An Evaluation of the Product Security Maturity Model Through Case Studies at 15 Software Producing Organizations

Publication date

2024-02-09

Authors

Baninemeh, ElenaISNI 000000051776213X
Toomey, Harold
Labunets, KatsiarynaORCID 0000-0003-0884-2440ISNI 0000000512551923
Wagenaar, GerardORCID 0000-0001-6982-7282ISNI 000000050779789X
Jansen, R.L.ORCID 0000-0003-3752-2868ISNI 000000039050399X

Editors

Hyrynsalmi, Sami
Münch, Jürgen
Smolander, Kari
Melegati, Jorge

Advisors

Supervisors

Document Type

Part of book
Open Access logo

License

cc_by

Abstract

Cybersecurity is becoming increasingly important from a software business perspective. The software that is produced and sold generally becomes part of a complex landscape of customer applications and enlarges the risk that customer organizations take. Increasingly, software producing organizations are realizing that they are on the front lines of the cybersecurity battles. Maintaining security in a software product and software production process directly influences the livelihood of a software business. There are many models for evaluating security of software products. The product security maturity model is commonly used in the industry but has not received academic recognition. In this paper we report on the evaluation of the product security maturity model on usefulness, applicability, and effectiveness. The evaluation has been performed through 15 case studies. We find that the model, though rudimentary, serves medium to large organizations well and that the model is not so applicable within smaller organizations.

Keywords

product security maturity model, software engineering security, software product security

Citation

Baninemeh, E, Toomey, H, Labunets, K, Wagenaar, G & Jansen, S 2024, An Evaluation of the Product Security Maturity Model Through Case Studies at 15 Software Producing Organizations. in S Hyrynsalmi, J Münch, K Smolander & J Melegati (eds), Software Business - 14th International Conference, ICSOB 2023, Proceedings. Lecture Notes in Business Information Processing, vol. 500 LNBIP, Springer, pp. 327-343. https://doi.org/10.1007/978-3-031-53227-6_23