• DocumentCode
    3368672
  • Title

    S2D-ProM: A Strategy Oriented Process Model for Secure Software Development

  • Author

    Essafi, Mehrez ; Labed, Lamia ; Ben Ghezala, Henda

  • Author_Institution
    Univ. of Manouba, Tunis
  • fYear
    2007
  • fDate
    25-31 Aug. 2007
  • Firstpage
    24
  • Lastpage
    24
  • Abstract
    Building secure software is about taking security into account during all phases of software development. This practice is missing in, widely used, traditional developments due to domain immaturity, newness of the field and process complexity. Software development includes two views, a product view and a process view. Product view defines what the product is, whereas process view describes how the product is developed. Here we are concerned with the process view. Modelling the process allows simulate and analyze a software development process, which can help developers better understand, manage and optimize the software development process. In this paper we present our approach S2D-ProM, for Secure Software Development Process Model, which is a strategy oriented process model. This latter, capture steps and strategies that are required for the development of secure software and provide a two level guidance. The first level guidance is strategic helping developers choosing one among several strategies. The second level guidance is tactical helping developers achieving their selection for producing secure software. The proposed process model is easily extensible and allows building customized processes adapted to context, developer´s finalities and product state. This flexibility allows the environment evolving through time to support new securing strategies.
  • Keywords
    security of data; software engineering; S2D-ProM; product view; secure software development; strategy oriented process model; Analytical models; Computer security; Context modeling; Information security; Laboratories; National security; Programming; Software development management; Software engineering; Software safety;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering Advances, 2007. ICSEA 2007. International Conference on
  • Conference_Location
    Cap Esterel
  • Print_ISBN
    0-7695-2937-2
  • Electronic_ISBN
    978-0-7695-2937-0
  • Type

    conf

  • DOI
    10.1109/ICSEA.2007.59
  • Filename
    4299907