Security Measurement and Analysis
• Presentation
Publisher
Software Engineering Institute
Topic or Tag
Abstract
For several years, the software engineering community has been working to identify practices aimed at developing more secure software. Although some foundational work has been performed, efforts to measure software security assurance have yet to materialize in any substantive fashion. As a result, decision-makers (e.g., development program and project managers, acquisition program offices) lack confidence in the security characteristics of their software infrastructures.
The CERT Program at Carnegie Mellon University’s Software Engineering Institute (SEI) has chartered the Security Measurement and Analysis (SMA) Project to advance the state of the practice in security measurement and analysis.
The objective of the SMA Project is to develop frameworks, methods, and tools for measuring and monitoring the security of large-scale, networked systems across the life cycle and supply chain.