70 likes | 289 Vues
Security SIG#6‘ in MTS 26th November 2012 Agenda & report. Fraunhofer FOKUS. Agenda SIG#6/#6bis. Currently registered participants: A. Takanen, S. Pietsch , A. Rennoch, (I. Bryant, S . Cadzow , G . Rethy ) Review/ discussion APs and WI status
E N D
Security SIG#6‘ in MTS26th November 2012Agenda & report Fraunhofer FOKUS
Agenda SIG#6/#6bis • Currently registered participants: A. Takanen, S. Pietsch, A. Rennoch, (I. Bryant, S. Cadzow, G. Rethy) • Review/discussionAPs and WI status • Review of „Security Testing Terminology and Concepts” (word document) • Planningforother WIs • Relation toothergroups/event - E2NA, NTECH? • Next steps:new APs, SIG#7 planning
APs (from SIG#5) • Ari/Axel: create/update ETSI Word document (Terminology & concepts) from Wiki content (allowchangebars etc.) and SIG#6 comments • done (1st draft) • in progress (2nd draft) • Scott, Ari/Ian, Ina/Axel: ETSI Security workshopsubmissionsdone • NN: Invite E2NA and CTI toreviewTerminology & Concepts (after stabledraft) in progress
Review of „Terminology“ • Switch to Word formattoallowchangebars etc.: • Second drafton terminology(Word format) • Multiple additionsby Ari/Miia, Ian, Christian, Steve • Christian (requirements) and Bogdan (TTCN-3) will also contribute • commentsofthecontenttobecommunicatedto Ari • InviteE2NA and CTI toreview Wiki terminology(after stabledraft)
Discussions • Status ofotherWis • Case studies (Ari) • delayed after WI on terminology&conceptsisdone • inputfrome.g. diamonds.org and spacios.eu • Design guide (V&V) in progress (Scott) • Contributionfrom Ian, Jan andotherswelcome • „Security testing methodology“ (Scott) • Will be integrated e.g. as an annex to V&V document • Time schedules • WI-1: stable draft in January • WI-2: early draft in January • WI-3: ?
ETSI Security workshop • Event 16/17.Januaryhttp://www.etsi.org/SECURITYWORKSHOP • Session 8 (2nd day, 4 - 5:30 pm) • Scott: Methods to develop security standards – a review of work old and new in ETSI and why it's important to use • Ari: Security Testing: Terminology, Concepts, Lifecycle (Ian) • Ina: Case Study Experiences with Risk-based Security Testing and Model-based Fuzzing • Panel (chair: Scott) • Pleaseregisterandsupport
New Aps / meetings • Ari (thisweek): distribute 2nd draft on terminology • Axel (thisweek): contactjorge.cuellar@siemens.comforinputfromwww.spacios.eu • All (untilmidofDecember): send commentsaboutthecontentoftheterminologydocument (2nd version) to Ari • Ari (untilmidofDecember) tocontact Ian regardinginputwrt. „lifecyle“ forthe ETSI Security WS • Next meetings/calls • SIG#7: 18th January ETSI (beforeMTS#58)