Title :
Protection Poker: The New Software Security "Game";
Author :
Williams, Laurie ; Meneely, Andrew ; Shipley, Grant
Author_Institution :
North Carolina State Univ., Raleigh, NC, USA
Abstract :
Without infinite resources, software development teams must prioritize security fortification efforts to prevent the most damaging attacks. The Protection Poker "game" is a collaborative means for guiding this prioritization and has the potential to improve software security practices and team software security knowledge.
Keywords :
computer games; security of data; software engineering; protection poker game; security fortification efforts; software development; software security; team software security knowledge; Delphi estimation; Wideband Delphi estimation; design; documentation; management; measurement; protection mechanisms; risk assessment; risk estimation; security; verification;
Journal_Title :
Security & Privacy, IEEE
DOI :
10.1109/MSP.2010.58