1. Introduction
The IWSS is a developing system for the security of web-based information systems. The goal of the IWSS was to merge a client system base (CSB) and risk information repository (RIR) with a relational database system and forms a distributed integrated web security system. IWSS provides a centralised risk information database, which can be used as a risk analysis tool to create a local CSB to implement the risk analysis and management for a local web based information system.