Secure software engineering: Evaluation of emerging trends

Adel Hamdan Mohammad, Ja’far Alqatawna, Mohammad A. M. Abushariah · 2017

With the dramatic increase in the number of software security problems, a growing body of research in how to integrate security within software development is notable. Many security approaches have appeared to solve security problems by applying a set of activities through Software Development Life Cycle (SDLC). Among the top approaches are McGraw's Touchpoints, Comprehensive Lightweight Application Security Process (CLASP) from Open Web Application Security Project (OWASP) organization, and Microsoft Security Development Lifecycle (SDL). In this paper, we evaluate these three security approaches by discussing their common process, strength, and limitations. Moreover, we discuss why these approaches do not effectively increase software security. Finally, we set the stage for a future framework to enhance and simplify the application of various security activities within the SDLC.

Read the paper · More papers on PaperTik