A Light-Weight Tool for the Self-assessment of Security Compliance in Software Development - An Industry Case

被引:4
|
作者
Moyon, Fabiola [1 ,2 ]
Bayr, Christoph [2 ]
Mendez, Daniel [3 ,4 ]
Dannart, Sebastian [5 ]
Beckers, Kristian [1 ]
机构
[1] Siemens CT Munich, Munich, Germany
[2] Tech Univ Munich, Munich, Germany
[3] Blekinge Inst Technol, Karlskrona, Sweden
[4] Fortiss GmbH, Munich, Germany
[5] INFODAS GmbH, Cologne, Germany
来源
SOFSEM 2020: THEORY AND PRACTICE OF COMPUTER SCIENCE | 2020年 / 12011卷
关键词
Security standards; Secure software engineering; Security assessment; Secure development process; Tool-support;
D O I
10.1007/978-3-030-38919-2_33
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Companies are often challenged to modify and improve their software development processes in order to make them compliant with security standards. The complexity of these processes renders it difficult for practitioners to validate and foresee the effort required for compliance assessments. Further, performing gap analyses when processes are not yet mature enough is costly and involving auditors in early stages is, in our experience, often inefficient. An easier and more productive approach is conducting a self-assessment. However, practitioners, in particular developers, quality engineers, and product owners face difficulties to identify security-relevant process artifacts as required by standards. They would benefit from a proper and light-weight tool to perform early compliance assessments of their processes w.r.t. security standards before entering an in-depth audit. In this paper, we report on our current effort at Siemens Corporate Technology to develop such a light-weight assessment tool to assess the security compliance of software development processes with the IEC 62443-4-1 standard, and we discuss first results from an interview-based evaluation.
引用
收藏
页码:403 / 416
页数:14
相关论文
共 50 条
  • [1] Security Maturity Self-Assessment Framework for Software Development Lifecycle
    Brasoveanu, Raluca
    Karabulut, Yusuf
    Pashchenko, Ivan
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [2] Adapting the Lean Enterprise Self-Assessment Tool for the Software Development Domain
    Karvonen, Teemu
    Rodriguez, Pilar
    Kuvaja, Pasi
    Mikkonen, Kirsi
    Oivo, Markku
    2012 38TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA), 2012, : 266 - 273
  • [3] Statistical process control readiness in the food industry: Development of a self-assessment tool
    Lim, Sarina Abdul Halim
    Antony, Jiju
    TRENDS IN FOOD SCIENCE & TECHNOLOGY, 2016, 58 : 133 - 139
  • [4] Light-weight development method: a case study
    Chen, Jim Q.
    Phan, Dien
    Wang, B.
    Vogel, Douglas R.
    2007 INTERNATIONAL CONFERENCE ON SERVICE SYSTEMS AND SERVICE MANAGEMENT, VOLS 1-3, 2007, : 651 - +
  • [5] A SELF-ASSESSMENT TOOL FOR ENERGY MANAGEMENT FOR THE CARDBOARD INDUSTRY
    SAXENA, U
    BOHLMAN, K
    ENERGY ENGINEERING, 1995, 92 (03) : 23 - 32
  • [6] Development of a Self-Assessment Tool for Alopecia Areata
    Pixley, Jessica N.
    Zaino, Mallory L.
    Feldman, Steven R.
    McMichael, Amy J.
    JOURNAL OF CUTANEOUS MEDICINE AND SURGERY, 2023, 27 (06) : 652 - 654
  • [7] Development of a continuous improvement self-assessment tool
    Caffyn, S
    INTERNATIONAL JOURNAL OF OPERATIONS & PRODUCTION MANAGEMENT, 1999, 19 (11) : 1138 - 1153
  • [8] Development of an endometriosis self-assessment tool for patient
    Cho, Hyun-Hee
    Yoon, Young-Sub
    OBSTETRICS & GYNECOLOGY SCIENCE, 2022, 65 (03) : 256 - 265
  • [9] A formal methods case study: Using light-weight VDM for the development of a security system module
    Droschl, G
    Kuhn, W
    Sonneck, G
    Thuswald, M
    COMPUTER SAFETY, RELIABILITY AND SECURITY, PROCEEDINGS, 2000, 1943 : 187 - 197
  • [10] Development of a Life Skills Self-Assessment Tool for Coaches
    Kramers, Sara
    Camire, Martin
    Ciampolini, Vitor
    Milistetd, Michel
    JOURNAL OF SPORT PSYCHOLOGY IN ACTION, 2022, 13 (01) : 54 - 64