Abstract:
The automotive industry today has increasingly more requirements regarding cybersecurity. There is a need to be able to trace these requirements throughout software devel...Show MoreMetadata
Abstract:
The automotive industry today has increasingly more requirements regarding cybersecurity. There is a need to be able to trace these requirements throughout software development and testing. A common approach is to use ALM (application lifecycle management) tools to manage activities in the software development lifecycle. In this paper, we present the concept of using information from ALM tools, such as security requirements and test cases, to run application security testing tools with appropriate configurations and finally incorporating the results from the testing tools back into the ALM tools. The benefit is that it is possible to verify that a requirement has been fulfilled by tracing the results from the testing tools back to the requirements. The process can be automated since automated tools are used. We also built a prototype to showcase the applicability of the concept. This approach saves time and effort and allows for traceability of security requirements.
Published in: 2019 IEEE 19th International Conference on Software Quality, Reliability and Security Companion (QRS-C)
Date of Conference: 22-26 July 2019
Date Added to IEEE Xplore: 07 October 2019
ISBN Information: