Security Testing in Application Development
Project Idea Metadata
- Project Idea Name: Security Testing in Application Development
- Date: 10/28/2021 11:25:03 AM
- Administrators:
Project Idea Description
Ausgangslage und Problemstellung
In software development, a lot is demanded from a developer. Time pressure is one of the problems where a developer inadvertently introduces vulnerabilities into his source code.
An attacker can exploit these vulnerabilities to harm an organization. Therefore, when developing software, it is essential to test it for vulnerabilities in the source code, logic, and input/output at an early stage, but also in the design phase so that IT security managers know about the requirements. However, there are many application security testing tools that can be used for different purposes.
But which tools should be used now, and which are crucial in the software development life cycle?
Ziel der Arbeit und erwartete Resultate
This paper examines different types of application security tools and reveals which purposes they are used for. Derived from this, the study examines in which phases in the software development lifecycle they can be used and explains precisely why.
From the results, a concept is developed that shows an abstract way to develop secure software.
This concept is then used to compare whether the ratings match or differ from those of a selected interviewee in the software development industry.
Gewünschte Methoden, Vorgehen
Using literature research, a solid basic knowledge of application security testing will be obtained.
The knowledge gained is used to create a concept for the secure development of software within the software development cycle.
Based on this result, a qualitative interview is conducted with a selected business partner.
Kreativität, Varianten, Innovation:
Define checklists, list tools, workflows, etc.
This paper examines different types of application security tools and reveals which purposes they are used for. Derived from this, the study examines in which phases in the software development lifecycle they can be used and explains precisely why.