Software Security Mapping Framework: Operationalization of Security Requirements
This paper introduces a structured framework designed to translate abstract software security principles into concrete, actionable practices. Developed through collaborative research with academic and industry experts, the framework systematically maps 131 security requirements from various standards (including ISM, NIST SSDF, and SLSA) to over 400 detailed operational steps across the software development lifecycle. It uses a goal-oriented approach to establish traceable links between four core strategic goals (Secure Environment, Secure Development, Software Traceability, and Vulnerability Management) and specific tasks, assigning clear responsibilities and implementation phases. The framework's practical utility is demonstrated through a case study on the Log4j vulnerability, and it is provided in a machine-readable OSCAL format to support automation and tool integration, helping organizations effectively navigate and implement supply chain security practices.
Comments
Post a Comment