Software quality and application security base on the AGILISO software development process and the OWASP standard

被引:0
|
作者
Blandon-Jaramillo, Carlos Arturo [1 ]
Jaramillo-Becerra, Jhon Steven [2 ]
机构
[1] Progrezando Com, Cali, Colombia
[2] Univ Caldas, Manizales, Colombia
来源
TECNOLOGIA EN MARCHA | 2023年 / 36卷 / 0-期
关键词
Software quality; security; agile processes; software development; system audit;
D O I
10.18845/tm.v36i8.6923
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Globalization has driven all industrial sectors towards the modernization of obtaining, storing and accessing information in the support, mission and strategic processes, modernization that have started to become practically mandatory and immediate after the world pandemic declaration, which forced these processes to be carried out virtually since governments decreed confinements to the entire population; this unexpected circumstance leads to the imperative need to improve both software development practices and security testing of the applications that support the business operation. In this context, those responsible for internal control and information systems auditing departments must generate permanent evaluations of both software development processes and application security, ensuring compliance with international standards ISO/IEC 27001 and ISO/IEC 29110, verifying that the business logic is adequately supported by the organizations' own or outsourced developments. This is a proposal to evaluate software quality based on the AGILISO software development process and application security based on the OWASP application security verification standard, strengthening and optimizing the auditing activity by internal control, auditors and information systems consultants, allowing the timely proposal of action plans that seek to correct the deviations detected.
引用
收藏
页数:95
相关论文
共 50 条
  • [41] Automated Process Quality Assurance for Distributed Software Development
    Zhai, Jian
    Yang, Qiusong
    Yang, Ye
    Xiao, Junchao
    Wang, Qing
    Li, Mingshu
    [J]. SOFTWARE ENGINEERING APPROACHES FOR OFFSHORE AND OUTSOURCED DEVELOPMENT, 2009, 16 : 196 - 210
  • [42] Quality management in software development process: An empirical model
    Gyorkos, J
    Rozman, I
    Horvat, RV
    Hericko, M
    [J]. IEMC 96 PROCEEDINGS - MANAGING VIRTUAL ENTERPRISES: A CONVERGENCE OF COMMUNICATIONS, COMPUTING, AND ENERGY TECHNOLOGIES, 1996, : 191 - 195
  • [43] Influence of software development process capability on product quality
    Golubic, S
    [J]. ConTEL 2005: Proceedings of the 8th International Conference on Telecommunications, Vols 1 and 2, 2005, : 457 - 463
  • [44] Security Assurance Model of Software Development for Global Software Development Vendors
    Khan, Rafiq Ahmad
    Khan, Siffat Ullah
    Alzahrani, Musaad
    Ilyas, Muhammad
    [J]. IEEE ACCESS, 2022, 10 : 58458 - 58487
  • [45] Waveform application development process for Software Defined Radios
    Christensen, E
    Miller, A
    Wing, E
    [J]. MILCOM 2000: 21ST CENTURY MILITARY COMMUNICATIONS CONFERENCE PROCEEDINGS, VOLS 1 AND 2: ARCHITECTURES & TECHNOLOGIES FOR INFORMATION SUPERIORITY, 2000, : 231 - 235
  • [46] A methodology for priority setting with application to software development process
    Lee, M
    Pham, H
    Zhang, XM
    [J]. EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 1999, 118 (02) : 375 - 389
  • [47] SOFTWARE ENVIRONMENT for OPTIMAL SOFTWARE QUALITY DEVELOPMENT
    Lazic, Ljubomir
    Milinkovic, Stevan A.
    [J]. 2012 20TH TELECOMMUNICATIONS FORUM (TELFOR), 2012, : 1693 - 1696
  • [48] Software quality: Application of a process model for quality-in-use assessment
    Souza-Pereira, Leonice
    Pombo, Nuno
    Ouhbi, Sofia
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (07) : 4626 - 4634
  • [49] SOFTWARE APPLICATION FOR THE DEVELOPMENT OF QUALITY CULTURE IN HIGHER EDUCATION
    Seghedin, Neculai Eugen
    Chitariu, Dragos
    [J]. QUALITY AND EFFICIENCY IN E-LEARNING, VOL 3, 2013, : 338 - 343
  • [50] A quantitative security evaluation and analysis model for web applications based on OWASP application security verification standard
    Wen, Shao-Fang
    Katt, Basel
    [J]. COMPUTERS & SECURITY, 2023, 135