• DocumentCode
    1924176
  • Title

    A Knowledge Management Approach to Support a Secure Software Development

  • Author

    Nunes, Francisco José Barreto ; Belchior, Arnaldo Dias ; Albuquerque, Adriano Bessa

  • Author_Institution
    Dept. of Appl. Comput. Sci., Univ. of Fortaleza (UNIFOR), Fortaleza
  • fYear
    2009
  • fDate
    16-19 March 2009
  • Firstpage
    829
  • Lastpage
    834
  • Abstract
    Organizations that want to increase their profits from reliable and secure software product need to invest in software security approaches. However, secure software is not easily achieved and the actual scenario is that investments in software development process improvement do not assure software that resist from attacks or do not present security vulnerabilities. The PSSS (Process to Support Software Security) may help obtaining secure software as it proposes security activities to be integrated into software development life cycles. This paper resumes the application of the PSSS and proposes the support of a knowledge management environment based, specially, on security inspections of the artifacts generated during the processes execution. It also proposes a checklist to security inspections on the software requirements. This will improve how the security aspects are being considered during the development of secure software and will help to establish the security as an important discipline on the organizational culture.
  • Keywords
    formal specification; knowledge management; organisational aspects; security of data; software process improvement; software reliability; Process to Support Software Security; knowledge management; organizational culture; reliable software product; secure software development; secure software product; security inspection; software development life cycle; software development process improvement; software requirement; Application software; Computer security; IEC standards; ISO standards; Information security; Inspection; Knowledge management; Programming; Software standards; Standards development; knowledge management; security; software process;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2009. ARES '09. International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4244-3572-2
  • Electronic_ISBN
    978-0-7695-3564-7
  • Type

    conf

  • DOI
    10.1109/ARES.2009.155
  • Filename
    5066572