From Application Security Verification Standard (ASVS) to Regulation Compliance: A Case Study in Financial Services Sector

V. Tan, C. Cheh, Binbin Chen
{"title":"From Application Security Verification Standard (ASVS) to Regulation Compliance: A Case Study in Financial Services Sector","authors":"V. Tan, C. Cheh, Binbin Chen","doi":"10.1109/ISSREW53611.2021.00046","DOIUrl":null,"url":null,"abstract":"The OWASP Application Security Verification Standard (ASVS) is a widely used web application development guideline regarding the technical security controls and secure development requirements. While software development teams refer to ASVS to secure their applications and development process, they also need to ensure the compliance of various security related regulations, including sector-specific ones. In this work, we study the synergy of these two activities, i.e., by following ASVS, how does a development team position their developed applications in meeting those regulation requirements. We take the highly regulated financial services sector as a case study. In particular, we look at two recent guidelines published by Monetary Authority of Singapore (MAS) - the Technology Risk Management (TRM) guidelines and Notice 655 Cyber Hygiene. We developed a systematic approach to map ASVS to those two sector-specific regulations. Our results show that by adopting ASVS, a development team can achieve a high degree of regulatory compliance (38.6 % for the MAS TRM guidelines and 47.6% for the MAS Notice 655, respectively). That demonstrates the viability of using international standards (like ASVS) to support compliance with the two sector-specific regulations. In addition, our mapping approach can be useful for organizations to support their compliance efforts.","PeriodicalId":385392,"journal":{"name":"2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)","volume":"34 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISSREW53611.2021.00046","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

The OWASP Application Security Verification Standard (ASVS) is a widely used web application development guideline regarding the technical security controls and secure development requirements. While software development teams refer to ASVS to secure their applications and development process, they also need to ensure the compliance of various security related regulations, including sector-specific ones. In this work, we study the synergy of these two activities, i.e., by following ASVS, how does a development team position their developed applications in meeting those regulation requirements. We take the highly regulated financial services sector as a case study. In particular, we look at two recent guidelines published by Monetary Authority of Singapore (MAS) - the Technology Risk Management (TRM) guidelines and Notice 655 Cyber Hygiene. We developed a systematic approach to map ASVS to those two sector-specific regulations. Our results show that by adopting ASVS, a development team can achieve a high degree of regulatory compliance (38.6 % for the MAS TRM guidelines and 47.6% for the MAS Notice 655, respectively). That demonstrates the viability of using international standards (like ASVS) to support compliance with the two sector-specific regulations. In addition, our mapping approach can be useful for organizations to support their compliance efforts.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
从应用安全验证标准(ASVS)到法规遵从:金融服务行业的案例研究
OWASP应用程序安全验证标准(ASVS)是一个广泛使用的关于技术安全控制和安全开发需求的web应用程序开发指南。当软件开发团队引用ASVS来保护他们的应用程序和开发过程时,他们还需要确保遵守各种与安全相关的法规,包括特定于部门的法规。在这项工作中,我们研究这两个活动的协同作用,也就是说,通过遵循ASVS,开发团队如何定位他们开发的应用程序以满足那些规则需求。我们以监管严格的金融服务业为例进行研究。我们特别关注新加坡金融管理局(MAS)最近发布的两项指导方针——技术风险管理(TRM)指导方针和655号网络卫生通知。我们开发了一种系统的方法,将ASVS映射到这两个特定行业的法规。我们的结果表明,通过采用ASVS,开发团队可以实现高度的法规遵从性(分别为MAS TRM指南38.6%和MAS通知655 47.6%)。这证明了使用国际标准(如ASVS)来支持遵守这两个行业特定法规的可行性。此外,我们的映射方法对于组织支持其遵从性工作非常有用。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
An efficient dual ensemble software defect prediction method with neural network Genetic Algorithm-based Testing of Industrial Elevators under Passenger Uncertainty Predicting gray fault based on context graph in container-based cloud Aging and Rejuvenation Models of Load Changing Attacks in Micro-Grids Sensitivity Analysis of Software Rejuvenation Model with Markov Regenerative Process
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1