12.07.2015 Views

A Process Research Framework - Software Engineering Institute ...

A Process Research Framework - Software Engineering Institute ...

A Process Research Framework - Software Engineering Institute ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Appendix[Beznosov 2005]Beznosov, K. & Kruchten, P. “Towards Agile Security Assurance,”47–54. Proceedings of the 2004 Workshop on New Security Paradigms.White Point Beach Resort, Nova Scotia, Canada, September20–23, 2004. New York, NY: ACM Press, 2005.[Davis 2004]Davis, N., et al. “<strong>Process</strong>es for Producing Secure <strong>Software</strong>:Summary of US National Cybersecurity Summit Subgroup Report.”IEEE Security & Privacy, IEEE, 2004.[Davis 2006]Davis, N. Secure <strong>Software</strong> Development Life Cycle <strong>Process</strong>es.https://buildsecurityin.us-cert.gov/portal/article/knowledge/sdlc_process/secure_SDLC_processes.xml (2006).[DHS 2006]Department of Homeland Security. Build Security In.https://buildsecurityin.us-cert.gov/portal/index.html (2006).[Howard 2006]Howard, M. & Lipner, S. The Security Development Lifecycle.Redmond, WA (USA): Microsoft Press, 2006 (ISBN 0735622140).[Jarzombek 2006]Jarzombek, J. & Goertzel, K. M. “Security in the <strong>Software</strong> Life Cycle.”Crosstalk: The Journal of Defense <strong>Software</strong> <strong>Engineering</strong> (September 2006).http://www.stsc.hill.af.mil/Crosstalk/2006/09/0609JarzombekGoertzel.html.[Lipner 2005]Lipner, S. & Howard, M. The Trustworthy Computing Security DevelopmentLifecycle. http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnsecure/html/sdl.asp (2005).[Lipson 2006]Lipson, H. Evolutionary Design of Secure Systems—The First Step isRecognizing the Need for Change (2006). https://buildsecurityin.us-cert.gov/portal/article/bestpractices/Assembly_Integration_And_Evolution (2006).[McGraw 2006]McGraw, G. <strong>Software</strong> Security: Building Security In. Boston,MA (USA): Addison-Wesley, 2006.IPRC <strong>Framework</strong> | Further Reading and References 149

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!