Software Security Investment: The Right Amount of a Good Thing

被引:0
|
作者
Heitzenrater, Chad [1 ,2 ]
Simpson, Andrew [2 ]
机构
[1] US Air Force Res Lab, Informat Directorate, 525 Brooks Rd, Rome, NY 13441 USA
[2] Univ Oxford, Dept Comp Sci, Wolfson Bldg,Parks Rd, Oxford OX1 3QD, England
关键词
D O I
10.1109/SecDev.2016.15
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Despite an ever-increasing amount of money and attention devoted to cybersecurity, we continue to see wide-ranging cybersecurity failures. As security practitioners examine new approaches to combat this trend, a growing community has coalesced around secure software development, or 'SWSec', as a best practice. While this movement has highlighted the role engineering process plays in combating the underlying source of vulnerabilities, it has yet to enjoy wide adoption. Anecdotal evidence points to an inability to demonstrate the return on investment (ROI) as a rationale behind this reluctance, and current information security investment models have failed to account for such expenditures. We seek to build upon such models to reflect SWSec investments, with a view to demonstrating the ROI enjoyed by SWSec practice. We summarise our current research toward these ends and identify the research required to fully reflect SWSec alongside current security investments.
引用
收藏
页码:53 / 59
页数:7
相关论文
共 50 条
  • [41] To do the right thing or to do the thing right? Humanitarianism and ethics
    Walker, P
    ECUMENICAL REVIEW, 1997, 49 (01): : 78 - 84
  • [42] A jump-diffusion approach to modelling software security investment
    Zheng, JiaXiang
    Wang, Jun
    Ren, YunFei
    Guo, Hongyu
    2012 FIFTH INTERNATIONAL CONFERENCE ON BUSINESS INTELLIGENCE AND FINANCIAL ENGINEERING (BIFE), 2012, : 274 - 278
  • [43] RIGHT MIND FOR RIGHT THING
    ROBINSON, AD
    TRAINING AND DEVELOPMENT JOURNAL, 1977, 31 (02): : 32 - 35
  • [44] Right thing at the right place
    Rehsteiner, Fritz
    ZWF Zeitschrift fuer Wirtschaftlichen Fabrikbetrieb, 2000, 95 (06):
  • [45] Usability of internet security software: Have they got it right?
    Szewczyk P.
    Proceedings - 2011 5th International Conference on Network and System Security, NSS 2011, 2011, : 337 - 341
  • [46] Doing the right thing right
    Bigham, Eric C.
    CHEMICAL & ENGINEERING NEWS, 2006, 84 (45) : 32 - 32
  • [47] The Right Thing To Do With the Wrong Thing
    Blackstone, Eugene H.
    ANNALS OF THORACIC SURGERY, 2012, 93 (04): : 1025 - 1026
  • [48] DOING THE RIGHT THING - HOW SOCIAL-SECURITY CLAIMANTS VIEW COMPLIANCE
    WEATHERLEY, R
    AUSTRALIAN AND NEW ZEALAND JOURNAL OF SOCIOLOGY, 1993, 29 (01): : 21 - 39
  • [49] Patient autonomy: A good thing or a bad thing?
    Goodman, NW
    BRITISH JOURNAL OF HOSPITAL MEDICINE, 1997, 57 (10): : 530 - 530
  • [50] As good as the real thing
    Prof Eng, 2007, 1 (40):