DocumentCode :
2134532
Title :
Security Engineering Approach to Support Software Security
Author :
Nunes, Francisco José Barreto ; Belchior, Arnaldo Dias ; Albuquerque, Adriano Bessa
Author_Institution :
Mestrado em Inf. Aplic., Univ. de Fortaleza, Fortaleza, Brazil
fYear :
2010
fDate :
5-10 July 2010
Firstpage :
48
Lastpage :
55
Abstract :
As information security and privacy become increasingly important to organizations, the demand grows for software development processes that assure information integrity, availability, and confidentiality. Unfortunately, despite the investments made in process improvement, there is still no guarantee that the developed software products are protected from attacks or do not present security vulnerabilities. As soon as software products continue to present security flaws and be compromised by attacks, the Systems Security Engineering - Capability Maturity Model (SSE-CMM) becomes the de facto model to structure a software security approach. Moreover, security best practices, practical experience or international standards, like ISO/IEC 15408, should also be considered to support security engineering as they propose activities that can be adapted to enhance security in a software development process and contribute towards the overall software security. This paper proposes a security engineering approach to support software security through a specialized process that helps develop more secure software, entitled Process to Support Software Security (PSSS). In addition, one of PSSS´s subprocess, Model Security Threat, is explained in detail. This paper also presents the results of the case study when the PSSS was first applied in a software development project as well as the preliminary results of a large project implementation.
Keywords :
data integrity; data privacy; security of data; software development management; software engineering; capability maturity model; information availability; information confidentiality; information integrity; information privacy; information security; international standards; model security threat; organizations; process to support software security; security flaws; security vulnerabilities; software development processes; software development project; software product development; systems security engineering; IEC standards; ISO standards; Information security; Organizations; Programming; Software; Information Security; Process to Support Software Security; Security Engineering; Software Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Services (SERVICES-1), 2010 6th World Congress on
Conference_Location :
Miami, FL
Print_ISBN :
978-1-4244-8199-6
Electronic_ISBN :
978-0-7695-4129-7
Type :
conf
DOI :
10.1109/SERVICES.2010.37
Filename :
5575592
Link To Document :
بازگشت