Continuous Secure Software Development and Analysis

Schulz, Sophie ORCID iD icon; Reiche, Frederik ORCID iD icon; Hahner, Sebastian ORCID iD icon; Schiffl, Jonas ORCID iD icon


Software security becomes increasingly important nowadays. Security should be considered as early as
possible in the software development. However, considering different aspects of security is a complex
task. In this paper, we propose an extendable framework for continuous secure software development
and evolution. The framework provides interconnected analyses on different stages of development.
Explicit assumption management helps to verify the security requirements more properly. Thus, the
security of the system under development can be estimated more accurately. Finally, the concrete assumptions also help to identify and close security gaps that arise during the software’s lifetime.

