Software Security Investment: The Right Amount of a Good Thing

被引:0
|
作者
Heitzenrater, Chad [1 ,2 ]
Simpson, Andrew [2 ]
机构
[1] US Air Force Res Lab, Informat Directorate, 525 Brooks Rd, Rome, NY 13441 USA
[2] Univ Oxford, Dept Comp Sci, Wolfson Bldg,Parks Rd, Oxford OX1 3QD, England
关键词
D O I
10.1109/SecDev.2016.15
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Despite an ever-increasing amount of money and attention devoted to cybersecurity, we continue to see wide-ranging cybersecurity failures. As security practitioners examine new approaches to combat this trend, a growing community has coalesced around secure software development, or 'SWSec', as a best practice. While this movement has highlighted the role engineering process plays in combating the underlying source of vulnerabilities, it has yet to enjoy wide adoption. Anecdotal evidence points to an inability to demonstrate the return on investment (ROI) as a rationale behind this reluctance, and current information security investment models have failed to account for such expenditures. We seek to build upon such models to reflect SWSec investments, with a view to demonstrating the ROI enjoyed by SWSec practice. We summarise our current research toward these ends and identify the research required to fully reflect SWSec alongside current security investments.
引用
收藏
页码:53 / 59
页数:7
相关论文
共 50 条