Exploring SDLCs: Methodology or Madness?

profileRainebow
1-s2.0-S0167404814001345-main.pdf

ww.sciencedirect.com

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 4

Available online at w

ScienceDirect

journal homepage: www.elsevier .com/locate/cose

Implementing information security best practices on software lifecycle processes: The ISO/IEC 15504 Security Extension

Antoni Lluı́s Mesquida*, Antonia Mas 1

Department of Mathematics and Computer Science, University of the Balearic Islands, Ctra. de Valldemossa,

Km. 7.5, 07122 Palma de Mallorca, Spain

a r t i c l e i n f o

Article history:

Received 9 July 2013

Received in revised form

12 September 2014

Accepted 22 September 2014

Available online 2 October 2014

Keywords:

ISO/IEC 27002

Information security management

systems

ISO/IEC 15504 (SPICE)

Security extension

Software process improvement (SPI)

* Corresponding author. Tel.: þ34 971 172 99 E-mail addresses: [email protected]

1 Tel.: þ34 971 172 991; fax: þ34 971 173 0 http://dx.doi.org/10.1016/j.cose.2014.09.003 0167-4048/© 2014 Elsevier Ltd. All rights rese

a b s t r a c t

The ISO/IEC 15504 international standard can be aligned with the ISO/IEC 27000 informa-

tion security management framework. During the research conducted all the existing re-

lations between ISO/IEC 15504-5 software development base practices and ISO/IEC 27002

security controls have been analysed and the ISO/IEC 15504 Security Extension has been

developed. This extension details the changes that software companies should make in the

software lifecycle processes for the successful implementation of the related security

controls. To attain our research objectives, we evaluate the ISO/IEC 15504 Security Extension

through case studies in a sample of software development organizations. This study fol-

lows the design science research paradigm that is based on constructive research.

© 2014 Elsevier Ltd. All rights reserved.

1. Introduction

Nowadays information has become a very important asset for

companies and, as well as other crucial assets, it requires

special protection. In fact, information should be adequately

protected independently of its format and transmissionmode.

The main objective of information security is to properly

protect information from unauthorized access, use, disclo-

sure, disruption, modification and destruction (Bernard, 2007;

Gerber and von Solms, 2008; Mellado et al., 2010a).

The implementation of information security controls as

those defined in ISO/IEC 27002 is a priority for companies to

1; fax: þ34 971 173 003. s (A.L. Mesquida), antoni 03.

rved.

assure its continuity, minimise possible injuries and maxi-

mize the return of investment and business opportunities

(Karabacak and Sogukpinar, 2006; Lai andDai, 2009; von Solms

and von Solms, 2001).

In software development companies in particular, infor-

mation security is also fundamental (Mellado et al., 2010b,

2008; Zuccatoy, 2007). A significant number of software com-

panies, that have been or are currently involved in a process

improvement programme according to ISO/IEC 15504 (ISO/IEC,

2004b, 2004c), demand the implementation of ISO/IEC 27000 as

a security standard.

In order to guide software organizations involved in pro-

cess improvement programmes according to ISO/IEC 15504 in

[email protected] (A. Mas).

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 420

the implementation of the ISO/IEC 27000 standard, even

obtaining a certification against ISO/IEC 27001 (ISO/IEC 2013a),

it is necessary to adequately select and efficiently implement

the appropriate security controls between all the controls

provided by the ISO/IEC 27002 standard (ISO/IEC 2013b).

During the last years, several initiatives relating quality

and security best practices have emerged (Boynton, 2007; Da

Veiga and Eloff, 2010; Knapp et al., 2009; Lepmets et al., 2012;

Xiao-yan et al., 2011; Zvanut and Bajec, 2010). Barafort et al.

(2006) developed a process reference model and a process

implementation model which provide a framework for

assessing and increasing process capability and organisa-

tionalmaturity in the field information security. Valdevit et al.

(2009) proposed a guide for amore affordable, easier and faster

way to implement a vast majority of ISO/IEC 27001 in SMEs.

