search menu icon-carat-right cmu-wordmark

Considering Operational Security Risk During System Development

January 2007 Article
Carol Woody, Christopher J. Alberts

In this article, the authors examine OCTAVE, an operational security-risk methodology, and apply it to security-related risks during system development.

Abstract

The operational security of software-intensive systems is closely linked to the practices and techniques used during system design and development. The authors examine OCTAVE, an operational security-risk methodology, and apply it to the security-related risks identifiable while developing software-intensive systems.