Siirry päänavigointiin Siirry hakuun Siirry pääsisältöön

Quality needs structure: Industrial experiences in systematically defining software security requirements

  • Christian Fruehwirth
  • , Richard Mordinyi

    Tutkimustuotos: Artikkeli kirjassa/konferenssijulkaisussaConference article in proceedingsScientificvertaisarvioitu

    Abstrakti

    Successful, quality software projects need to be able to rely on a sufficient level of security in order to manage the technical, legal and business risks that arise from distributed development. The definition of a 'sufficient' level of security however, is typically only captured in implicit requirements that are rarely gathered in a methodological way. Such an unstructured approach makes the work of quality managers incredibly difficult and often forces developers to unwillingly operate in an unclear/undefined security state throughout the project. Ideally, security requirements are elicited in methodological manner enabling a structured storage, retrieval, or checking of requirements. In this paper we report on the experiences of applying a structured requirements elicitation method and list a set of gathered reference security requirements. The reported experiences were gathered in an industrial setting using the open source platform OpenCIT in cooperation with industry partners. The output of this work enables security and quality conscious stakeholders in a software project to draw from our experiences and evaluate against a reference base line.

    AlkuperäiskieliEnglanti
    OtsikkoSoftware Quality: Process Automation in Software Development - 4th International Conference, SWQD 2012, Proceedings
    KustantajaSpringer
    Sivut217-229
    Sivumäärä13
    Vuosikerta94 LNBIP
    ISBN (painettu)9783642272127
    DOI - pysyväislinkit
    TilaJulkaistu - 2012
    OKM-julkaisutyyppiA4 Artikkeli konferenssijulkaisussa
    TapahtumaInternational Conference on Software Quality Days - Vienna, Itävalta
    Kesto: 17 tammik. 201219 tammik. 2012
    Konferenssinumero: 4

    Julkaisusarja

    NimiLecture Notes in Business Information Processing
    Vuosikerta94 LNBIP
    ISSN (painettu)18651348

    Conference

    ConferenceInternational Conference on Software Quality Days
    LyhennettäSWQD
    Maa/AlueItävalta
    KaupunkiVienna
    Ajanjakso17/01/201219/01/2012

    Sormenjälki

    Sukella tutkimusaiheisiin 'Quality needs structure: Industrial experiences in systematically defining software security requirements'. Ne muodostavat yhdessä ainutlaatuisen sormenjäljen.

    Siteeraa tätä