DocumentCode :
900392
Title :
A Software Procurement and Security Primer
Author :
Ladd, David
Author_Institution :
Microsoft Corp., Redmond, WA
Volume :
4
Issue :
6
fYear :
2006
Firstpage :
71
Lastpage :
73
Abstract :
Given society´s increasing dependence on software-intensive systems, each business unit within an organization should examine its role in delivering and deploying secure systems. Software procurement is an early element of the process that organizations often leave out of the security equation until an incident occurs and sensitive materials, such as personally identifiable information from a customer database, are lost or misused. This article explores some useful concepts that help integrate security more firmly into the software-procurement process. In keeping with Basic Training´s spirit, these concepts are merely food for thought - a conceptual framework for asking the right questions at the right time. For those involved with software or software procurement in an organization, it helps to start by asking potential vendors some simple questions about their software-development processes, education and training, and accountability
Keywords :
DP industry; organisational aspects; procurement; security of data; software management; customer database; personally identifiable information; secure systems; security primer; software procurement; software-development processes; software-intensive systems; Computer science education; Computer security; Documentation; Educational institutions; Educational programs; Feedback; Industrial training; Privacy; Procurement; Weapons; procurement; security; software development; software security;
fLanguage :
English
Journal_Title :
Security & Privacy, IEEE
Publisher :
ieee
ISSN :
1540-7993
Type :
jour
DOI :
10.1109/MSP.2006.142
Filename :
4042663
Link To Document :
بازگشت