An Automatic Approach To Aid Process Integration Within A Secure Software Processes Family

Jia-Kuan Ma,Ya-Sha Wang,Lei Shi,Hong Mei
DOI: https://doi.org/10.1007/978-3-642-14347-2_17
2010-01-01
Abstract:Defining secure processes is an important means for assuring software security. A wealth of dedicated secure processes has emerged in these years. These processes are similar to some extent, while differ from one another in detail. Conceptually, they can be further regarded as a so called "Process Family". In order to integrate practices from different family members, and further improve efficiency and effectiveness compared to using a single process, in this paper we propose an automatic approach to implement the integration of the three forefront secure processes, namely, CLASP, SDL and Touchpoints. Moreover, we select a module from an e-government project in China, and conduct an exploratory experiment to compare our approach with cases when one single secure process is employed. The empirical result confirms the positive effects of our approach.
What problem does this paper attempt to address?