Development system security process of ISO/IEC TR 15504 and security considerations for software process improvement

被引:0
|
作者
Lee, ES
Lee, M
机构
[1] TQMS, Seoul, South Korea
[2] Chonbuk Natl Univ, Sch Elect & Informat Engn, JeonJu, ChonBuk, South Korea
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This research is intended to develop the system security process. The IT products like as Firewall, IDS (Intrusion Detection System) and VPN (Virtual Private Network) are made to perform special functions related to security, so the developers of these products or systems should consider many kinds of things related to security not only design itself but also development environment to protect integrity of products. When we are making these kinds of software products, ISO/IEC TR 15504 may provide a framework for the assessment of software processes, and this framework can be used by organizations involved in planning, monitoring, controlling, and improving the acquisition, supply, development, operation, evolution and support of software. But, in the ISO/IEC TR 15504, considerations for security are relatively poor to other security-related criteria such as ISO/IEC 21827 or ISO/IEC 15408 [10-12]. In this paper we propose some measures related to development process security by analyzing the ISO/IEC 21827, the Systems Security Engineering Capability Maturity Model (SSE-CMM) and ISO/IEC 15408, Common Criteria (CC). And we present a Process of Security for ISO/IEC TR 15504. This enable estimation of development system security process by case study.
引用
收藏
页码:363 / 372
页数:10
相关论文
共 50 条
  • [1] Development site security process of ISO/IEC TR 15504
    Lee, ES
    Kim, TH
    KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT 3, PROCEEDINGS, 2004, 3215 : 60 - 66
  • [2] Introduction and evaluation of development system security process of ISO/IEC TR 15504
    Lee, ES
    Lee, KW
    Kim, TH
    Jung, IH
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 451 - 460
  • [3] Analysis the priority of security requirement items for the process improvement by ISO/IEC 15504 and ISO/IEC 15408
    Lee, Eun-Ser
    Kim, Haeng-Kon
    Hwang, Sun-Myoung
    SERA 2007: 5TH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH, MANAGEMENT, AND APPLICATIONS, PROCEEDINGS, 2007, : 25 - +
  • [4] Supplement of security-related parts of ISO/IEC TR 15504
    Kim, S
    Leem, C
    Kim, T
    Kim, J
    COMPUTER AND INFORMATION SCIENCES - ISCIS 2003, 2003, 2869 : 1084 - 1089
  • [5] An ISO/IEC 15504 Security Extension
    Lluis Mesquida, Antoni
    Mas, Antonia
    Amengual, Esperanca
    SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION, 2011, 155 : 64 - 72
  • [6] Validating the ISO/IEC 15504 measures of software development process capability
    El Emam, K
    Birk, A
    JOURNAL OF SYSTEMS AND SOFTWARE, 2000, 51 (02) : 119 - 149
  • [7] Security Process Capability Model Based on ISO/IEC 15504 Conformant Enterprise SPICE
    Mitasiunas, Antanas
    Novickis, Leonids
    Kalpokas, Rimas
    APPLIED COMPUTER SYSTEMS, 2014, 15 (01) : 36 - 41
  • [8] ISO/IEC 15504 adaptation for software process assessment in SMEs
    Pichaco, AM
    Alcover, EA
    SERP'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH AND PRACTICE, VOLS 1 AND 2, 2003, : 693 - 697
  • [9] Implementing information security best practices on software lifecycle processes: The ISO/IEC 15504 Security Extension
    Mesquida, Antoni Lluis
    Mas, Antonia
    COMPUTERS & SECURITY, 2015, 48 : 19 - 34
  • [10] Metrics design for software process assessment based on ISO/IEC 15504
    Hwang, SM
    Yeom, HG
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 4, 2006, 3983 : 909 - 916