Security risks of global software development life cycle: Industry practitioner's perspective
Khan, Rafiq Ahmad; Khan, Siffat Ullah; Akbar, Muhammad Azeem; Alzahrani, Musaad (2022-11-23)
Katso/ Avaa
Sisältö avataan julkiseksi: 24.11.2023
Post-print / Final draft
Khan, Rafiq Ahmad
Khan, Siffat Ullah
Akbar, Muhammad Azeem
Alzahrani, Musaad
23.11.2022
Journal of Software: Evolution and Process
John Wiley & Sons Ltd.
School of Engineering Science
Kaikki oikeudet pidätetään.
© 2022 John Wiley & Sons Ltd.
© 2022 John Wiley & Sons Ltd.
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi-fe2023021727661
https://urn.fi/URN:NBN:fi-fe2023021727661
Tiivistelmä
Software security has become increasingly important because the malicious attack and other hacker risks of a computer system have grown popularity in the last few years. As a result, several researchers have examined security solutions as early as the requirement engineering phase. With the growth of the software business and the internet, there is a need to understand the security risks against each phase of the software development life cycle (SDLC). This study aims to empirically investigate and prioritize the risks that could negatively impact the software security aspects of SDLC in the context of global software development (GSD). To achieve the study objectives, we conducted an industrial empirical study to determine the impact of software security threats against each phase of SDLC. Furthermore, the fuzzy analytical hierarchy process (FAHP) was used to prioritize the list of software security risks against the SDLC. The results and analysis of this study provide a ranked-based decision-making framework, which assists the practitioners in considering the most critical security risks on priority. The results show “improper plan for secure requirement identification, inception, authentication, authorization, and privacy,” “lack of threat models updating,” “lack of output validation,” “lack of certification in the final release and archive,” and “spoofing” as the top-ranked security risks of SDLC in GSD. In addition, the application of FAHP is novel in this domain as it is helpful to address multicriteria decision-making problems.
Lähdeviite
Khan, RA, Khan, SU, Akbar, MA, Alzahrani, M. Security risks of global software development life cycle: Industry practitioner's perspective. J Softw Evol Proc. 2022;e2521. doi:10.1002/smr.2521
Alkuperäinen verkko-osoite
https://onlinelibrary.wiley.com/doi/10.1002/smr.2521Kokoelmat
- Tieteelliset julkaisut [1140]