2016
DOI: 10.1002/sec.1700
|View full text |Cite
|
Sign up to set email alerts
|

The practice of secure software development in SDLC: an investigation through existing model and a case study

Abstract: Software security is an essential requirement for software systems. However, recent investigation indicates that many software development methodologies do not explicitly include methods for incorporating information security into the software development life cycles (SDLC). This research investigates, using case study, the methodologies being used in software development in Saudi Arabia and describes a model for integrating security into the SDLC. The aim is to identify the appropriate means of introducing se… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
30
0

Year Published

2019
2019
2023
2023

Publication Types

Select...
4
2
2

Relationship

0
8

Authors

Journals

citations
Cited by 47 publications
(30 citation statements)
references
References 30 publications
0
30
0
Order By: Relevance
“…Hasan et al [17] have also stressed the importance of integrating the SDLC. A model for ensuring security is built into the SDLC has previously been proposed [18], and others have investigated the use of such models, subsequently publishing a case study [19].…”
Section: Implementing Security Into the Software Development Lifecyclmentioning
confidence: 99%
“…Hasan et al [17] have also stressed the importance of integrating the SDLC. A model for ensuring security is built into the SDLC has previously been proposed [18], and others have investigated the use of such models, subsequently publishing a case study [19].…”
Section: Implementing Security Into the Software Development Lifecyclmentioning
confidence: 99%
“…Obviously, majority of software products undergoing live testing are vulnerable to threats and mostly fail to provide a secure and safe environment to clients and users. This is due to the lack of systematic evaluations such as systematic reviews, procedures, approaches, or frameworks as these evaluations could help project managers and software engineers to ensure that security processes are continuously followed throughout the software development process, according to a set of predefined procedures or rules (Karim, Albuolayan, Saba, & Rehman, 2016;Mundher, Muhamad, Rehman, Saba, & Kausar, 2014). To efficiently grip the security problems, that are present in during the development of applications, it is necessary to consider security-minded thinking throughout the development processes, which reduces the threats of missing essential security requirements or creating vital faults in software design .…”
Section: Introductionmentioning
confidence: 99%
“…Software application developers can add security during any of the six stages of SDLC, and security need not be an afterthought. Studies have shown that software development efforts focus on functionality and usability and do not explicitly include cybersecurity in the SDLC process [7]. Due to competing priorities, software application developers often only focus on what they consider the core functionality and leave out security implementation for later stages [8,9].…”
Section: Software Development Life Cyclementioning
confidence: 99%
“…However, each stage of SDLC lends itself to including security. The following table, adapted from Karim et al [7], shows some ways in which software application developers can incorporate security in each stage of SDLC.…”
Section: Software Development Life Cyclementioning
confidence: 99%
See 1 more Smart Citation