The authors of this paper are experienced in implementing

ISO/IEC 15504 in software companies (Amengual and Mas,

2007; Mas and Amengual, 2005; Mas et al., 2012, 2010) and in

using multiple standards in a combined way (Amengual and

Mas, 2003; Mesquida et al., 2009; Pardo et al., 2012). We have

also examined the relationship between this standard with

other ISO standards, such as ISO 9001 (Amengual and Mas,

2003; Mas and Amengual, 2004) and ISO/IEC 20000 (Mesquida

et al., 2012). Moreover, we have analysed the alignment of

ISO/IEC 15504 and other software process assessment and

improvement models such as CMMI-DEV (SEI, 2010), ITmark

(ITmark, 2013) and Competisoft (Oktaba et al., 2007) and taken

into account the lessons learned from the development of

other models based on ISO/IEC 15504 (Garz�as et al., 2013;

Tudor, 2009).

With the main intention of joining forces in the combined

implementation of ISO/IEC 15504 and ISO/IEC 27000, we

focused on the relationship between the base practices of ISO/

IEC 15504-5 (ISO/IEC, 2006) and the security controls of ISO/IEC

27002 with a double objective:

� To facilitate the implementation of ISO/IEC 27001 in orga-

nizations which have already reached a particular matu-

rity level according to ISO/IEC 15504.

� To define a method for the implementation of ISO/IEC

15504 that already considers the ISO/IEC 27001 security

aspects.

After a complete analysis of all the existing relations be-

tween ISO/IEC 15504-5 processes and ISO/IEC 27002 security

controls, it can be stated that ISO/IEC 15504-5 considers, or

could easily consider, an important number of the security

aspects which are necessary for the implementation of an

Information Security Management System. Consequently,

software companies which have been involved in a process

improvement programme according to ISO/IEC 15504 could

take advantage of their experience in the implementation of

the proposed base practices in order to implement the

selected ISO/IEC 27002 security controls.

Delving into this result, from the existing relations be-

tween the ISO/IEC 27002 security controls and the ISO/IEC

15504-5 base practices, and after analysing in depth the pur-

pose and requirements of each security control and the

related base practices, a security extension to ISO/IEC 15504 is

proposed. The ISO/IEC 15504 Security Extension describes the

adaptations and modifications that should be done in ISO/IEC

15504-5 processes in order to include the security aspects of

the ISO/IEC 27002 related controls.

At the time of constructing this security extension we

analysed the structure and contents of the ISO/IEC TS 15504-

10 standard (ISO/IEC, 2011), which provides specialized pro-

cesses and techniques for developing safety-related systems.

This safety extension describes three new processes: safety

management, safety engineering and safety qualification. The

goal of our new security extension was to detail all process

amplifications in the existing ISO/IEC 15504-5 software

development processes to cover ISO/IEC 27002 information

security controls.

Moreover, we examined the alignment of ISO/IEC 15504

and other software process assessment and improvement

models such as CMMI-DEV (SEI, 2010), ITmark (ITmark, 2013)

and Competisoft (Oktaba et al., 2007) and also took into ac-

count the lessons learned from the development of other

models based on ISO/IEC 15504 (Garz�as et al., 2013; Tudor,

2009).

This paper presents the ISO/IEC 15504 Security Extension and

how it can be used by an organization involved in a software

process improvement initiative to facilitate the implementa-

tion of ISO/IEC 27000 security aspects. The paper is structured

as follows: Section 2 describes the research method used to

meet the research objectives. Section 3 presents the interna-

tional standards used and the process followed to develop the

ISO/IEC 15504 Security Extension. Section 4 describes how the

security extension can be applied in software development

organizations and section 5 shows the lessons learned from

its validation in industry. Finally, Section 6 concludes this

paper and opens discussions regarding the results.

2. Research method and approach

This study follows the design science research paradigm that

is based on constructive research. The design science para-

digm is fundamentally about problem-solving and it seeks to

create artefacts to solve identified organizational problems

(Hevner et al., 2004). Design science attempts to create things

that serve human purposes and these things are then

assessed against criteria of value or utility. Rather than posing

theories as in natural science, design science strives to create

models, methods, and implementations that are innovative

and valuable (March and Smith, 1995).

As shown in Fig. 1, in design science a method or model is

first built for specific purposes, and then evaluated to deter-

mine howwell it works (March and Smith, 1995). In building an

artefact we first have to demonstrate that it is needed, i.e. we

have to illustrate the problem relevance as described by

Hevner et al. (2004), and that the artefact can be constructed to

address an important organizational problem (March and

Smith, 1995). Once the artefact has been built, we need to

know if it performs the specific task it was built for. In order to

know how well the artefact works, the artefact must be eval-

uated scientifically to see if any progress has been made

compared to existing solutions. Design science research ef-

forts may begin with simplified conceptualization and repre-

sentation of problems but with the changes in organizational

Fig. 1 e Design science research paradigm (adapted from Hevner et al. (2004)).

