2020 IEEE 32nd Conference on Software Engineering Education and Training (CSEE&T) 2020
DOI: 10.1109/cseet49119.2020.9206233
|View full text |Cite
|
Sign up to set email alerts
|

Secure Sourcing of COTS Products: A Critical Missing Element in Software Engineering Education

Abstract: The aim of this paper is to publicize both the challenge and potential solution for the integration of secure supply chain risk management content into conventional software engineering programs. Specifically, software engineering programs typically do not teach how to ensure that the code produced and sold in commercial off-the-shelf (COTS) products hasn't been compromised through the sourcing process. We propose four instructional modules and topics based on established principles that can form the basis of … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
2
1

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(1 citation statement)
references
References 2 publications
0
1
0
Order By: Relevance
“…It is important to understand the implication of choosing a suitable component from a third-party repository because of the trade-off in quality [8]. Software Engineering taught programs do not teach how to ensure that COTS components are not compromised from production to integration [9]. Data are generated during component execution, which can be distilled and mined [10].…”
Section: Related Workmentioning
confidence: 99%
“…It is important to understand the implication of choosing a suitable component from a third-party repository because of the trade-off in quality [8]. Software Engineering taught programs do not teach how to ensure that COTS components are not compromised from production to integration [9]. Data are generated during component execution, which can be distilled and mined [10].…”
Section: Related Workmentioning
confidence: 99%