作者: Radek Fujdiak , Petr Mlynek , Pavel Mrnustik , Maros Barabas , Petr Blazek
DOI: 10.1109/NTMS.2019.8763845
关键词:
摘要: Nowadays, software development is a more complex process than ever was and it faces the challenges, where security became one of most crucial. The issues an essential part engineers understanding vulnerabilities, risks others everyday bread. needs in resulted creation so-called Secure Software Development Life Cycle (SSDLC). This methodological concept included classical Life-Cycle, which described by five main phases - analysis, design, implementation (building), testing, evaluation (deployment maintenance). SSDLC adds another dimension ensuring security. We introduce our same named tool "Secure Life-cycle", follows general idea goes beyond it. Our helps to create security, hardening, validation reporting guidelines for selected use-cases. environment defining current future requirements based on collection standards, recommendations, best practice, many others. Connecting with other tools improves level automation Product (PLC). gives connection context among safety performance parameters. Compared static definition, provides simple extension straight integration PLC non- or nearly-non personal (human) interaction.