DocumentCode
1924176
Title
A Knowledge Management Approach to Support a Secure Software Development
Author
Nunes, Francisco José Barreto ; Belchior, Arnaldo Dias ; Albuquerque, Adriano Bessa
Author_Institution
Dept. of Appl. Comput. Sci., Univ. of Fortaleza (UNIFOR), Fortaleza
fYear
2009
fDate
16-19 March 2009
Firstpage
829
Lastpage
834
Abstract
Organizations that want to increase their profits from reliable and secure software product need to invest in software security approaches. However, secure software is not easily achieved and the actual scenario is that investments in software development process improvement do not assure software that resist from attacks or do not present security vulnerabilities. The PSSS (Process to Support Software Security) may help obtaining secure software as it proposes security activities to be integrated into software development life cycles. This paper resumes the application of the PSSS and proposes the support of a knowledge management environment based, specially, on security inspections of the artifacts generated during the processes execution. It also proposes a checklist to security inspections on the software requirements. This will improve how the security aspects are being considered during the development of secure software and will help to establish the security as an important discipline on the organizational culture.
Keywords
formal specification; knowledge management; organisational aspects; security of data; software process improvement; software reliability; Process to Support Software Security; knowledge management; organizational culture; reliable software product; secure software development; secure software product; security inspection; software development life cycle; software development process improvement; software requirement; Application software; Computer security; IEC standards; ISO standards; Information security; Inspection; Knowledge management; Programming; Software standards; Standards development; knowledge management; security; software process;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security, 2009. ARES '09. International Conference on
Conference_Location
Fukuoka
Print_ISBN
978-1-4244-3572-2
Electronic_ISBN
978-0-7695-3564-7
Type
conf
DOI
10.1109/ARES.2009.155
Filename
5066572
Link To Document