Managing Security in Software

Kalle Rindell, Karin Bernsmed, Martin Gilje Jaatun · 2019

Context: Security work in software development is generally under-prioritized. Software developers are not aware of security engineering practices, or find them external to the software development process. To the management, security work presents itself in the form of reactive testing performed out of necessity, incurring only costs in terms of time and resources. The long-term benefits of the security work are more difficult to demonstrate and the security investment harder to justify.

Read the paper · More papers on PaperTik