Development site security process of ISO/IEC TR 15504

被引:0
|
作者
Lee, ES
Kim, TH
机构
[1] Chung Ang Univ, Seoul, South Korea
[2] KISA, Seoul, South Korea
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The IT products like as firewall, IDS (Intrusion Detection System) and VPN (Virtual Private Network) are made to perform special functions related to security, so the developers of these products or systems should consider many kinds of things related to security not only design itself but also development environment to protect integrity of products. When we are making these kinds of software products, ISO/IEC TR 15504 may provide a framework for the assessment of software processes, and this framework can be used by organizations involved in planning, monitoring, controlling, and improving the acquisition, supply, development, operation, evolution and support of software. But, in the ISO/IEC TR 15504, considerations for security are relatively poor to other security-related criteria such as ISO/IEC 21827 or ISO/IEC 15408 [1012]. In fact, security related to software development is concerned with many kinds of measures that may be applied to the development environment or developer to protect the confidentiality and integrity of the IT product or system developed. In this paper we propose some measures related to development process security by analyzing the ISO/IEC 21827, the Systems Security Engineering Capability Maturity Model (SSE-CMM) and ISO/IEC 15408, Common Criteria (CC). And we present a Process of Security for ISO/IEC TR 15504.
引用
收藏
页码:60 / 66
页数:7
相关论文
共 50 条
  • [1] Introduction and evaluation of development system security process of ISO/IEC TR 15504
    Lee, ES
    Lee, KW
    Kim, TH
    Jung, IH
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 451 - 460
  • [2] Development system security process of ISO/IEC TR 15504 and security considerations for software process improvement
    Lee, ES
    Lee, M
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2005, PT 2, 2005, 3481 : 363 - 372
  • [3] Supplement of security-related parts of ISO/IEC TR 15504
    Kim, S
    Leem, C
    Kim, T
    Kim, J
    COMPUTER AND INFORMATION SCIENCES - ISCIS 2003, 2003, 2869 : 1084 - 1089
  • [4] An ISO/IEC 15504 Security Extension
    Lluis Mesquida, Antoni
    Mas, Antonia
    Amengual, Esperanca
    SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION, 2011, 155 : 64 - 72
  • [5] Analysis the priority of security requirement items for the process improvement by ISO/IEC 15504 and ISO/IEC 15408
    Lee, Eun-Ser
    Kim, Haeng-Kon
    Hwang, Sun-Myoung
    SERA 2007: 5TH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH, MANAGEMENT, AND APPLICATIONS, PROCEEDINGS, 2007, : 25 - +
  • [6] Validating the ISO/IEC 15504 measures of software development process capability
    El Emam, K
    Birk, A
    JOURNAL OF SYSTEMS AND SOFTWARE, 2000, 51 (02) : 119 - 149
  • [7] Security Process Capability Model Based on ISO/IEC 15504 Conformant Enterprise SPICE
    Mitasiunas, Antanas
    Novickis, Leonids
    Kalpokas, Rimas
    APPLIED COMPUTER SYSTEMS, 2014, 15 (01) : 36 - 41
  • [8] ISO/IEC 15504 measurement applied to COBIT process maturity
    Walker, Alastair
    McBride, Tom
    Basson, Gerhard
    Oakley, Robert
    BENCHMARKING-AN INTERNATIONAL JOURNAL, 2012, 19 (02) : 159 - +
  • [9] ISO/IEC 15504 adaptation for software process assessment in SMEs
    Pichaco, AM
    Alcover, EA
    SERP'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH AND PRACTICE, VOLS 1 AND 2, 2003, : 693 - 697
  • [10] High Levels of Process Capability in CMMI and ISO/IEC 15504
    Rout, Terry
    SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION, 2011, 155 : 197 - 199