Claim Missing Document
Check
Articles

Found 1 Documents
Search
Journal : Engineering, Mathematics and Computer Science Journal (EMACS)

Combining Academia and Industry Approach for Secure Coding and Requirements Checklist in S-SDLC: Systematic Literature Review Anderies, Anderies; Rachmawati, Ika Dyah Agustia; Jingga, Kenny; Candra, Calvin Linardy
Engineering, MAthematics and Computer Science Journal (EMACS) Vol. 7 No. 2 (2025): EMACS
Publisher : Bina Nusantara University

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.21512/emacsjournal.v7i2.13429

Abstract

Rapid progress of digital transformation has occurred governments, organization and vendors around the world. where this rapid digital transformation is not linearly followed by the security protection of digital infrastructure and its application. For example, in Indonesia One of the largest banks was unable to operate its online and physical services for three consecutive days due to a cyber-attack. And many international organizations also experienced the same thing or even worse like bankruptcy. Because of this phenomenon the authors have performed a systematic literature review and identified there are two important phases namely requirement and coding in secure software development lifecycle (S-SDLC). In this study the authors compose 18 Secure Requirement practices (SREC) and 72 Secure Coding Checklist (SCOC) checklist based on Combining previous academia research study and international standard of open secure coding practices (OSCP) in which we target the security vulnerable most occurred to governments, organization and vendors around the world according to Open Web Application Security Project Foundation.  This checklist can be embedded in the Quality Assurance process to check in sequence whether the Requirements and Coding that are produced are safe or not from the cyber-attack. Additionally, the checklist approach is simple to understand and can be implemented to a popular public consumer automation testing tools enabling faster software development while maintaining software security.