Evaluation of the HAVOSS software process maturity model

Martin Höst, Martin Hell

Research output: Chapter in Book/Report/Conference proceedingPaper in conference proceedingpeer-review

104 Downloads (Pure)

Abstract

The HAVOSS (Handling Vulnerabilities in OSS) maturity model describes important processes for managing security vulnerabilities in OSS modules in developed products. So far, the model has not been evaluated in any real assessment process. Here we present a study where the model was evaluated by using it in assessments of processes for two product types in one organization. Each assessment was conducted in a focus group meeting where their procedures were analyzed. The evaluation was conducted by posing specific questions about the model during the focus group meetings and by investigating how difficult it was to assess the maturity of practices from the transcribed text. It was found that some practices were easy to assess, while other could be analysed separately for different parts of the products. Further work can be conducted on how assessments can be conducted and how they can be combined with other software security initiatives.
Original languageEnglish
Title of host publicationEuromicro Conference on Software Engineering and Advanced Applications (SEAA)
PublisherIEEE - Institute of Electrical and Electronics Engineers Inc.
Pages137-140
Number of pages4
ISBN (Electronic)978-1-7281-9532-2
DOIs
Publication statusPublished - 2020
EventEuromicro Conference on Software Engineering and Advanced Applications (SEAA), 2020 - Virtual conference, Portoroz, Slovenia
Duration: 2020 Aug 262020 Aug 28

Conference

ConferenceEuromicro Conference on Software Engineering and Advanced Applications (SEAA), 2020
Country/TerritorySlovenia
CityPortoroz
Period2020/08/262020/08/28

Subject classification (UKÄ)

  • Software Engineering

Fingerprint

Dive into the research topics of 'Evaluation of the HAVOSS software process maturity model'. Together they form a unique fingerprint.

Cite this