【24h】

Benchmarking SDL and CLASP lifecycle

机译:基准SDL和扣钩生命周期

获取原文

摘要

Processes for secure software development play a crucial role in the software lifecycle. They help organizations to meet security requirements throughout the development lifecycle. Among these processes, OWASP's CLASP and Microsoft's SDL are leaders for security support in the software life cycle. This has prompted researchers to compare and evaluate these two approaches in order to use them in an opportunistic manner. However, these studies focus mainly on the activities identified in each of these approaches. We think that the interested parties point of view is important. So, our research question is: what are the main concerns for the various stakeholders in a secure development lifecycle? And how SDL and CLASP contribute to meet these concerns? This paper aims to study and compare the two approaches with considering three dimensional viewpoints: security and security audit viewpoint, software engineering viewpoint and decider viewpoint according to the stakeholders involved in these processes. Our comparison is based on a number of criteria that we classified according to these 3 viewpoints.
机译:安全软件开发的流程在软件生命周期中发挥着至关重要的作用。它们帮助组织满足整个开发生命周期的安全要求。在这些过程中,OWASP的Clasp和Microsoft的SDL是软件生命周期中安全支持的领导者。这促使研究人员比较和评估这两种方法,以便以机会主义方式使用它们。然而,这些研究主要关注每种方法中所确定的活动。我们认为有关方面的观点很重要。因此,我们的研究问题是:在安全的发展生命周期中,各利益相关者的主要问题是什么? SDL和Clasp如何有助于满足这些问题?本文旨在研究和比较考虑三维观点:安全性和安全审计视点,软件工程观点和参加参考视点的两种方法,根据这些过程的利益相关者。我们的比较基于我们根据这3个观点分类的许多标准。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号