Software quality and application security base on the AGILISO software development process and the OWASP standard

被引:0
|
作者
Blandon-Jaramillo, Carlos Arturo [1 ]
Jaramillo-Becerra, Jhon Steven [2 ]
机构
[1] Progrezando Com, Cali, Colombia
[2] Univ Caldas, Manizales, Colombia
来源
TECNOLOGIA EN MARCHA | 2023年 / 36卷 / 0-期
关键词
Software quality; security; agile processes; software development; system audit;
D O I
10.18845/tm.v36i8.6923
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Globalization has driven all industrial sectors towards the modernization of obtaining, storing and accessing information in the support, mission and strategic processes, modernization that have started to become practically mandatory and immediate after the world pandemic declaration, which forced these processes to be carried out virtually since governments decreed confinements to the entire population; this unexpected circumstance leads to the imperative need to improve both software development practices and security testing of the applications that support the business operation. In this context, those responsible for internal control and information systems auditing departments must generate permanent evaluations of both software development processes and application security, ensuring compliance with international standards ISO/IEC 27001 and ISO/IEC 29110, verifying that the business logic is adequately supported by the organizations' own or outsourced developments. This is a proposal to evaluate software quality based on the AGILISO software development process and application security based on the OWASP application security verification standard, strengthening and optimizing the auditing activity by internal control, auditors and information systems consultants, allowing the timely proposal of action plans that seek to correct the deviations detected.
引用
收藏
页数:95
相关论文
共 50 条
  • [21] Approach to a quality process for the ubiquitous software development
    Rubio, Jose Miguel L.
    Bozo, Jorge P.
    [J]. CERMA 2007: ELECTRONICS, ROBOTICS AND AUTOMOTIVE MECHANICS CONFERENCE, PROCEEDINGS, 2007, : 701 - 705
  • [22] A standard software application development: SAP R/3
    Plattner, H
    [J]. PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, 1996, : 320 - 320
  • [23] Application of CMMI in Software Product Development Process
    Han, Bing
    Fang, Yinglan
    [J]. PRZEGLAD ELEKTROTECHNICZNY, 2012, 88 (1B): : 44 - 47
  • [24] Analysis of software component quality to improve object utilization in software development process
    Rahul, Kumar
    Sinha, Brijesh Kumar
    [J]. PROCEEDINGS OF THE 2016 2ND INTERNATIONAL CONFERENCE ON APPLIED AND THEORETICAL COMPUTING AND COMMUNICATION TECHNOLOGY (ICATCCT), 2016, : 515 - 518
  • [25] Design of a process for software security
    Byers, David
    Shahmehri, Nahid
    [J]. ARES 2007: SECOND INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2007, : 301 - +
  • [26] Evaluating software security maturity using OWASP SAMM: Different approaches and stakeholders perceptions
    Fucci, Davide
    Alegroth, Emil
    Felderer, Michael
    Johannesson, Christoffer
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 2024, 214
  • [27] STANDARD SOFTWARE QUALITY METRICS
    INGILS, J
    [J]. AT&T TECHNICAL JOURNAL, 1986, 65 (02): : 113 - 118
  • [28] Development of a software security assessment instrument to reduce software security risk
    Gilliam, DP
    Kelly, JC
    Powell, JD
    Bishop, M
    [J]. PROCEEDINGS OF THE TENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, 2001, : 144 - 149
  • [29] Software process and quality
    Khodabandeh, A
    [J]. 1997 CERN SCHOOL OF COMPUTING, 1997, 97 (08): : 157 - 160
  • [30] Economic Impact of Software Security Activities in Software Development
    Chehrazi, Golriz
    [J]. 2013 INTERNATIONAL CONFERENCE ON RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS), 2013,