Software quality and application security base on the AGILISO software development process and the OWASP standard

被引:0
|
作者
Blandon-Jaramillo, Carlos Arturo [1 ]
Jaramillo-Becerra, Jhon Steven [2 ]
机构
[1] Progrezando Com, Cali, Colombia
[2] Univ Caldas, Manizales, Colombia
来源
TECNOLOGIA EN MARCHA | 2023年 / 36卷 / 0-期
关键词
Software quality; security; agile processes; software development; system audit;
D O I
10.18845/tm.v36i8.6923
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Globalization has driven all industrial sectors towards the modernization of obtaining, storing and accessing information in the support, mission and strategic processes, modernization that have started to become practically mandatory and immediate after the world pandemic declaration, which forced these processes to be carried out virtually since governments decreed confinements to the entire population; this unexpected circumstance leads to the imperative need to improve both software development practices and security testing of the applications that support the business operation. In this context, those responsible for internal control and information systems auditing departments must generate permanent evaluations of both software development processes and application security, ensuring compliance with international standards ISO/IEC 27001 and ISO/IEC 29110, verifying that the business logic is adequately supported by the organizations' own or outsourced developments. This is a proposal to evaluate software quality based on the AGILISO software development process and application security based on the OWASP application security verification standard, strengthening and optimizing the auditing activity by internal control, auditors and information systems consultants, allowing the timely proposal of action plans that seek to correct the deviations detected.
引用
收藏
页数:95
相关论文
共 50 条
  • [1] Structuring a Comprehensive Software Security Course Around the OWASP Application Security Verification Standard
    Elder, Sarah E.
    Zahan, Nusrat
    Kozarev, Val
    Shu, Rui
    Menzies, Tim
    Williams, Laurie
    [J]. 2021 IEEE/ACM 43RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: JOINT TRACK ON SOFTWARE ENGINEERING EDUCATION AND TRAINING (ICSE-JSEET 2021), 2021, : 95 - 104
  • [2] A Quality Software Process for Rapid Application Development
    Gerry Coleman
    Renaat Verbruggen
    [J]. Software Quality Journal, 1998, 7 : 107 - 122
  • [3] A quality software process for rapid application development
    Coleman, G
    Verbruggen, R
    [J]. SOFTWARE QUALITY JOURNAL, 1998, 7 (02) : 107 - 122
  • [4] Case Base for Secure Software Development Using Software Security Knowledge Base
    Hazeyama, Atsuo
    Saito, Masahito
    Yoshioka, Nobukazu
    Kumagai, Azusa
    Kobashi, Takanori
    Washizaki, Hironori
    Kaiya, Haruhiko
    Okubo, Takao
    [J]. IEEE 39TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC 2015), VOL 3, 2015, : 97 - 103
  • [5] Incorporating Security into Software Development Process
    Yoshioka, R.
    Watanobe, Y.
    Mirenkov, N.
    [J]. NEW TRENDS IN SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES, 2008, 182 : 99 - 109
  • [6] The Impact of Software Development Process on Software Quality: A Review
    Singh, Brijendra
    Gautam, Shikha
    [J]. 2016 8TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMMUNICATION NETWORKS (CICN), 2016, : 666 - 672
  • [7] Integrating Application Security into Software Development
    Payne, Jeffery
    [J]. IT PROFESSIONAL, 2010, 12 (02) : 6 - 9
  • [8] OWASP Risk Analysis Driven Security Requirements Specification for Secure Android Mobile Software Development
    Qian, Kai
    Parizi, Reza M.
    Lo, Dan
    [J]. 2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2018, : 382 - 383
  • [9] Cheating the software development process and producing high quality software
    Karolak, D
    [J]. INTERNATIONAL SOCIETY FOR COMPUTERS AND THEIR APPLICATIONS 13TH INTERNATIONAL CONFERENCE ON COMPUTERS AND THEIR APPLICATIONS, 1998, : 9 - 12
  • [10] Essential contents for software development process and software quality education
    Hwang, Sun-Myung
    [J]. INTERNATIONAL JOURNAL OF ENGINEERING SYSTEMS MODELLING AND SIMULATION, 2014, 6 (1-2) : 44 - 53