Risk-Based Measurement and Analysis: Application to Software Security
Christopher Alberts, Julia Allen, Robert H. Stoddard · 2012
For several years, the software engineering community has been working to identify practices aimed at developing more secure software.Although some foundational work has been performed, efforts to measure software security assurance have yet to materialize in any substantive fashion.As a result, decision makers (e.g., development program and project managers, acquisition program offices) lack confidence in the security characteristics of their software-reliant systems.The