Back to Search Start Over

HAVOSS: A Maturity Model for Handling Vulnerabilities in Third Party OSS Components

Authors :
Nikbakht Bideh, Pegah
Höst, Martin
Hell, Martin
Nikbakht Bideh, Pegah
Höst, Martin
Hell, Martin
Source :
Lecture Notes in Computer Science; 11271, pp 81-97 (2018); ISSN: 0302-9743
Publication Year :
2018

Abstract

Security has been recognized as a leading barrier for IoT adoption. The growing number of connected devices and reported software vulnerabilities increases the importance firmware updates. Maturity models for software security do include parts of this, but are lacking in several aspects. This paper presents and evaluates a maturity model (HAVOSS) for handling vulnerabilities in third party OSS and COTS components. The maturity model was designed by first reviewing industry interviews, current best practice guidelines and other maturity models. After that, the practices were refined through industry interviews, resulting in six capability areas covering in total 21 practices. These were then evaluated based on their importance according to industry experts. It is shown that the practices are seen as highly important, indicating that the model can be seen as a valuable tool when assessing strengths and weaknesses in an organization's ability to handle firmware updates.

Details

Database :
OAIster
Journal :
Lecture Notes in Computer Science; 11271, pp 81-97 (2018); ISSN: 0302-9743
Notes :
application/pdf, English
Publication Type :
Electronic Resource
Accession number :
edsoai.on1065536461
Document Type :
Electronic Resource