• DocumentCode
    1924240
  • Title

    Software Inspections Using Guided Checklists to Ensure Security Goals

  • Author

    Elberzhager, Frank ; Klaus, Alexander ; Jawurek, Marek

  • fYear
    2009
  • fDate
    16-19 March 2009
  • Firstpage
    853
  • Lastpage
    858
  • Abstract
    Security is a crucial issue in many modern software systems and can lead to immense costs if required security goals are not fulfilled. Fewer techniques exist to address the systematic analysis and detection of security problems, especially during early development phases. Based on well-known and established inspection techniques, we investigated traditional reading support, which did not fit exactly what we needed to ensure security goals. Therefore, we developed a new kind of checklist which we call guided checklist. This kind of checklist focuses the inspector much more on how to check security goals and provides the inspector with more fine-grained support than traditional reading support. To derive such checklists, we developed a model for security goals. A continuous example shows what the security goal model looks like and how to apply the guided checklist.
  • Keywords
    security of data; guided checklists; security goals; software inspections; systematic analysis; Availability; Costs; Data security; Inspection; Manuals; National security; Quality assurance; Software engineering; Software quality; Software systems; SGIT; guided checklist; security inspection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2009. ARES '09. International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4244-3572-2
  • Electronic_ISBN
    978-0-7695-3564-7
  • Type

    conf

  • DOI
    10.1109/ARES.2009.20
  • Filename
    5066576