A Preliminary Structure of Software Security Assurance Model

被引:15
|
作者
Khan, Rafiq Ahmad [1 ]
Khan, Siffat Ullah [1 ]
机构
[1] Univ Malakand, Software Engn Res Grp, Dept Comp Sci & IT, Khyber Paktunkhwa, Pakistan
关键词
Software Security; Software Development Life Cycle; Global Software Development; Vendors; Systematic mapping study; Systematic literature review; Empirical Study; Case study;
D O I
10.1145/3196369.3196385
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software security is an important aspect that needs to be considered during the entire software development life cycle (SDLC). Integrating software security at each phase of SDLC has become an urgent need. To address software security, various approaches, techniques, methods, practices, and models have been proposed and developed. However, recent research shows that many software development methodologies do not explicitly include methods for incorporating software security during the development of software as it evolves from requirements engineering to its final disposal. The primary objective of this research is to study the state-of-the-art of security in the context of SDLC by following systematic mapping study (SMS). In the second phase, we will identify, through systematic literature review (SLR) and empirical study in the industry, the software security contributions, security challenges and their practices for global software development (GSD) vendors. The ultimate aim is to develop a Software Security Assurance Model (SSAM) to assist GSD vendor organisations in measuring their readiness towards the development of secure software.
引用
收藏
页码:137 / 140
页数:4
相关论文
共 50 条
  • [31] Towards Evaluation of Security Assurance during the Software Development Lifecycle
    Uusitalo, Ilkka
    Karppinen, Kaarina
    Ahonen, Pasi
    Pentikainen, Heimo
    2009 INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY (ARES), VOLS 1 AND 2, 2009, : 817 - 822
  • [32] A reference model for enterprise security -: High assurance enterprise security
    Enstrom, David W.
    Walsh, D'Arcy
    Hossendoust, Siavosh
    ICEIS 2007: PROCEEDINGS OF THE NINTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS: INFORMATION SYSTEMS ANALYSIS AND SPECIFICATION, 2007, : 355 - +
  • [33] Preliminary Evaluation of a Software Security Learning Environment
    Hazeyama, Atsuo
    Saito, Masahito
    INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2014, 2 (03) : 26 - 39
  • [34] Preliminary Evaluation of a Software Security Learning Environment
    Hazeyama, Atsuo
    Saito, Masahito
    SOFTWARE ENGINEERING RESEARCH, MANAGEMENT AND APPLICATIONS, 2015, 578 : 113 - 125
  • [35] Model-Based Assurance of Security Controls
    Beres, Yolanta
    Baldwin, Adrian
    Shiu, Simon
    QOP'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON QUALITY OF PROTECTION, 2007, : 55 - 55
  • [36] Software assurance for model-based design
    Oh, Jane M. C.
    Watney, Garth J.
    Benowitz, Edward G.
    2008 IEEE AEROSPACE CONFERENCE, VOLS 1-9, 2008, : 3559 - 3564
  • [37] The Security Culture Readiness Model (SCRM) for Saudi Universities: A Preliminary Structure
    Albinali, Mona
    Niazi, Mahmood
    PROCEEDINGS OF 2024 28TH INTERNATION CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, EASE 2024, 2024, : 692 - 697
  • [38] Invited Talk: Software Engineering, AI and autonomous vehicles: Security assurance
    Zheng, James Xi
    2020 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS (PERCOM WORKSHOPS), 2020,
  • [39] Interventions for Software Security Creating a Lightweight Program of Assurance Techniques for Developers
    Weir, Charles
    Becker, Ingolf
    Noble, James
    Blair, Lynne
    Sasse, M. Angela
    Rashid, Awais
    2019 IEEE/ACM 41ST INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: SOFTWARE ENGINEERING IN PRACTICE (ICSE-SEIP 2019), 2019, : 41 - 50
  • [40] Improving Vulnerability Detection Measurement [Test Suites and Software Security Assurance]
    Hoole, Alexander M.
    Traore, Issa
    Delaitre, Aurelien
    de Oliveira, Charles
    PROCEEDINGS OF THE 20TH INTERNATIONAL CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING 2016 (EASE '16), 2016,