{"product_id":"9783032441188","title":"Security Compliance Engineering An Integrated Workflow from Regulatory Requirements to Security Testing","description":"\u003ch1\u003eSecurity Compliance Engineering\u003c\/h1\u003e\u003ch2\u003eAn Integrated Workflow from Regulatory Requirements to Security Testing\u003c\/h2\u003e\u003ch3\u003eGianpietro Castiglione | Giampaolo Bella | Daniele Santamaria\u003c\/h3\u003e\u003cdiv\u003e\u003cb\u003eComputers \/ Security \/ General\u003c\/b\u003e\u003c\/div\u003e\u003cbr\u003e\u003cdiv\u003e\n\u003cp\u003eCompliance assessment and technical security testing have traditionally been separate activities. Security Compliance Engineering brings them together into a more coherent workflow.\u003c\/p\u003e\n\u003cp\u003eThis book develops Security Compliance Engineering as an integrated workflow that, starting from the interpretation and structured representation of regulatory requirements, introduces methodologies for machine-supported compliance assessment and for guiding security testing from identified compliance gaps. These compliance gaps can guide attack-pattern analysis, candidate kill chain modelling, and software-level assessment. The NIS 2 Directive provides the principal case study throughout the book, while the proposed methodologies are conceived for broader cybersecurity legislation. Together, the different methodologies aim to reduce the conceptual distance between cybersecurity legislation and technical security testing.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics and features:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduces Security Compliance Engineering as a methodological perspective connecting cybersecurity legislation, compliance assessment, and security testing\u003c\/li\u003e\n\u003cli\u003ePresents syntactic, semantic, and reasoning-based methodologies for representing and assessing regulatory requirements\u003c\/li\u003e\n\u003cli\u003eIllustrates how compliance findings can support the generation and prioritisation of security-relevant attack-pattern and weakness hypotheses\u003c\/li\u003e\n\u003cli\u003eDevelops system-level and software-level paths for leveraging these compliance-derived hypotheses in candidate kill-chain construction and targeted software security assessment, respectively\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eThis volume is particularly relevant to researchers and security professionals working at the intersection of cybersecurity legislation, regulatory compliance, and security testing, as well as practitioners interested in integrating compliance activities with security-engineering processes.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eGianpietro Castiglione\u003c\/strong\u003e is a Research Associate at the School of Computing, Newcastle University. \u003cstrong\u003eGiampaolo Bella\u003c\/strong\u003e is a Full Professor in the Department of Political and Social Sciences, University of Catania. \u003cstrong\u003eDaniele Francesco Santamaria\u003c\/strong\u003e is an Assistant Professor in the Department of Mathematics and Computer Science, University of Catania.\u003c\/p\u003e\n\u003c\/div\u003e\u003cdiv\u003e\n\u003cp\u003e\u003cstrong\u003eGianpietro Castiglione \u003c\/strong\u003eis a PhD student in computer science at the University of Catania. His research during his doctoral program focused particularly on bridging the technological and conceptual gap between modern security directives, such as NIS 2, and more technical aspects of security, such as attack derivation. He therefore dedicated his doctoral path to conjecturing and testing the methodologies presented in this book, as a culmination of the research topics addressed. The results have been presented in articles in international journals and conferences.\u003c\/p\u003e\n\u003cp\u003eFor more details, please refer to the CV.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eGiampaolo Bella\u003c\/strong\u003e is full professor at University of Catania. He took his Ph.D. at Cambridge University Computer Laboratory in 2000 with a thesis entered in the Distinguished Dissertation scheme.\u003c\/p\u003e\n\u003cp\u003eVisiting Researcher with SAP Research France in 2008 and Visiting Professor at De Montfort University (UK) in 2010 and at Royal Holloway University of London in 2019.\u003c\/p\u003e\n\u003cp\u003eHe is a lecturer of modules towards the Laurea degrees of the University of Catania.\u003c\/p\u003e\n\u003cp\u003eHe calls himself a researcher before anything else, with a scientific publication record in the areas of security protocols and their socio-technical aspects, methods of formal verification and penetration testing, as well as legal aspect of cybersecurity.\u003c\/p\u003e\n\u003cp\u003eHe is called as Independent Expert by the EU since 2009 for the evaluation and review of research and development projects within the FP7, H2020 and Horizon Europe frameworks. He has acted as Scientific Coordinator of several European projects, including COSCA and POC4COMMERCE among the recent ones.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDaniele Francesco Santamaria\u003c\/strong\u003e is Assistant Professor at the Department of Mathematics and Computer Science of the University of Catania.\u003c\/p\u003e\n\u003cp\u003eDuring his career, Daniele joined an international project called POC4COMMERCE, in the ambit of the ONTOCHAIN initiative, founded by the Next Generation of Internet (NGI) consortium and dedicated to the development of a novel software ecosystem for trusted, traceable, and transparent ontological knowledge for blockchain-oriented e-commerce. He also joined the PECS - Privacy Enrooted Car Systems, funded by NGI in the ambit of the Trustchain initiative, and dedicated to securing personal data within the modern car ecosystem. Daniele is also involved in an Italian national project Progetti di Rilevante Interesse Nazionale (PRIN) dedicated to ontological approaches in archaeology and called GODSCAPES.\u003c\/p\u003e\n\u003cp\u003eHe is  PI of the project MASS - A Meta-ontological Approach to Securing the Semantic Web  and of the project SWOTOP - Semantic Web of EveryThing through Ontological Protocols, funded by the University of Catania.\u003c\/p\u003e\n\u003c\/div\u003e\u003cbr\u003e\u003ctable\u003e\n\u003ctr\u003e\n\u003ctd\u003ePublication Date: \u003c\/td\u003e\n\u003ctd\u003e13 March 2027\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ePublisher: \u003c\/td\u003e\n\u003ctd\u003eSpringer Nature Switzerland\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eImprint: \u003c\/td\u003e\n\u003ctd\u003eSpringer\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eISBN-13: \u003c\/td\u003e\n\u003ctd\u003e9783032441188\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eFormat: \u003c\/td\u003e\n\u003ctd\u003eHardback\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003c\/table\u003e","brand":"Springer Nature Switzerland","offers":[{"title":"Default Title","offer_id":62349728678028,"sku":"9783032441188","price":179.99,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0710\/9545\/1788\/files\/9783032441188.tif?v=1791402238","url":"https:\/\/lateknightbooks.com\/products\/9783032441188","provider":"Late Knight Books and Services, LLC","version":"1.0","type":"link"}