2005Unpublished venueRequires access

Security sensitive software development

M.P. Ressler

Open publisher page 1 citations

Abstract

Security has become an increasingly visible characteristic of software systems. Software providers are finding that developing secure software products is a difficult task. As a software provider, Bellcore has a commitment to its clients to protect their systems and data. This paper discusses efforts that are part of work undertaken at Bellcore to address its commitment to its clients. A corporate security policy is fundamental to the development of security sensitive software. A discussion of the key notions of the proposed Bellcore Security Policy is presented. Fundamental to that policy is the notion that the amount of security consideration given to an application development project is in direct proportion to the value of the information within the the risks associated with that application being violated. Not all products need the same degree of security considerations. This paper also presents a discussion of security requirements. Security. requirements must address more than simply security features and mechanisms. Adding more security mechanisms to software is not a sufficient technique for increasing confidence in the application's security. The most successful approach to securing software is to incorporate security considerations throughout the entire product lifecycle. From product conceptualization to deployment and maintenance, proper attention must be given to security. In addition to the Bellcore Security Policy, this paper discusses basic security features as well as security considerations for each phase of a typical software development lifecycle.

About this research paper

What this paper is about

Security has become an increasingly visible characteristic of software systems. Software providers are finding that developing secure software products is a difficult task. As a software provider, Bellcore has a commitment to its clients to protect their systems and data. This paper discusses efforts that are part of work undertaken at Bellcore to address its commitment to its clients. A corporate security policy is fundamental to the development of security sensitive software. A discussion of the key notions of the proposed Bellcore Security Policy is presented. Fundamental to that policy is the notion that the amount of security consideration given to an application development project is in direct proportion to the value of the information within the the risks associated with that application being violated. Not all products need the same degree of security considerations. This paper also presents a discussion of security requirements. Security. requirements must address more than simply security features and mechanisms. Adding more security mechanisms to software is not a sufficient technique for increasing confidence in the application's security. The most successful approach to securing software is to incorporate security considerations throughout the entire product lifecycle. From product conceptualization to deployment and maintenance, proper attention must be given to security. In addition to the Bellcore Security Policy, this paper discusses basic security features as well as security considerations for each phase of a typical software development lifecycle.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Security has become an increasingly visible characteristic of software systems. Software providers are finding that developing secure software products is a difficult task. As a software provider, Bellcore has a commitment to its clients to protect their systems and data. This paper discusses efforts that are part of work undertaken at Bellcore to address its commitment to its clients. A corporate security policy is fundamental to the development of security sensitive software. A discussion of the key notions of the proposed Bellcore Security Policy is presented. Fundamental to that policy is the notion that the amount of security consideration given to an application development project is in direct proportion to the value of the information within the the risks associated with that application being violated. Not all products need the same degree of security considerations. This paper also presents a discussion of security requirements. Security. requirements must address more than simply security features and mechanisms. Adding more security mechanisms to software is not a sufficient technique for increasing confidence in the application's security. The most successful approach to securing software is to incorporate security considerations throughout the entire product lifecycle. From product conceptualization to deployment and maintenance, proper attention must be given to security. In addition to the Bellcore Security Policy, this paper discusses basic security features as well as security considerations for each phase of a typical software development lifecycle.

Key concepts: Software security assurance, Computer science, Security engineering, Computer security, Security information and event management, Computer security model, Security service, Security through obscurity

Related papers

Back to paper searchBrowse research topicsOriginal source
Security sensitive software development — Research Paper | ScholarLens