Academic Journal
Impact of security assessment for more secure software – a tactics and multi-dimensional perspective.
| Τίτλος: | Impact of security assessment for more secure software – a tactics and multi-dimensional perspective. |
|---|---|
| Συγγραφείς: | Ali, Mohammad1 (AUTHOR) ali792334@gmail.com, Uddin, Md Sala2 (AUTHOR), Uddin, Nayeem3 (AUTHOR), Hasan, Md Mahbub3 (AUTHOR) |
| Πηγή: | Information Security Journal: A Global Perspective. May2026, p1-15. 15p. 3 Illustrations. |
| Θεματικοί όροι: | *Risk assessment, *Computer software development, *Computer security vulnerabilities, Warnings |
| Περίληψη: | Security assessment activities in the software development life cycle (SDLC) are often carried out in a fragmented manner, where requirements prioritization, threat identification, and risk scoring are treated as separate steps and provide limited traceability to actionable mitigation. This paper proposes an integrated SDLC-oriented security assessment framework that unifies security requirements prioritization, structured threat modeling, quantitative risk scoring, and pattern-guided mitigation within a single workflow. The framework prioritizes security requirements using SQUARE/CLASP, identifies threats using STRIDE, and prioritizes risks using DREAD. High-priority threats are then mapped to a mitigation workflow guided by security patterns (Detect–Block–Respond–Recover), supporting iterative reassessment across development stages. The framework is evaluated using STRIDE/DREAD-based threat simulations across six STRIDE threat categories and quantified using the proposed improvement metric. The results indicate an average increase of 27–35% in overall security effectiveness and a consistent shift of high-severity risks toward medium/low levels across the evaluated cases. Overall, the proposed workflow provides a practical and repeatable approach for integrating requirements, threat modeling, and mitigation decision-making across the SDLC. [ABSTRACT FROM AUTHOR] |
| Copyright of Information Security Journal: A Global Perspective is the property of Taylor & Francis Ltd and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Βάση Δεδομένων: | Business Source Index |
| FullText | Text: Availability: 0 CustomLinks: – Url: https://resolver.ebsco.com/c/fiv2js/result?sid=EBSCO:bsx&genre=article&issn=19393555&ISBN=&volume=&issue=&date=20260507&spage=1&pages=1-15&title=Information Security Journal: A Global Perspective&atitle=Impact%20of%20security%20assessment%20for%20more%20secure%20software%20%E2%80%93%20a%20tactics%20and%20multi-dimensional%20perspective.&aulast=Ali%2C%20Mohammad&id=DOI:10.1080/19393555.2026.2667311 Name: Full Text Finder (for New FTF UI) (ns324271) Category: fullText Text: Full Text Finder MouseOverText: Full Text Finder |
|---|---|
| Header | DbId: bsx DbLabel: Business Source Index An: 193483963 RelevancyScore: 1412 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 1411.61413574219 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Impact of security assessment for more secure software – a tactics and multi-dimensional perspective. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Ali%2C+Mohammad%22">Ali, Mohammad</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> ali792334@gmail.com</i><br /><searchLink fieldCode="AR" term="%22Uddin%2C+Md+Sala%22">Uddin, Md Sala</searchLink><relatesTo>2</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Uddin%2C+Nayeem%22">Uddin, Nayeem</searchLink><relatesTo>3</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Hasan%2C+Md+Mahbub%22">Hasan, Md Mahbub</searchLink><relatesTo>3</relatesTo> (AUTHOR) – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Information+Security+Journal%3A+A+Global+Perspective%22">Information Security Journal: A Global Perspective</searchLink>. May2026, p1-15. 15p. 3 Illustrations. – Name: Subject Label: Subject Terms Group: Su Data: *<searchLink fieldCode="DE" term="%22Risk+assessment%22">Risk assessment</searchLink><br />*<searchLink fieldCode="DE" term="%22Computer+software+development%22">Computer software development</searchLink><br />*<searchLink fieldCode="DE" term="%22Computer+security+vulnerabilities%22">Computer security vulnerabilities</searchLink><br /><searchLink fieldCode="DE" term="%22Warnings%22">Warnings</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: Security assessment activities in the software development life cycle (SDLC) are often carried out in a fragmented manner, where requirements prioritization, threat identification, and risk scoring are treated as separate steps and provide limited traceability to actionable mitigation. This paper proposes an integrated SDLC-oriented security assessment framework that unifies security requirements prioritization, structured threat modeling, quantitative risk scoring, and pattern-guided mitigation within a single workflow. The framework prioritizes security requirements using SQUARE/CLASP, identifies threats using STRIDE, and prioritizes risks using DREAD. High-priority threats are then mapped to a mitigation workflow guided by security patterns (Detect–Block–Respond–Recover), supporting iterative reassessment across development stages. The framework is evaluated using STRIDE/DREAD-based threat simulations across six STRIDE threat categories and quantified using the proposed improvement metric. The results indicate an average increase of 27–35% in overall security effectiveness and a consistent shift of high-severity risks toward medium/low levels across the evaluated cases. Overall, the proposed workflow provides a practical and repeatable approach for integrating requirements, threat modeling, and mitigation decision-making across the SDLC. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Information Security Journal: A Global Perspective is the property of Taylor & Francis Ltd and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=bsx&AN=193483963 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1080/19393555.2026.2667311 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 15 StartPage: 1 Subjects: – SubjectFull: Risk assessment Type: general – SubjectFull: Computer software development Type: general – SubjectFull: Computer security vulnerabilities Type: general – SubjectFull: Warnings Type: general Titles: – TitleFull: Impact of security assessment for more secure software – a tactics and multi-dimensional perspective. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Ali, Mohammad – PersonEntity: Name: NameFull: Uddin, Md Sala – PersonEntity: Name: NameFull: Uddin, Nayeem – PersonEntity: Name: NameFull: Hasan, Md Mahbub IsPartOfRelationships: – BibEntity: Dates: – D: 07 M: 05 Text: May2026 Type: published Y: 2026 Identifiers: – Type: issn-print Value: 19393555 Titles: – TitleFull: Information Security Journal: A Global Perspective Type: main |
| ResultId | 1 |