Reducing Software Security Risk Through an Integrated Approach



The paper presents joint work by the California Institute of Technology’s Jet Propulsion Laboratory and the University of California at Davis (UC Davis) sponsored by the National Aeronautics and Space Administration Goddard Independent Verification and Validation Facility to develop a security assessment instrument for the software development and maintenance life cycle. The paper presents research on the generation of a software security assessment instrument to aid developers in assessing and assuring the security of software in the development and maintenance lifecycles.

The definitive version was published in Proceedings of the 26th Annual NASA Goddard Software Engineering Workshop, Nov. 2001.