Projects per year
Abstract
The HAVOSS (Handling Vulnerabilities in OSS) maturity model describes important processes for managing security vulnerabilities in OSS modules in developed products. So far, the model has not been evaluated in any real assessment process. Here we present a study where the model was evaluated by using it in assessments of processes for two product types in one organization. Each assessment was conducted in a focus group meeting where their procedures were analyzed. The evaluation was conducted by posing specific questions about the model during the focus group meetings and by investigating how difficult it was to assess the maturity of practices from the transcribed text. It was found that some practices were easy to assess, while other could be analysed separately for different parts of the products. Further work can be conducted on how assessments can be conducted and how they can be combined with other software security initiatives.
Original language | English |
---|---|
Title of host publication | Euromicro Conference on Software Engineering and Advanced Applications (SEAA) |
Publisher | IEEE - Institute of Electrical and Electronics Engineers Inc. |
Pages | 137-140 |
Number of pages | 4 |
ISBN (Electronic) | 978-1-7281-9532-2 |
DOIs | |
Publication status | Published - 2020 |
Event | Euromicro Conference on Software Engineering and Advanced Applications (SEAA), 2020 - Virtual conference, Portoroz, Slovenia Duration: 2020 Aug 26 → 2020 Aug 28 |
Conference
Conference | Euromicro Conference on Software Engineering and Advanced Applications (SEAA), 2020 |
---|---|
Country/Territory | Slovenia |
City | Portoroz |
Period | 2020/08/26 → 2020/08/28 |
Subject classification (UKÄ)
- Software Engineering
Fingerprint
Dive into the research topics of 'Evaluation of the HAVOSS software process maturity model'. Together they form a unique fingerprint.Projects
- 2 Finished
-
HATCH: HATCH: Handling Vulnerabilities in the Value Chain
Höst, M. (PI) & Hell, M. (Researcher)
Swedish Government Agency for Innovation Systems (Vinnova)
2018/11/30 → 2021/11/30
Project: Research
-
SMARTY: Säkra mjukvaruuppdateringar för den smarta staden
Hell, M. (PI), Magnusson, B. (PI), Gehrmann, C. (CoI), Paladi, N. (Researcher), Karlsson, L. (Researcher), Sönnerup, J. (Researcher), Johnsson, B. A. (Researcher), Hedin, G. (Researcher), Nordahl, M. (Researcher), Pagnin, E. (Researcher), Kundu, R. (Researcher), Åkesson, A. (Researcher), Stankovski Wagner, P. (Researcher) & Ramezanian, S. (Researcher)
Swedish Foundation for Strategic Research, SSF
2018/03/01 → 2024/12/31
Project: Research