2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET) 2021
DOI: 10.1109/icse-seet52601.2021.00019
|View full text |Cite
|
Sign up to set email alerts
|

Structuring a Comprehensive Software Security Course Around the OWASP Application Security Verification Standard

Abstract: Lack of security expertise among software practitioners is a problem with many implications. First, there is a deficit of security professionals to meet current needs. Additionally, even practitioners who do not plan to work in security may benefit from increased understanding of security. The goal of this paper is to aid software engineering educators in designing a comprehensive software security course by sharing an experience running a software security course for the eleventh time.Through all the eleven y… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
2
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
4
2
1

Relationship

1
6

Authors

Journals

citations
Cited by 10 publications
(2 citation statements)
references
References 20 publications
0
2
0
Order By: Relevance
“…Collecting data for this study required a team of four graduate students a combined eleven months of full-time work and twenty months of part-time work; four months part-time work from an undergraduate student; and the results of assignments from a large graduate-level software security course. Our experiences in structuring the software security course have been reported previously in Elder et al [26].…”
Section: Introductionmentioning
confidence: 76%
“…Collecting data for this study required a team of four graduate students a combined eleven months of full-time work and twenty months of part-time work; four months part-time work from an undergraduate student; and the results of assignments from a large graduate-level software security course. Our experiences in structuring the software security course have been reported previously in Elder et al [26].…”
Section: Introductionmentioning
confidence: 76%
“…According to [98], some of the software security maturity models include Open Web Application Security Project (OWASP)'s Software Assurance Maturity Model (OpenSAMM), Building Security In Maturity Model (BSIMM) and BSIMM for vendors (vBSIMM). However, these security-specific maturity models and their checklists are not adequate in all contexts [99].…”
Section: Security Models and Frameworkmentioning
confidence: 99%