WP7 – Security and Privacy Claims

 Coordinated by
UMU (M01-M12)

Objective

The main objective of this work package is to develop a security certification methodology combining risk assessment and testing to evaluate a system over a series of security and privacy claims based on objective metrics, allowing harmonisation and mutual recognition based on evidence that quantify the level of trust.

The specific goals of WP7 are to:

  1. Identify suitable security and privacy metrics and claims to evaluate the security and privacy of a system
  2. Develop a security certification methodology using the identified security and privacy metrics and claims.

Deliverables

Outcomes

Fuzzing Tool

Fuzzing Tool will test System Under Test (SUT) security vulnerabilities or inputs not contemplated that could compromise the system; as a black-box process, by using unintended or incorrect inputs and monitoring their corresponding outputs.

ResilBlockly

This exploitation result consists in cybersecurity consultancy services supported by ResilBlockly (former Blockly4SoS), a Model-Driven Engineering tool that has been developed in the context of BIECO.

Security evaluation methodology

Security evaluation methodology to evaluate the security of an ICT system. The methodology is based on standards such as ISO 31000 standard for Risk Management, the ISO 29119 standard for Security Testing or the MUD standard…

Extended MUD file

The extended Manufacturer Usage Description (MUD) file is an extension of the MUD Internet Engineering Task Force (IETF) standard…

BIECO Project

SUBSCRIBE and become part of the BIECO community!

We don’t spam!

Share This