Saved in:
Bibliographic Details
Main Authors: Arzt, Steven, Schreiber, Linda, Appelt, Dominik
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2406.04152
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916278002778112
author Arzt, Steven
Schreiber, Linda
Appelt, Dominik
author_facet Arzt, Steven
Schreiber, Linda
Appelt, Dominik
contents Software security has been an important research topic over the years. The community has proposed processes and tools for secure software development and security analysis. However, a significant number of vulnerabilities remains in real-world software-driven systems and products. To alleviate this problem, legislation is being established to oblige manufacturers, for example, to comply with essential security requirements and to establish appropriate development practices. We argue that software engineering research needs to provide better tools and support that helps industry comply with the new standards while retaining effcient processes. We argue for a stronger cooperation between legal scholars and computer scientists, and for bridging the gap between higher-level regulation and code-level engineering.
format Preprint
id arxiv_https___arxiv_org_abs_2406_04152
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Position: How Regulation Will Change Software Security Research
Arzt, Steven
Schreiber, Linda
Appelt, Dominik
Software Engineering
D.2.9
Software security has been an important research topic over the years. The community has proposed processes and tools for secure software development and security analysis. However, a significant number of vulnerabilities remains in real-world software-driven systems and products. To alleviate this problem, legislation is being established to oblige manufacturers, for example, to comply with essential security requirements and to establish appropriate development practices. We argue that software engineering research needs to provide better tools and support that helps industry comply with the new standards while retaining effcient processes. We argue for a stronger cooperation between legal scholars and computer scientists, and for bridging the gap between higher-level regulation and code-level engineering.
title Position: How Regulation Will Change Software Security Research
topic Software Engineering
D.2.9
url https://arxiv.org/abs/2406.04152