Berlin, 15 December 2011 update Security SIG in MTS Fraunhofer FOKUS Tallinn, 4-5 October 2011 Berlin, 15 December 2011 update Sphia Antipolis 13 March 2012 Göttingen, 15 May 2012
Work item overview & status Discussion of work progress Agenda SIG#3 Round Call Work item overview & status Discussion of work progress Relation to other groups/events Next steps, perspectives: E2NA, Security workshop, SIG#4?
Recall of SIG history Plan for Security-SIG in MTS (Tallin, 10/2011) SIG#1 (Berlin, 12/2011) Discussion on scope: specification, analysis, testing 3 NWIs „wording“: terminology, case study experiences (2nd half 2012), design guide Appointment of rapporteurs: Ari T. and Scott C. SIG#2 (Sophia, 03/2012) Start of Wiki initiative about terminology Draft on security design guide (with lifecycle diagram) Need for more promotion
Security Testing Terminology and Concepts - STATUS not a pure listing of definitions but an introduction of terms using full text to avoid copyright issues and to allow comparison without “re-definition“ Abstract TBD Introduction (focus/promote new testing areas) TBD Basic terminology listing available, text TBD Risk Assessment (TVRA) first input, TBD Functional Testing general overview available, but specific parts TBD Penetration Testing TBD Vulnerability Testing TBD Performance Testing TBD Fuzzing available Please JOIN & Contribute: https://collab.codenomicon.com/collab/codeetsi/
SIG#2 APs Invite people from other ETSI TC‘s: AP: Scott invite OCG_security (done) Wiki text should not only be a list of words, but with text and tutorial character (in progress) Invite CTI to check Contents (open) Steve: the introduction part should focus/promote new testing areas (open)
SIG#2 reminders Steve: opportunity for ETSI Security workshop MTS to chair a security testing session Start to plan topics, areas of interests CfP expected in September Discussion on the lifecycle: no normative agreement on penetration testing available, Ian provides new lifecycle diagram -> design guide
SIG future work Allocate responsible people for Wiki sections? Relations to E2NA-security? SIG continuation to be decided: SIG#4 phone call only (July)? SIG#5 before MTS#57 (18.09.)?