Channels ▼
RSS

Security

CMMI Extends Framework For Security


Organizational benchmarking body the CMMI Institute has extended the eponymously named development framework to address security concerns in software and systems development.

An August 2013 study of Ponemon Institute and Security Innovation found that "most software development organizations" (and by that presumably they include teams of all sizes up and down the land) do not consider security in the development process, leaving the end applications and products vulnerable.

CMMI for Development is a framework of practices designed to improve quality and reliability in development processes, and many users have included security efforts in CMMI adoptions.

This update claims to addresses security in a new way, with a set of practices "explicitly designed" to include security concerns in CMMI adoption and appraisals.

With the release of a technical report entitled "Security by Design with CMMI for Development V1.3: An Application Guide for Improving Processes for Secure Products", the CMMI framework is extended to include guidelines for including security requirements as quality criteria in the development process.

Specific new process areas include Organizational Preparedness for Secure Development, Security Management in Projects, Security Requirements and Technical Solution, and Security Verification and Validation.

"We understand that security issues concern every level of the technology-centered enterprise," said Kirk Botula, CEO, CMMI Institute. "At the institute, we are actively seeking ways to help CMMI users tailor the frameworks to best meet their organization's business goals. We are pleased to help organizations to develop operational resiliency against attacks by creating sustainable methods for developing secure products."


Related Reading


More Insights






Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dr. Dobb's encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dr. Dobb's moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing or spam. Dr. Dobb's further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

Video