Maturity model for secure software testing

Author:

Alam Gulzar1ORCID,Mahmood Sajjad1ORCID,Alshayeb Mohammad1ORCID,Niazi Mahmood1ORCID,Zafar Saad2

Affiliation:

1. Information and Computer Science Department, Interdisciplinary Research Center for Intelligent Secure Systems King Fahd University of Petroleum and Minerals Dhahran Saudi Arabia

2. Riphah International University Islamabad Pakistan

Abstract

AbstractSecurity is an essential attribute of high‐quality software. However, effectively incorporating security practices into different phases of the software development life cycle (SDLC) remains challenging. Owing to less mature secure testing processes, organizations are prone to ineffective testing practices for defect detection, including severe security‐related failures. Thus, in this study, we present a maturity model for secure software testing (MMSST) to assist software development organizations in improving the secure testing of software applications. We conducted a multivocal literature review and identified 68 primary studies from the formal and gray literature. Then, based on the available evidence, 27 process areas were identified to develop the proposed MMSST. The MMSST includes five main categories: governance, contrive and design, execution, deployment and configuration, and mature. The MMSST was subsequently evaluated using case studies related to practical environments. Results demonstrate that the proposed MMSST is useful for estimating the maturity level of an organization with respect to the secure testing phase of the SDLC. The participants of the case studies also agreed that the proposed MMSST is useful in terms of structure, user satisfaction, and ease of use. We believe that the proposed MMSST can help organizations evaluate and improve software security testing practices. In addition, the proposed MMSST is expected to provide researchers and industry practitioners with an effective foundation for developing new secure testing approaches and tools.

Funder

King Fahd University of Petroleum and Minerals

Publisher

Wiley

Subject

Software

Reference114 articles.

1. McGrawG MiguesS WestJ.Building Security. In Maturity Model (BSIMM). Version 6;2015.

2. UMLsec: Extending UML for Secure Systems Development

3. Attack surface: mitigate security risks by minimizing the code you expose to untrusted users;Howard M;MSDN Mag (2004),2004

4. Securing the testing process for industrial automation software

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3