Software Security Costing Issues

Margaret E. Bisignani, Teresa S. Reed · Journal of Parametrics · 1987

Traditionally, computer security has been accomplished by providing physical system safeguards. This assumes that the threats to private information come from outside the system boundaries. However, with the advent of distributed processing, distributed databases, communications networks, and requirements for specialized operating environments, physical safeguards may not be sufficient. The need for security can be readily understood and appreciated. What is less obvious is the way to achieve security and impact it will have on system development cost. The purpose of this paper is twofold. First, the potential cost impact of security on each phase of the software lifecycle is discussed. Next, a methodology which can aid in determining the effect of security measures on cost are examined through the use of a generic example. Software costs associated with software security are estimated by parametric techniques and the adaption of parametric drivers is discussed. Even though this paper is directed towards a Department of Defense environment, the cost methodology presented is equally applicable to a commercial environment.

Read the paper · More papers on PaperTik