Security Paradigms In SDLC Requirement Phase — A Comparative Analysis Approach
Mehwish Shaikh, Pir Hamid Ali Qureshi, Murk Shaikh, Qasim Ali Arain, Asma Zubedi, Pireh Shaikh · 2021 International Conference on Engineering and Emerging Technologies (ICEET) · 2021
Security is crucial for the success of any project, as it is the first prerequisite for any project. A number of experts have proposed a number of different security methods, but they all had some various types of issues, like Identification of risks, risk assessments of threats, specification of security measures to be deployed, requirement inspections to identify the flaws in security requirements, and optimization of low-level security requirements are all key examples of security tasks. In this paper, a comparative study is carried out on various types of security methods used in the requirement phase of Software Development Life Cycle (SDLC) processes and on maturity model as well. Firstly, comparison of the Security Assurance Maturity Model (SAMM) with Building Security in Maturity Model (BSIMM) and Capability Maturity Model Integration (CMMI) is conducted for determining which maturity model is the best for implementation. Secondly, comparison between different software security methods is conducted to determine what method is suitable for security implementation in the Software Development Life Cycle requirement phase.