Title :
A Knowledge Management Approach to Support a Secure Software Development
Author :
Nunes, Francisco José Barreto ; Belchior, Arnaldo Dias ; Albuquerque, Adriano Bessa
Author_Institution :
Dept. of Appl. Comput. Sci., Univ. of Fortaleza (UNIFOR), Fortaleza
Abstract :
Organizations that want to increase their profits from reliable and secure software product need to invest in software security approaches. However, secure software is not easily achieved and the actual scenario is that investments in software development process improvement do not assure software that resist from attacks or do not present security vulnerabilities. The PSSS (Process to Support Software Security) may help obtaining secure software as it proposes security activities to be integrated into software development life cycles. This paper resumes the application of the PSSS and proposes the support of a knowledge management environment based, specially, on security inspections of the artifacts generated during the processes execution. It also proposes a checklist to security inspections on the software requirements. This will improve how the security aspects are being considered during the development of secure software and will help to establish the security as an important discipline on the organizational culture.
Keywords :
formal specification; knowledge management; organisational aspects; security of data; software process improvement; software reliability; Process to Support Software Security; knowledge management; organizational culture; reliable software product; secure software development; secure software product; security inspection; software development life cycle; software development process improvement; software requirement; Application software; Computer security; IEC standards; ISO standards; Information security; Inspection; Knowledge management; Programming; Software standards; Standards development; knowledge management; security; software process;
Conference_Titel :
Availability, Reliability and Security, 2009. ARES '09. International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
978-1-4244-3572-2
Electronic_ISBN :
978-0-7695-3564-7
DOI :
10.1109/ARES.2009.155