A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector

Every year, web applications have expanded their presence in more areas in financial organizations, health organizations, public sector, retail and accommodation. Security is important in data protection so as not to be infringed by unauthorized parties. If the vulnerabilities found are not amended,...

Full description

Saved in:
Bibliographic Details
Main Authors: Jakeri, M.M., Hassan, M.F.
Format: Conference or Workshop Item
Published: Institute of Electrical and Electronics Engineers Inc. 2019
Online Access:https://www.scopus.com/inward/record.uri?eid=2-s2.0-85062892016&doi=10.1109%2fIISA.2018.8631401&partnerID=40&md5=57c179c388d5f3c164ee925197e514ac
http://eprints.utp.edu.my/23505/
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.utp.eprints.23505
record_format eprints
spelling my.utp.eprints.235052021-08-19T07:45:47Z A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector Jakeri, M.M. Hassan, M.F. Every year, web applications have expanded their presence in more areas in financial organizations, health organizations, public sector, retail and accommodation. Security is important in data protection so as not to be infringed by unauthorized parties. If the vulnerabilities found are not amended, it leads to cyber-attacks such as Structured Query Language Injection Attack (SQLIA) performed by certain parties which enable them to gain unauthorized data access. To cater security issues, variety of security frameworks for secure software development life cycle (SDLC) were introduced. Secure SDLC is created by integrating security-related activities to an each phase of in used development methodologies such as waterfall model or agile model. However, the application security problem continues to grow. Strict, complicated and heavyweight frameworks are underutilized due to several factors. The factors that influence the implementation of secure SDLC identified in public sector (the scope is State Secretary Offices in Malaysia) are inadequate development timeline, improper development team size and less awareness of team members' workload. It is agreed that integrating security at earlier (requirement and design) phase is the most effective and cheapest way to develop secure web application. Hence, an adaptive secure SDLC model is proposed to integrate security activities using Fuzzy Analytic Hierarchy Process (FAHP) focusing on the influence factors as the main criteria and meet the international and local secure frameworks standards. The proposed model will recommend adaptive security activities as a guideline to be applied at earlier phases of SDLC to help eliminate/ minimize the web application vulnerabilities and increase the application security and implemented as a proof-of-concept prototype at selected Malaysian public sector for in-house web application development. © 2018 IEEE Institute of Electrical and Electronics Engineers Inc. 2019 Conference or Workshop Item NonPeerReviewed https://www.scopus.com/inward/record.uri?eid=2-s2.0-85062892016&doi=10.1109%2fIISA.2018.8631401&partnerID=40&md5=57c179c388d5f3c164ee925197e514ac Jakeri, M.M. and Hassan, M.F. (2019) A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector. In: UNSPECIFIED. http://eprints.utp.edu.my/23505/
institution Universiti Teknologi Petronas
building UTP Resource Centre
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Teknologi Petronas
content_source UTP Institutional Repository
url_provider http://eprints.utp.edu.my/
description Every year, web applications have expanded their presence in more areas in financial organizations, health organizations, public sector, retail and accommodation. Security is important in data protection so as not to be infringed by unauthorized parties. If the vulnerabilities found are not amended, it leads to cyber-attacks such as Structured Query Language Injection Attack (SQLIA) performed by certain parties which enable them to gain unauthorized data access. To cater security issues, variety of security frameworks for secure software development life cycle (SDLC) were introduced. Secure SDLC is created by integrating security-related activities to an each phase of in used development methodologies such as waterfall model or agile model. However, the application security problem continues to grow. Strict, complicated and heavyweight frameworks are underutilized due to several factors. The factors that influence the implementation of secure SDLC identified in public sector (the scope is State Secretary Offices in Malaysia) are inadequate development timeline, improper development team size and less awareness of team members' workload. It is agreed that integrating security at earlier (requirement and design) phase is the most effective and cheapest way to develop secure web application. Hence, an adaptive secure SDLC model is proposed to integrate security activities using Fuzzy Analytic Hierarchy Process (FAHP) focusing on the influence factors as the main criteria and meet the international and local secure frameworks standards. The proposed model will recommend adaptive security activities as a guideline to be applied at earlier phases of SDLC to help eliminate/ minimize the web application vulnerabilities and increase the application security and implemented as a proof-of-concept prototype at selected Malaysian public sector for in-house web application development. © 2018 IEEE
format Conference or Workshop Item
author Jakeri, M.M.
Hassan, M.F.
spellingShingle Jakeri, M.M.
Hassan, M.F.
A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector
author_facet Jakeri, M.M.
Hassan, M.F.
author_sort Jakeri, M.M.
title A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector
title_short A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector
title_full A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector
title_fullStr A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector
title_full_unstemmed A review of factors influencing the implementation of secure framework for in-house web application development in Malaysian public sector
title_sort review of factors influencing the implementation of secure framework for in-house web application development in malaysian public sector
publisher Institute of Electrical and Electronics Engineers Inc.
publishDate 2019
url https://www.scopus.com/inward/record.uri?eid=2-s2.0-85062892016&doi=10.1109%2fIISA.2018.8631401&partnerID=40&md5=57c179c388d5f3c164ee925197e514ac
http://eprints.utp.edu.my/23505/
_version_ 1738656481619738624
score 13.211869