A Preliminary Structure of Software Security Assurance Model

被引:15
|
作者
Khan, Rafiq Ahmad [1 ]
Khan, Siffat Ullah [1 ]
机构
[1] Univ Malakand, Software Engn Res Grp, Dept Comp Sci & IT, Khyber Paktunkhwa, Pakistan
关键词
Software Security; Software Development Life Cycle; Global Software Development; Vendors; Systematic mapping study; Systematic literature review; Empirical Study; Case study;
D O I
10.1145/3196369.3196385
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software security is an important aspect that needs to be considered during the entire software development life cycle (SDLC). Integrating software security at each phase of SDLC has become an urgent need. To address software security, various approaches, techniques, methods, practices, and models have been proposed and developed. However, recent research shows that many software development methodologies do not explicitly include methods for incorporating software security during the development of software as it evolves from requirements engineering to its final disposal. The primary objective of this research is to study the state-of-the-art of security in the context of SDLC by following systematic mapping study (SMS). In the second phase, we will identify, through systematic literature review (SLR) and empirical study in the industry, the software security contributions, security challenges and their practices for global software development (GSD) vendors. The ultimate aim is to develop a Software Security Assurance Model (SSAM) to assist GSD vendor organisations in measuring their readiness towards the development of secure software.
引用
收藏
页码:137 / 140
页数:4
相关论文
共 50 条
  • [1] Software assurance for security
    McGraw, G
    COMPUTER, 1999, 32 (04) : 103 - 105
  • [2] Systems and Software Assurance - A Model Cyber Security Course
    Jovanovic, V.
    Harris, J. K.
    2016 39TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2016, : 923 - 927
  • [3] Security Assurance Model of Software Development for Global Software Development Vendors
    Khan, Rafiq Ahmad
    Khan, Siffat Ullah
    Alzahrani, Musaad
    Ilyas, Muhammad
    IEEE ACCESS, 2022, 10 : 58458 - 58487
  • [4] Demanding software security assurance
    Cusimano, John
    Control (Chicago, Ill), 2011, 24 (02): : 14 - 16
  • [5] Empirical Software Security Assurance
    Harper, Dave
    WEB APPLICATION SECURITY, 2010, 72 : 11 - 11
  • [6] Software Security Assurance of Telecommunication Systems
    Savola, Reijo M.
    2009 INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS (ICMCS 2009), 2009, : 138 - 143
  • [7] Software security assurance SOUP to NUTS
    Axelrod, C. Warren
    Axelrod, C. Warren (waxelrod@delta-risk.net), 2015, U.S. Department of Defense (28): : 37 - 43
  • [8] Assessing of software security reliability: Dimensional security assurance techniques
    Ali, Mohammad
    Ullah, Ahsan
    Islam, Md. Rashedul
    Hossain, Rifat
    COMPUTERS & SECURITY, 2025, 150
  • [9] Software Security Assurance of Electrical Grid Systems Relating Mechatronics to Software Security Engineering
    Axelrod, C. Warren
    2014 INTERNATIONAL ENERGY AND SUSTAINABILITY CONFERENCE (IESC), 2014,
  • [10] Importance of Cyber Security in Software Quality Assurance
    Haider, Ammar
    Bhatti, Wafa
    2022 17TH INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES (ICET'22), 2022, : 6 - 11