Skip to main navigation Skip to search Skip to main content

La sécurité des applications en technologie de l'information : une approche d'intégration des éléments de sécurité dans le cycle de vie des applications et des systèmes d'information

Translated title of the thesis: Application security in information technology : an approach for integrating security elements in the life cycle of applications and information systems
  • Luc Poulin

Student thesis: Doctoral thesisDoctorate in Engineering: Engineering

Abstract

The information technology (IT) industry and organizations that use IT have at their disposal many resources to develop, acquire and maintain secure applications. However, although there is a variety of best practices, standards and tools that affect applications security, organizations are struggling to achieve that goal. Sixteen issues to explain this situation were identified in this research, which goal is to design, to get approved by an international standards organization and to make available to those who develop or use applications, a new model of application security (AS model). Using this AS model will help to implement and demonstrate the security of an application, thus ensuring the protection of sensitive information involved in its use. The AS model offers concepts, principles, processes and components to enable an organization to develop a normative framework that meets its security needs, while respecting its capabilities. This AS model considers the business, legal and technological environments where specific applications are developed and used. It also helps to manage the security risks from the people, processes and technology that could threaten sensitive information involved in these applications. This AS model allows an organization to identify and implement a set of controls and security measures to ensure a level of confidence in the security of an application during its life cycle. Finally, the AS model allows the organization to provide measurable and repeatable evidence achieving and maintaining a target level of confidence, depending on the context of use of specific applications. The AS model includes different elements of application security architecture that can be used by organizations and the IT industry. These elements are defined, validated, tested and integrated by organizations in a normative framework to be used as an authoritative source to guide the implementation of security for their applications.
Date15 Sept 2015
Original languageFrench
Awarding Institution
  • École de technologie supérieure
SupervisorAlain Abran (Supervisor) & Alain April (Co-supervisor)

Cite this

'