Bringing Security Testing to Development: How to Enable Developers to Act as Security Experts
Achim D. Brucker, Dimitar Yanev, Stephen Hookings
Abstract
Achim D. Brucker, Dimitar Yanev, Stephen Hookings
Abstract
Security testing is an important part of any security development life-cycle (SDLC) and, thus, should be a part of any software development life-cycle.We will present SAP's Security Testing Strategy that enables developers to find security vulnerabilities early by applying a variety of different security testing methods and tools. We explain the motivation behind it, how we enable global development teams to implement the strategy, across different SDLCs and report on our experiences.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Security testing is an important part of any security development life-cycle (SDLC) and, thus, should be a part of any software development life-cycle.We will present SAP's Security Testing Strategy that enables developers to find security vulnerabilities early by applying a variety of different security testing methods and tools. We explain the motivation behind it, how we enable global development teams to implement the strategy, across different SDLCs and report on our experiences.
Key concepts: Security testing, Systems development life cycle, Security through obscurity, Security bug, Computer security, Security engineering, Computer science, Software security assurance