Skip to main content

Advertisement

Log in

What Software Security Means to Business

  • Dokumentation
  • Published:
Datenschutz und Datensicherheit - DuD Aims and scope Submit manuscript

Abstract

Software security: we know we want it, we make choices and tradeoffs that have implications for it, yet, in a general sense, it has escaped true definition and defied measurement. Definition and measurement though are sequential, meaning that something must be defined to make any comparisons against it. In a technical sense, many have positioned software security as protecting the confidentiality, integrity and availability of data, resources and sometimes the application itself. This „definition” tries to capture security broadly but in practice the importance of these things — and the value that defending them has to an organization — varies wildly.

More important than defining what security is, we need to capture what it means in context, and what it costs. The only definition that really matters to the enterprise then is one that deals with the contextual nature of security, risk, and pain. This paper is an attempt to explore what software security means to enterprises. Its purpose is to lay the foundation for software security metrics that are truly actionable by the business community to help drive security decisions for the software they buy, build, and outsource. The thoughts, ideas, insights and proposals here come from the members of the Application Security Industry Consortium (AppSIC)0, a group of software security executives, researchers, analysts and practitioners from the vendor, enterprise consumer, academic, and analyst communities. Our intention in writing it is to spur debate on the topic, and, through the input of the community, create a foundation upon which to build software security metrics that are meaningful to business.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Subscribe and save

Springer+ Basic
$34.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Price excludes VAT (USA)
Tax calculation will be finalised during checkout.

Instant access to the full article PDF.

Similar content being viewed by others

Literatur

  • Application Security Industry Consortium, AppSIC, www.appsic.org.

  • G. Stoneburner, A. Goguen, and A. Feringa „Risk Management Guide for Information Technology Systems” p. 8, National Institute of Standards (NIST) Special Publication 800-30, 2002.

Download references

Author information

Consortia

Rights and permissions

Reprints and permissions

About this article

Cite this article

Members of the Application Security Industry Consortium (AppSIC). What Software Security Means to Business. DuD 30, 632–635 (2006). https://doi.org/10.1007/s11623-006-0163-9

Download citation

  • Published:

  • Issue Date:

  • DOI: https://doi.org/10.1007/s11623-006-0163-9

Keywords