DocumentCode :
1638445
Title :
A Security Practices Evaluation Framework
Author :
Morrison, Patrick
Author_Institution :
Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
Volume :
2
fYear :
2015
Firstpage :
935
Lastpage :
938
Abstract :
Software development teams need guidance on choosing security practices so they can develop code securely. The academic and practitioner literature on software development security practices is large, and expanding. However, published empirical evidence for security practice use in software development is limited and fragmented, making choosing appropriate practices difficult. Measurement frameworks offer a tool for collecting and comparing software engineering data. The goal of this work is to aid software practitioners in evaluating security practice use in the development process by defining and validating a measurement framework for software development security practice use and outcomes. We define the Security Practices Evaluation Framework (SP-EF), a measurement framework for software development security practices. SP-EF supports evidence-based practice selection. To enable comparison of practices across publications and projects, we define an ontology of software development security practices. We evaluate the framework and ontology on historical data and industrial projects.
Keywords :
security of data; software development management; software metrics; software quality; SP-EF; evidence-based practice selection; industrial projects; security practice evaluation framework; software development process; software development security practice ontology; software development security practices; software development teams; software engineering data; Context; Ontologies; Process control; Security; Size measurement; Software; Software measurement; Measurement Frameworks; Quality; Security; Software Development Lifecycle.;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Engineering (ICSE), 2015 IEEE/ACM 37th IEEE International Conference on
Conference_Location :
Florence
Type :
conf
DOI :
10.1109/ICSE.2015.296
Filename :
7203118
Link To Document :
بازگشت