已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整的填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

Systematic Literature Review on Security Risks and its Practices in Secure Software Development

系统开发生命周期 软件安全保证 计算机科学 软件开发 计算机安全 软件开发过程 安全性测试 安全工程 安全编码 安全漏洞 安全信息和事件管理 软件同行评审 默默无闻的安全 保安服务 软件 信息安全 软件建设 云安全计算 操作系统 云计算
作者
Rafiq Ahmad Khan,Siffat Ullah Khan,Habib Ullah Khan,Muhammad Ilyas
出处
期刊:IEEE Access [Institute of Electrical and Electronics Engineers]
卷期号:10: 5456-5481 被引量:48
标识
DOI:10.1109/access.2022.3140181
摘要

Security is one of the most critical aspects of software quality. Software security refers to the process of creating and developing software that assures the integrity, confidentiality, and availability of its code, data, and services. Software development organizations treat security as an afterthought issue, and as a result, they continue to face security threats. Incorporating security at any level of the Software Development Life Cycle (SDLC) has become an urgent requirement. Several methodologies, strategies, and models have been proposed and developed to address software security, but only a few of them give reliable evidence for creating secure software applications. Software security issues, on the other hand, have not been adequately addressed, and integrating security procedures into the SDLC remains a challenge. The major purpose of this paper is to learn about software security risks and practices so that secure software development methods can be better designed. A systematic literature review (SLR) was performed to classify important studies to achieve this goal. Based on the inclusion, exclusion, and quality assessment criteria, a total of 121 studies were chosen. This study identified 145 security risks and 424 best practices that help software development organizations to manage the security in each phase of the SDLC. To pursue secure SDLC, this study prescribed different security activities, which should be followed in each phase of the SDLC. Successful integration of these activities minimizing effort, time, and budget while delivering secure software applications. The findings of this study assist software development organizations in improving the security level of their software products and also enhancing their security efficiency. This will raise the developer’s awareness of secure development practices as well.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
AJoe发布了新的文献求助10
1秒前
心外科医生完成签到,获得积分10
1秒前
Angenstern完成签到 ,获得积分10
1秒前
草拟大坝完成签到 ,获得积分0
1秒前
清爽的诗云完成签到 ,获得积分10
2秒前
小燕子完成签到 ,获得积分10
2秒前
Wang_JN完成签到 ,获得积分10
3秒前
DF完成签到 ,获得积分10
3秒前
LM879完成签到,获得积分20
3秒前
pinklay完成签到 ,获得积分10
3秒前
小陈发布了新的文献求助10
4秒前
星辰完成签到,获得积分10
4秒前
小远完成签到 ,获得积分10
6秒前
伶俐雨双发布了新的文献求助10
6秒前
liu完成签到 ,获得积分10
6秒前
谨慎雪碧完成签到 ,获得积分10
7秒前
木木完成签到,获得积分10
7秒前
小田心完成签到 ,获得积分10
7秒前
Hello应助星辰采纳,获得10
7秒前
李健应助有热心愿意采纳,获得10
9秒前
执着的采枫完成签到 ,获得积分10
9秒前
鹿小新完成签到 ,获得积分10
10秒前
自信放光芒~完成签到 ,获得积分10
10秒前
摆烂完成签到 ,获得积分10
10秒前
科研通AI5应助HJJHJH采纳,获得30
11秒前
小熊熊完成签到 ,获得积分10
12秒前
Amancio118完成签到 ,获得积分10
12秒前
Delight完成签到 ,获得积分10
12秒前
明时完成签到,获得积分10
13秒前
青出于蓝蔡完成签到,获得积分10
13秒前
Akim应助伶俐雨双采纳,获得10
14秒前
drz完成签到 ,获得积分10
14秒前
wwmmyy完成签到 ,获得积分10
15秒前
结实的小土豆完成签到 ,获得积分10
15秒前
个性的大白菜真实的钥匙完成签到 ,获得积分10
15秒前
陈道哥完成签到 ,获得积分10
16秒前
16秒前
神外第一刀完成签到 ,获得积分10
17秒前
李爱国应助木木采纳,获得10
18秒前
Rjy完成签到 ,获得积分10
18秒前
高分求助中
Continuum thermodynamics and material modelling 3000
Production Logging: Theoretical and Interpretive Elements 2500
Healthcare Finance: Modern Financial Analysis for Accelerating Biomedical Innovation 2000
Applications of Emerging Nanomaterials and Nanotechnology 1111
Covalent Organic Frameworks 1000
Les Mantodea de Guyane Insecta, Polyneoptera 1000
Theory of Block Polymer Self-Assembly 750
热门求助领域 (近24小时)
化学 医学 材料科学 生物 工程类 有机化学 生物化学 纳米技术 内科学 物理 化学工程 计算机科学 复合材料 基因 遗传学 物理化学 催化作用 细胞生物学 免疫学 电极
热门帖子
关注 科研通微信公众号,转发送积分 3477372
求助须知:如何正确求助?哪些是违规求助? 3068797
关于积分的说明 9109635
捐赠科研通 2760290
什么是DOI,文献DOI怎么找? 1514752
邀请新用户注册赠送积分活动 700461
科研通“疑难数据库(出版商)”最低求助积分说明 699547

今日热心研友

iNk
10
注:热心度 = 本日应助数 + 本日被采纳获取积分÷10