Significance of Security Metrics in Secure Software Development

Shams Tabrez Siddiqui
{"title":"Significance of Security Metrics in Secure Software Development","authors":"Shams Tabrez Siddiqui","doi":"10.5120/IJAIS2017451710","DOIUrl":null,"url":null,"abstract":"With increasing advancement of technology in the past years rise various security issues and problems. In this connected world, security is a paramount and challenging issue in software development and is the demand of time. However usually engineers/developers think about it after the development of the entire software and at that it’s too late. Though, the software developers are aware of the importance of security and its priority throughout software development life cycle. Considering the security challenging issues right from the early stages of software development and incorporating it during software development indicates good research and development. When the metrics considered during software development process from the initial stage then it assess the security risks more efficiently. One of the best known approaches to develop security metrics is Goal/Question/Metric (GQM) approach that assesses the security risks in various stages of software development process. Software security can be measured with the help of metrics derived from the source available. The main aim of this paper is to focus on numerous security metrics of software development phases and some standardized criteria is used for validation. Each and every phase have different metrics as compared to other. Those metrics are defined on the bases of their results and products. The final product derived from the proposed security metrics of the software will be secure and qualified. General Terms Security, software development phases, validation.","PeriodicalId":92376,"journal":{"name":"International journal of applied information systems","volume":"9 1","pages":"10-15"},"PeriodicalIF":0.0000,"publicationDate":"2017-09-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of applied information systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5120/IJAIS2017451710","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

With increasing advancement of technology in the past years rise various security issues and problems. In this connected world, security is a paramount and challenging issue in software development and is the demand of time. However usually engineers/developers think about it after the development of the entire software and at that it’s too late. Though, the software developers are aware of the importance of security and its priority throughout software development life cycle. Considering the security challenging issues right from the early stages of software development and incorporating it during software development indicates good research and development. When the metrics considered during software development process from the initial stage then it assess the security risks more efficiently. One of the best known approaches to develop security metrics is Goal/Question/Metric (GQM) approach that assesses the security risks in various stages of software development process. Software security can be measured with the help of metrics derived from the source available. The main aim of this paper is to focus on numerous security metrics of software development phases and some standardized criteria is used for validation. Each and every phase have different metrics as compared to other. Those metrics are defined on the bases of their results and products. The final product derived from the proposed security metrics of the software will be secure and qualified. General Terms Security, software development phases, validation.
安全度量在安全软件开发中的意义
近年来随着科技的不断进步,各种安全问题层出不穷。在这个互联的世界中,安全性是软件开发中最重要的和具有挑战性的问题,也是时间的要求。然而,工程师/开发人员通常是在整个软件开发完成后才考虑这个问题,这时已经太晚了。尽管如此,软件开发人员还是意识到安全性的重要性及其在整个软件开发生命周期中的优先级。从软件开发的早期阶段就考虑到具有挑战性的安全问题,并在软件开发期间将其纳入其中,这表明了良好的研究和开发。当在软件开发过程中从初始阶段开始考虑度量时,它可以更有效地评估安全风险。开发安全度量的最著名的方法之一是目标/问题/度量(GQM)方法,它评估软件开发过程各个阶段的安全风险。软件安全性可以借助来自可用源的度量来度量。本文的主要目的是关注软件开发阶段的众多安全度量,以及用于验证的一些标准化标准。与其他阶段相比,每个阶段都有不同的度量标准。这些指标是根据他们的结果和产品来定义的。从建议的软件安全度量派生的最终产品将是安全和合格的。一般条款安全,软件开发阶段,验证。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信