Academic Journal

Impact of security assessment for more secure software – a tactics and multi-dimensional perspective.

Λεπτομέρειες βιβλιογραφικής εγγραφής
Τίτλος: Impact of security assessment for more secure software – a tactics and multi-dimensional perspective.
Συγγραφείς: Ali, Mohammad1 (AUTHOR) ali792334@gmail.com, Uddin, Md Sala2 (AUTHOR), Uddin, Nayeem3 (AUTHOR), Hasan, Md Mahbub3 (AUTHOR)
Πηγή: Information Security Journal: A Global Perspective. May2026, p1-15. 15p. 3 Illustrations.
Θεματικοί όροι: *Risk assessment, *Computer software development, *Computer security vulnerabilities, Warnings
Περίληψη: Security assessment activities in the software development life cycle (SDLC) are often carried out in a fragmented manner, where requirements prioritization, threat identification, and risk scoring are treated as separate steps and provide limited traceability to actionable mitigation. This paper proposes an integrated SDLC-oriented security assessment framework that unifies security requirements prioritization, structured threat modeling, quantitative risk scoring, and pattern-guided mitigation within a single workflow. The framework prioritizes security requirements using SQUARE/CLASP, identifies threats using STRIDE, and prioritizes risks using DREAD. High-priority threats are then mapped to a mitigation workflow guided by security patterns (Detect–Block–Respond–Recover), supporting iterative reassessment across development stages. The framework is evaluated using STRIDE/DREAD-based threat simulations across six STRIDE threat categories and quantified using the proposed improvement metric. The results indicate an average increase of 27–35% in overall security effectiveness and a consistent shift of high-severity risks toward medium/low levels across the evaluated cases. Overall, the proposed workflow provides a practical and repeatable approach for integrating requirements, threat modeling, and mitigation decision-making across the SDLC. [ABSTRACT FROM AUTHOR]
Copyright of Information Security Journal: A Global Perspective is the property of Taylor & Francis Ltd and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Βάση Δεδομένων: Business Source Index
FullText Text:
  Availability: 0
CustomLinks:
  – Url: https://resolver.ebsco.com/c/fiv2js/result?sid=EBSCO:bsx&genre=article&issn=19393555&ISBN=&volume=&issue=&date=20260507&spage=1&pages=1-15&title=Information Security Journal: A Global Perspective&atitle=Impact%20of%20security%20assessment%20for%20more%20secure%20software%20%E2%80%93%20a%20tactics%20and%20multi-dimensional%20perspective.&aulast=Ali%2C%20Mohammad&id=DOI:10.1080/19393555.2026.2667311
    Name: Full Text Finder (for New FTF UI) (ns324271)
    Category: fullText
    Text: Full Text Finder
    MouseOverText: Full Text Finder
Header DbId: bsx
DbLabel: Business Source Index
An: 193483963
RelevancyScore: 1412
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 1411.61413574219
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Impact of security assessment for more secure software – a tactics and multi-dimensional perspective.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Ali%2C+Mohammad%22">Ali, Mohammad</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> ali792334@gmail.com</i><br /><searchLink fieldCode="AR" term="%22Uddin%2C+Md+Sala%22">Uddin, Md Sala</searchLink><relatesTo>2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Uddin%2C+Nayeem%22">Uddin, Nayeem</searchLink><relatesTo>3</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Hasan%2C+Md+Mahbub%22">Hasan, Md Mahbub</searchLink><relatesTo>3</relatesTo> (AUTHOR)
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Information+Security+Journal%3A+A+Global+Perspective%22">Information Security Journal: A Global Perspective</searchLink>. May2026, p1-15. 15p. 3 Illustrations.
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: *<searchLink fieldCode="DE" term="%22Risk+assessment%22">Risk assessment</searchLink><br />*<searchLink fieldCode="DE" term="%22Computer+software+development%22">Computer software development</searchLink><br />*<searchLink fieldCode="DE" term="%22Computer+security+vulnerabilities%22">Computer security vulnerabilities</searchLink><br /><searchLink fieldCode="DE" term="%22Warnings%22">Warnings</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Security assessment activities in the software development life cycle (SDLC) are often carried out in a fragmented manner, where requirements prioritization, threat identification, and risk scoring are treated as separate steps and provide limited traceability to actionable mitigation. This paper proposes an integrated SDLC-oriented security assessment framework that unifies security requirements prioritization, structured threat modeling, quantitative risk scoring, and pattern-guided mitigation within a single workflow. The framework prioritizes security requirements using SQUARE/CLASP, identifies threats using STRIDE, and prioritizes risks using DREAD. High-priority threats are then mapped to a mitigation workflow guided by security patterns (Detect–Block–Respond–Recover), supporting iterative reassessment across development stages. The framework is evaluated using STRIDE/DREAD-based threat simulations across six STRIDE threat categories and quantified using the proposed improvement metric. The results indicate an average increase of 27–35% in overall security effectiveness and a consistent shift of high-severity risks toward medium/low levels across the evaluated cases. Overall, the proposed workflow provides a practical and repeatable approach for integrating requirements, threat modeling, and mitigation decision-making across the SDLC. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Information Security Journal: A Global Perspective is the property of Taylor & Francis Ltd and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=bsx&AN=193483963
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1080/19393555.2026.2667311
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 15
        StartPage: 1
    Subjects:
      – SubjectFull: Risk assessment
        Type: general
      – SubjectFull: Computer software development
        Type: general
      – SubjectFull: Computer security vulnerabilities
        Type: general
      – SubjectFull: Warnings
        Type: general
    Titles:
      – TitleFull: Impact of security assessment for more secure software – a tactics and multi-dimensional perspective.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Ali, Mohammad
      – PersonEntity:
          Name:
            NameFull: Uddin, Md Sala
      – PersonEntity:
          Name:
            NameFull: Uddin, Nayeem
      – PersonEntity:
          Name:
            NameFull: Hasan, Md Mahbub
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 07
              M: 05
              Text: May2026
              Type: published
              Y: 2026
          Identifiers:
            – Type: issn-print
              Value: 19393555
          Titles:
            – TitleFull: Information Security Journal: A Global Perspective
              Type: main
ResultId 1