Managing security debt across PLC phases in a VSE context

dc.contributor.authorLarrucea, Xabier
dc.contributor.authorSantamaria, Izaskun
dc.contributor.authorFernandez-Gauna, Borja
dc.contributor.institutionTecnalia Research & Innovation
dc.contributor.institutionSWT
dc.date.accessioned2024-07-24T12:05:28Z
dc.date.available2024-07-24T12:05:28Z
dc.date.issued2020-03-01
dc.descriptionPublisher Copyright: © 2019 John Wiley & Sons, Ltd.
dc.description.abstractNowadays, security and safety aspects are two of the major concerns for any software system development, especially while developing safety critical systems. This is especially relevant for very small entities because they have a limited amount of resources for dealing with all these aspects at the same time. In addition, these systems are highly regulated domains, and they involve a huge set of standards focused on safety and security-related issues. Therefore, these small entities are not only facing hurdles related to technical aspects but also from the so-called technical debt when overarching a critical development. This paper extends the assurance cases approach by integrating security aspects within the life cycle, and it proposes a framework for managing the associated security technical debt for very small entities. A tool chain is outlined, and the approach is illustrated with an industrial use case.en
dc.description.statusPeer reviewed
dc.identifier.citationLarrucea , X , Santamaria , I & Fernandez-Gauna , B 2020 , ' Managing security debt across PLC phases in a VSE context ' , Journal of software: Evolution and Process , vol. 32 , no. 3 , e2214 . https://doi.org/10.1002/smr.2214
dc.identifier.doi10.1002/smr.2214
dc.identifier.issn1532-060X
dc.identifier.urihttps://hdl.handle.net/11556/3561
dc.identifier.urlhttp://www.scopus.com/inward/record.url?scp=85080983685&partnerID=8YFLogxK
dc.language.isoeng
dc.relation.ispartofJournal of software: Evolution and Process
dc.rightsinfo:eu-repo/semantics/restrictedAccess
dc.subject.keywordsassurance case
dc.subject.keywordsISO/IEC 29110
dc.subject.keywordssafety
dc.subject.keywordssecurity
dc.subject.keywordstechnical debt
dc.subject.keywordsSoftware
dc.titleManaging security debt across PLC phases in a VSE contexten
dc.typejournal article
Files