available) Radio Automotive More? SPACIOS project tbd

„Case studies“ (1st draft) For each of the case studies a similar structure of the description is planned. It will consist of the following parts: Characteriazation Background (challenges) System under Test Risk Analysis Security Testing Approaches Applied approaches Comparison with SoA tools/techniques Results so far Expectations Test Results Exploitation (value of techniques)

Next steps Jürgen/Peter: complete Diamonds case study input Ari/Peter: Invite E2NA and CTI to review Terminology & Concepts (after stable draft) ??? Ian/Scott: provide stable draft for September MTS: request formal liaison with ISO SC27/WG3&4 Next SIG meetings Discussion of current drafts in MTS#59 No SIG meeting planned (only if new drafts available)