Security Compliance Engineering

Security Compliance Engineering An Integrated Workflow from Regulatory Requirements to Security Testing

Sale price  $179.99 Regular price $199.99
Skip to product information
Security Compliance Engineering

Security Compliance Engineering An Integrated Workflow from Regulatory Requirements to Security Testing

Sale price  $179.99 Regular price $199.99

Reliable shipping

Flexible returns

Security Compliance Engineering

An Integrated Workflow from Regulatory Requirements to Security Testing

Gianpietro Castiglione | Giampaolo Bella | Daniele Santamaria

Computers / Security / General

Compliance assessment and technical security testing have traditionally been separate activities. Security Compliance Engineering brings them together into a more coherent workflow.

This book develops Security Compliance Engineering as an integrated workflow that, starting from the interpretation and structured representation of regulatory requirements, introduces methodologies for machine-supported compliance assessment and for guiding security testing from identified compliance gaps. These compliance gaps can guide attack-pattern analysis, candidate kill chain modelling, and software-level assessment. The NIS 2 Directive provides the principal case study throughout the book, while the proposed methodologies are conceived for broader cybersecurity legislation. Together, the different methodologies aim to reduce the conceptual distance between cybersecurity legislation and technical security testing.

Topics and features:

  • Introduces Security Compliance Engineering as a methodological perspective connecting cybersecurity legislation, compliance assessment, and security testing
  • Presents syntactic, semantic, and reasoning-based methodologies for representing and assessing regulatory requirements
  • Illustrates how compliance findings can support the generation and prioritisation of security-relevant attack-pattern and weakness hypotheses
  • Develops system-level and software-level paths for leveraging these compliance-derived hypotheses in candidate kill-chain construction and targeted software security assessment, respectively

This volume is particularly relevant to researchers and security professionals working at the intersection of cybersecurity legislation, regulatory compliance, and security testing, as well as practitioners interested in integrating compliance activities with security-engineering processes.

Gianpietro Castiglione is a Research Associate at the School of Computing, Newcastle University. Giampaolo Bella is a Full Professor in the Department of Political and Social Sciences, University of Catania. Daniele Francesco Santamaria is an Assistant Professor in the Department of Mathematics and Computer Science, University of Catania.

Gianpietro Castiglione is a PhD student in computer science at the University of Catania. His research during his doctoral program focused particularly on bridging the technological and conceptual gap between modern security directives, such as NIS 2, and more technical aspects of security, such as attack derivation. He therefore dedicated his doctoral path to conjecturing and testing the methodologies presented in this book, as a culmination of the research topics addressed. The results have been presented in articles in international journals and conferences.

For more details, please refer to the CV.

Giampaolo Bella is full professor at University of Catania. He took his Ph.D. at Cambridge University Computer Laboratory in 2000 with a thesis entered in the Distinguished Dissertation scheme.

Visiting Researcher with SAP Research France in 2008 and Visiting Professor at De Montfort University (UK) in 2010 and at Royal Holloway University of London in 2019.

He is a lecturer of modules towards the Laurea degrees of the University of Catania.

He calls himself a researcher before anything else, with a scientific publication record in the areas of security protocols and their socio-technical aspects, methods of formal verification and penetration testing, as well as legal aspect of cybersecurity.

He is called as Independent Expert by the EU since 2009 for the evaluation and review of research and development projects within the FP7, H2020 and Horizon Europe frameworks. He has acted as Scientific Coordinator of several European projects, including COSCA and POC4COMMERCE among the recent ones.

Daniele Francesco Santamaria is Assistant Professor at the Department of Mathematics and Computer Science of the University of Catania.

During his career, Daniele joined an international project called POC4COMMERCE, in the ambit of the ONTOCHAIN initiative, founded by the Next Generation of Internet (NGI) consortium and dedicated to the development of a novel software ecosystem for trusted, traceable, and transparent ontological knowledge for blockchain-oriented e-commerce. He also joined the PECS - Privacy Enrooted Car Systems, funded by NGI in the ambit of the Trustchain initiative, and dedicated to securing personal data within the modern car ecosystem. Daniele is also involved in an Italian national project Progetti di Rilevante Interesse Nazionale (PRIN) dedicated to ontological approaches in archaeology and called GODSCAPES.

He is PI of the project MASS - A Meta-ontological Approach to Securing the Semantic Web and of the project SWOTOP - Semantic Web of EveryThing through Ontological Protocols, funded by the University of Catania.


Publication Date: 13 March 2027
Publisher: Springer Nature Switzerland
Imprint: Springer
ISBN-13: 9783032441188
Format: Hardback

You may also like