• Cite Icon2
  • https://doi.org/10.5220/0003938901670173Copy DOI Icon

English

  • Jan 1, 2012
  • Esmiralda Moradian +1 more
Show More
  • Abstract
  • Literature Map
  • Citations
  • Similar Papers
Abstract

In today’s organizations, a vast amount of existing software systems is insecure, which results in compromised valuable assets and has negative consequences on the organizations. Throughout the years, many attempts have been made to build secure software systems, but the solutions proposed were limited to a few add-on fixes made after implementation and installation of the system.The contribution of the research in this thesis is a software security engineering methodology, called Controlled Security Engineering Process, which provides support to developers when developing more secure software systems by integrating software lifecycle and security lifecycle, and enhancing the control in the engineering process. The proposed methodology implements security in every phase of general software system engineering, i.e., requirement, design, implementation, and testing, as well as operation and maintenance to certify that software systems are built with security in mind.The Controlled Security Engineering Process methodology addresses security problems in the development lifecycle. Construction of a secure software system involves specific steps and activities, which include security requirements specifications of system behavior, secure software design, an analysis of the design, implementation, with secure coding and integration, and operating and maintenance procedures.The methodology incorporates software security patterns and control of the engineering process. The software security patterns can be used as security controls and information sources to demonstrate how a specific security task should be performed or a specific security problem solved. Many patterns can be implemented in an automated way, which can facilitate the work of software engineers.The control of the engineering process provides visibility over the development process. The control assures that authorised developers access legitimate and necessary information and projects’ documents by using authentication, and authorization.To support implementation of automated patterns and provide control over the engineering process, a design of a multi-agent system is provided. The multi-agent system supports implementation of patterns and extracting security information, and provides traceability in the engineering process. The security information is requirements, threats and security mechanisms that are provided by matching project documents, and traceability is achieved by monitoring and logging services.The Controlled Security Engineering Process methodology has been evaluated through interviews with developers, security professionals, and decision makers in different types of organizations but also through a case study which was carried out in an organization.

Similar Papers
  • Book Chapter
  • Citations23

Software Security Engineering

  • Jan 01, 2009
  • Mohammad Zulkernine +1
  • Conference Article
  • Citations13

Secure Modules for Undergraduate Software Engineering Courses

  • Oct 01, 2018
  • Jeong Yang +2
  • Conference Article
  • Citations4

Incorporation of Aspects of Systems Security and Software Security in Senior Capstone Projects

  • Apr 01, 2012
  • Natarajan Meghanathan +2
  • PDF
  • Conference Article
  • Citations21

Infiltrating security into development: exploring the world’s largest software security study

  • Aug 18, 2021
  • Charles Weir +3
  • Research Article

Top Management Support, Legitimation, and Effectiveness of Information Security Management

  • May 10, 2018
  • Waiguo jingji yu guanli
  • Kunxiang Dong +3
  • Conference Article
  • Citations6

Model for Implementing a IoMT Architecture with ISO/IEC 27001 Security Controls for Remote Patient Monitoring

  • Nov 09, 2022
  • Brandon Alegria +2
  • Conference Article
  • Citations7

Development of a Software Security Learning Environment

  • Aug 01, 2012
  • Atsuo Hazeyama +1
  • Research Article
  • Citations36

Model Based Process to Support Security and Privacy Requirements Engineering

  • Jul 01, 2012
  • International Journal of Secure Software Engineering
  • Shareeful Islam +4
  • Conference Article

Legal Challenges of Confidentiality and Publicity in the View of Information Security in Hungary

  • Jun 02, 2025
  • Tamás Szádeczky +1
  • Research Article
  • Citations44

Strategic value alignment for information security management: a critical success factor analysis

  • Jun 11, 2018
  • Information & Computer Security
  • Cindy Zhiling Tu +3
  • Book Chapter
  • Citations2

Gaming DevSecOps - A Serious Game Pilot Study

  • Sep 09, 2020
  • James S Okolica +2
  • Book Chapter
  • Citations22

A Social Ontology for Integrating Security and Software Engineering

  • Jan 01, 2008
  • E Yu +2
  • PDF
  • Supplementary Content
  • Citations21

Model‐driven engineering of safety and security software systems: A systematic mapping study and future research directions

  • May 26, 2022
  • Journal of Software (Malden, Ma)
  • Atif Mashkoor +3
  • Conference Article
  • Citations5

Leveraging External Data Sources to Enhance Secure System Design

  • May 18, 2021
  • Joe Samuel +2
  • Book Chapter
  • Citations2

Software Security Engineering – Part I

  • Jan 01, 2013
  • Issa Traore +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.