• Home
  • Search
  • An Integrated Cybersecurity Framework for Software Development and Risk‐Aware Practices in the SDLC
  • https://doi.org/10.1002/smr.70075Copy DOI Icon

An Integrated Cybersecurity Framework for Software Development and Risk‐Aware Practices in the SDLC

Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

ABSTRACT Cybersecurity risks are increasing in frequency and complexity, but many organizations struggle to plan and implement adequate protections at all stages of the software development life cycle (SDLC). Security is frequently added at the end of development (afterthought), and making effective use of safeguard space is difficult for IT leaders. The purpose of this study is to produce an all‐encompassing framework to adopt and ensure security throughout each phase of the SDLC, from planning through maintenance. The aim is to minimize vulnerabilities and improve the resilience of software by making “security by design” a structure that not only adopts security elegantly as a living document but also is built to be part of the development process. This study adopted a mixed‐methods approach. The initial stage of inquiry involved a systematic literature review (SLR) to identify common cybersecurity issues associated with each SDLC phase. The SLR was followed by an empirical survey of 71 software professionals from a variety of organizations. The survey was designed to gather perceived threats, current practices, and challenges associated with software development for survey participants' organizations. The data collected were analyzed and reviewed statistically, through chi‐square tests and ANOVA, to profile the variance relative to the size of the organization, geographic region, and experience level of the practitioner. The results noted several high‐risk challenges across the SDLC: underfunded security controls, imprecise requirements, insecure architecture, software bugs (i.e., injection vulnerabilities), inadequate testing, misconfigured production environments, and unreliable maintenance. The proposed framework provides cybersecurity mitigation techniques for each stage of the SDLC, such as leveraging security‐oriented design patterns, secure coding policies (i.e., input validation and authentication protocols), robust testing (i.e., penetration testing and code review), and continuous monitoring after deployment. The implementation of these measures leads to a significant risk reduction in the overall organizational security posture. The framework is a formalized end‐to‐end approach to secure software development by embedding security throughout the cycle. Embedding security as a part of the process versus an afterthought at every stage of the cycle creates a risk reduction impact. This integrated approach also provides organizations with the opportunity to foresee and mitigate events earlier in the cycle, along with general compliance mandates (i.e., GDPR, HIPAA, and PCI‐DSS), to provide more resilient, trustworthy software systems.

Similar Papers
  • Conference Article
  • Citations1

Reusable integrated components of inter-related patterns for software development

  • Dec 05, 2000
  • J Ram +1
  • Research Article

Evaluating the Interoperability and Relative Importance of Software Development Life Cycle Components Using Grey Relational Analysis

  • Apr 22, 2025
  • Computer Science, Engineering and Technology
  • Umesh Joshi +99
  • Research Article
  • Citations24

Security risks of global software development life cycle: Industry practitioner's perspective

  • Nov 23, 2022
  • Journal of Software: Evolution and Process
  • Rafiq Ahmad Khan +3
  • Conference Article
  • Citations5

Role of Software Metrics in Software Engineering and Requirements Analysis

  • Aug 27, 2005
  • Q Durrani
  • Research Article
  • Citations118

A fuzzy logic based approach for phase-wise software defects prediction using software metrics

  • Mar 19, 2015
  • Information and Software Technology
  • Harikesh Bahadur Yadav +1
  • Research Article
  • Citations2

Analyst’s Perception on the Use of AI-based Tools in the Software Development Life Cycle

  • Apr 04, 2024
  • Jurnal Sistem Informasi
  • Rafi Giffari +4
  • PDF
  • Research Article
  • Citations2

Review of ways to apply machine learning methods in software engineering

  • Jan 01, 2023
  • E3S Web of Conferences
  • Jameleh Asaad +1
  • Research Article
  • Citations1

Development of Interactive Learning Media for Software Engineering Subject Chapter Process Modeling in Higher Education

  • Nov 03, 2020
  • Letters in Information Technology Education (LITE)
  • Nadia Roosmalita Sari
  • Conference Article
  • Citations8

Managing Change in Agile Software Development a Comparative Study

  • Nov 01, 2018
  • Samrina Raza +1
  • Research Article
  • Citations407

Software development lifecycle models

  • May 11, 2010
  • ACM SIGSOFT Software Engineering Notes
  • Nayan B Ruparelia
  • Conference Article
  • Citations8

Integrating Web Application Security Penetration Testing into the Software Development Life Cycle: A Systematic Literature Review

  • Oct 25, 2021
  • Shayma Ahmed Altayaran +1
  • Research Article
  • Citations1

Cybersecurity Real-World Applications for the Software Development Life Cycle

  • Mar 01, 2025
  • Land Forces Academy Review
  • Ebone Mccoy
  • Conference Article

Experiences in Creating Inclusive Information and Communications Technologies (IICT): Democratizing Software Development in Social Development

  • Sep 01, 2012
  • Chrispen Hanyane
  • Book Chapter

Fuzzy Logic Based Computational Technique for Analyzing Software Bug Repository

  • Jan 03, 2023
  • Rama Ranjan Panda +1
  • Book Chapter
  • Citations3

Integrating Security in Cloud-Native Development

  • Apr 24, 2025
  • Pravin Pandey +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.