loading...
S2D-ProM: A Strategy Oriented Process Model for Secure Software Development
Cap Esterel, France August 25-August 31
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ICSEA.2007.59International Conference on Software ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Mehrez Essafi, University of Manouba
Lamia Labed, University of Manouba
Henda Ben Ghezala, University of Manouba
Building Secure Software is about taking security into account during all phases of software development. This practice is missing in, widely used, traditional developments due to domain immaturity, newness of the field and process complexity. Software development includes two views, a product view and a process view. Product view defines what the product is, whereas process view describes how the product is developed. Here we are concerned with the process view. Modelling the process allows simulate and analyze a software development process, which can help developers better understand, manage and optimize the software development process. In this paper we present our approach S2D-ProM, for Secure Software Development Process Model, which is a strategy oriented process model. This latter, capture steps and strategies that are required for the development of secure software and provide a two level guidance. The first level guidance is strategic helping developers choosing one among several strategies. The second level guidance is tactical helping developers achieving their selection for producing secure software. The proposed process model is easily extensible and allows building customized processes adapted to context, developer?s finalities and product state. This flexibility allows the environment evolving through time to support new securing strategies.
Citation:
Mehrez Essafi, Lamia Labed, Henda Ben Ghezala, "S2D-ProM: A Strategy Oriented Process Model for Secure Software Development," icsea, pp.24, International Conference on Software Engineering Advances (ICSEA 2007), 2007
Usage of this product signifies your acceptance of the Terms of Use.