2007
DOI: 10.1007/978-0-387-73269-5_6
|View full text |Cite
|
Sign up to set email alerts
|

SecSDM: A Model for Integrating Security into the Software Development Life Cycle

Abstract: Most traditional software development methodologies do not explicitly include a standardised method for incorporating information security into their life cycles. It is argued that security considerations should provide input into every phase of the Software Development Life Cycle (SDLC), from requirements gathering to design, implementation, testing and deployment. Therefore, to build more secure software applications, an improved software development process is required. The Secure Software Development Model… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
22
0

Year Published

2008
2008
2024
2024

Publication Types

Select...
4
3

Relationship

1
6

Authors

Journals

citations
Cited by 17 publications
(22 citation statements)
references
References 7 publications
0
22
0
Order By: Relevance
“…Hasan et al [17] have also stressed the importance of integrating the SDLC. A model for ensuring security is built into the SDLC has previously been proposed [18], and others have investigated the use of such models, subsequently publishing a case study [19].…”
Section: Implementing Security Into the Software Development Lifecyclmentioning
confidence: 99%
“…Hasan et al [17] have also stressed the importance of integrating the SDLC. A model for ensuring security is built into the SDLC has previously been proposed [18], and others have investigated the use of such models, subsequently publishing a case study [19].…”
Section: Implementing Security Into the Software Development Lifecyclmentioning
confidence: 99%
“…This work is an extension of that published in [2]. Where the focus of that paper was on integrating security into the software development life cycle (SDLC), this paper focuses on how to establish information security requirements to ensure the protection of the information assets implicated.…”
Section: Introductionmentioning
confidence: 99%
“…Secure programming language selection is the important step to achieve secure implementation phase, through following a secure coding standard and standard guideline, some model suggest that implementation using secure language to achieve secure implementation, like Apvrille and Pourzandi [11], and S2D-ProM [17], where some other suggest to use secure coding standard guideline to achieve secure implementation like MS SDL [4,13], SecSDM [6,30], McGraw's SSDLC process [2], S2D-ProM, CLASP [18], MS SDL goes further and suggests that certain security assurance activities should be performed during implementation.…”
Section: -Security Activity In Implementation Phasementioning
confidence: 99%
“…We must note that all these activities do not guarantee security of software but identify errors and vulnerability. Different models of SDLC models use these activities for testing phase such as the exception of AEGIS [5,31], SSDM [6], and SecSDM [30], all the processes recommend using multiple security assurance methods such as security testing, code reviews, static code analysis.…”
Section: -Ssd Activities For Security Assurance and Testingmentioning
confidence: 99%
See 1 more Smart Citation