Fucci, Davide und Alegroth, Emil und Felderer, Michael und Johannesson, Christoffer (2024) Evaluating software security maturity using OWASP SAMM: Different approaches and stakeholders perceptions. Journal of Systems and Software, 214 (112062). Elsevier. doi: 10.1016/j.jss.2024.112062. ISSN 0164-1212.
PDF
- Verlagsversion (veröffentlichte Fassung)
3MB |
Kurzfassung
Background: Recent years have seen a surge in cyber-attacks, which can be prevented or mitigated using software security activities. OWASP SAMM is a maturity model providing a versatile way for companies to assess their security posture and plan for improvements. Objective: We perform an initial SAMM assessment in collaboration with a company in the financial domain. Our objective is to assess a holistic inventory of the company security-related activities, focusing on how different roles perform the assessment and how they perceive the instrument used in the process. Methodology: We perform a case study to collect data using SAMM in a lightweight and novel manner through assessment using an online survey with 17 participants and a focus group with seven participants. Results: We show that different roles perceive maturity differently and that the two assessments deviate only for specific practices making the lightweight approach a viable and efficient solution in industrial practice. Our results indicate that the questions included in the SAMM assessment tool are answered easily and confidently across most roles. Discussion: Our results suggest that companies can productively use a lightweight SAMM assessment. We provide nine lessons learned for guiding industrial practitioners in the evaluation of their current security posture as well as for academics wanting to utilize SAMM as a research tool in industrial settings.
elib-URL des Eintrags: | https://elib.dlr.de/211275/ | ||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Dokumentart: | Zeitschriftenbeitrag | ||||||||||||||||||||
Titel: | Evaluating software security maturity using OWASP SAMM: Different approaches and stakeholders perceptions | ||||||||||||||||||||
Autoren: |
| ||||||||||||||||||||
Datum: | August 2024 | ||||||||||||||||||||
Erschienen in: | Journal of Systems and Software | ||||||||||||||||||||
Referierte Publikation: | Ja | ||||||||||||||||||||
Open Access: | Ja | ||||||||||||||||||||
Gold Open Access: | Nein | ||||||||||||||||||||
In SCOPUS: | Ja | ||||||||||||||||||||
In ISI Web of Science: | Ja | ||||||||||||||||||||
Band: | 214 | ||||||||||||||||||||
DOI: | 10.1016/j.jss.2024.112062 | ||||||||||||||||||||
Verlag: | Elsevier | ||||||||||||||||||||
ISSN: | 0164-1212 | ||||||||||||||||||||
Status: | veröffentlicht | ||||||||||||||||||||
Stichwörter: | OWASP SAMM; Industry-academia collaboration; Software security | ||||||||||||||||||||
HGF - Forschungsbereich: | Luftfahrt, Raumfahrt und Verkehr | ||||||||||||||||||||
HGF - Programm: | Raumfahrt | ||||||||||||||||||||
HGF - Programmthema: | Technik für Raumfahrtsysteme | ||||||||||||||||||||
DLR - Schwerpunkt: | Raumfahrt | ||||||||||||||||||||
DLR - Forschungsgebiet: | R SY - Technik für Raumfahrtsysteme | ||||||||||||||||||||
DLR - Teilgebiet (Projekt, Vorhaben): | R - Digitale Transformation in der Raumfahrt [SY] | ||||||||||||||||||||
Standort: | Oberpfaffenhofen | ||||||||||||||||||||
Institute & Einrichtungen: | Institut für Softwaretechnologie | ||||||||||||||||||||
Hinterlegt von: | Felderer, Michael | ||||||||||||||||||||
Hinterlegt am: | 20 Dez 2024 12:27 | ||||||||||||||||||||
Letzte Änderung: | 06 Jan 2025 09:22 |
Nur für Mitarbeiter des Archivs: Kontrollseite des Eintrags