The fourth principle draws attention to the fundamental ”information security triad” Confidentiality, Integrity, and Availability and suggests a constant review process and identification of any design choices in the standard which might foster Denial of Service or enable newSTRIDE threats. Additionally, the protocol has to be able to incorporate the latest securitysolutions or mechanisms in order to be future-proof and flexible. Concrete suggestions include the automatic notification of other controllers as soon as a controller has requested amaster role change or the use of unique keys or certificates for any active connection. While these requirements do not explicitly mitigate a STRIDE threat, they propose a reviewingprocess for the entire specification which could reduce the risk of future DoS, Spoofing orTampering.
đang được dịch, vui lòng đợi..