Towards the integration of security practices in the software implementation process of ISO/IEC 29110: A mapping

Mary Luz Sánchez-Gordón*, Ricardo Colomo-Palacios, Alex Sánchez, Antonio de Amescua Seco, Xabier Larrucea

*Autor correspondiente de este trabajo

Producción científica: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

5 Citas (Scopus)

Resumen

Secure software practices are gradually gaining relevance among software practitioners and researchers. This is happening because today more than ever software is becoming part of our lives and cybercrimes are constantly appearing. Despite its importance, its current practice in the software industry is still scarce. Indeed, software security problems are divided 50/50 between bugs and flaws. In particular, it remains a significant challenge for software practitioners in small software companies. Therefore, there is a need to support small companies in changing their existing ways of work to integrate these new and unfamiliar practices. The aim of this study is twofold. First, to help building an awareness of the software security process among practitioners in small companies. Second, to help the integration of these practices with software implementation process of ISO/IEC 29110 which results in an extension of the latter with additional activities identified from the industry best practices. Nevertheless, the extension proposal is to be performed selectively, based on the value of the software as an asset to the stakeholders and on stakeholders needs.

Idioma originalInglés
Título de la publicación alojadaSystems, Software and Services Process Improvement - 24th European Conference, EuroSPI 2017, Proceedings
EditoresRichard Messnarz, Jakub Stolfa, Svatopluk Stolfa, Rory V. O’Connor
EditorialSpringer Verlag
Páginas3-14
Número de páginas12
ISBN (versión impresa)9783319642178
DOI
EstadoPublicada - 2017
Evento24th European Conference on Systems, Software and Services Process Improvement, EuroSPI 2017 - Ostrava, República Checa
Duración: 6 sept 20178 sept 2017

Serie de la publicación

NombreCommunications in Computer and Information Science
Volumen748
ISSN (versión impresa)1865-0929

Conferencia

Conferencia24th European Conference on Systems, Software and Services Process Improvement, EuroSPI 2017
País/TerritorioRepública Checa
CiudadOstrava
Período6/09/178/09/17

Huella

Profundice en los temas de investigación de 'Towards the integration of security practices in the software implementation process of ISO/IEC 29110: A mapping'. En conjunto forman una huella única.

Citar esto