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 4 21

environments, assumptions made in prior research may

become invalid and need to be revisited and the artefact

refined. Evaluation is therefore an iterative cycle where

rigorous scientific evaluation methods are used (Hevner et al.,

2004) to review and refine the artefact.

The evaluation strategy considered naturalistic (e.g., field

setting) versus artificial evaluation (e.g., laboratory setting)

(Venable et al., 2012).

Following the principles of constructive research (J€arvinen,

2001), we first developed the ISO/IEC 15504 Security Extension

based on existing knowledge in different domains (Mesquida

et al., 2009, 2012; Mas et al., 2010), and then we evaluated

the extension in industry to determine its validity in a sample

of its end-users. Validity means that the framework works

and does what it is meant to do; that it is dependable in

operational terms in achieving its goals (Gregor and Hevner,

2013).

As shown on Fig. 1, the scientific knowledge base produced

by information security, process improvement, measurement

frameworks and systems thinking researchers is related in

this paper to the pragmatic and creative work of the IT

practitioners.

Although the different aspects of information security are

considered critical and vital for software development com-

panies, they tend not to be often measured, systemically

analysed and deployed on their production processes.We aim

to fill that gap in three iterative cycles through the develop-

ment, evaluation and refinement of the ISO/IEC 15504 Security

Extension.

In the first iteration, the existing principles of information

security management and process improvement measure-

ment practices were collected and synergised resulting in the

preliminary ISO/IEC 15504 Security Extension described in

greater detail in Section 3. We used the existing body of

knowledge of information security management to build the

extension: the information security management ISO/IEC

27000 family of standards (ISO/IEC, 2013a; ISO/IEC, 2013b) with

the measurement framework elements from the ISO/IEC

15504-2 (ISO/IEC, 2004c) standard.

In the second iteration, we further evaluated the extension

to understand its validity in industry through testing it in a

small sample of software development organizations. This

perspective offers the possibility of evaluating the extension

in reality, not just in theory. Naturalistic evaluation methods

offer the possibility to evaluate the artefact by practitioners.

Section 5 provides the results of the validation of the ISO/IEC

15504 Security Extension.

As a result of the second iteration, the extension will be

refined addressing the gaps, weaknesses and areas of

improvement detected by information security management

practitioners.

3. Development of the ISO/IEC 15504 Security Extension

This section outlines the systematic approach adopted during

the first iteration in order to map the ISO/IEC 27002 security

controls and the ISO/IEC 15504-5 base practices and develop

the ISO/IEC 15504 Security Extension. Moreover, an analysis

of all the detected relations between them is provided.

The complete mapping between the ISO/IEC 27002 controls

and the ISO/IEC 15504-5 base practices can be found in

Appendix 1.

3.1. Standards used

The structure of the international standards used to build the

security extension is firstly introduced.

3.1.1. ISO/IEC 27000 series The ISO/IEC 27000 series, also known as the Information Se-

curity Management System (ISMS) Family of Standards, pro-

vides best practice recommendations on information security

management, risks and controls within the context of an

overall ISMS. In order to conduct the research presented in

this paper only two standards of this series, ISO/IEC 27001 and

ISO/IEC 27002, have been used.

Table 2 e ISO/IEC 27002 Category structure.

Category name

Control Objective

Controls

(For each control

of the Category)

Control name Control description

Implementation guidance

Other information

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 422

ISO/IEC 27001 Information technology e Security tech-

niques e Information security management systems e Re-

quirements (ISO/IEC, 2013a) promotes the adoption of a

process approach and specifies the requirements for estab-

lishing, implementing, operating, monitoring, reviewing,

maintaining and improving a documented ISMS within the

context of an organization. This standard can be used in order

to assess conformance by interested internal and external

parties. The requirements set out in ISO/IEC 27001 are generic

and are intended to be applicable to all organizations,

regardless of type, size and nature. The standard is aligned

with ISO 9001 and ISO 14001 in order to support consistent and

integrated implementation and operation with related man-

agement standards. It is designed to enable an organization to

align or integrate its ISMS with related management system

requirements.

ISO/IEC 27002 Information technology e Security tech-

niques e Code of practice for information security controls

(ISO/IEC, 2013b) is the rename of the ISO/IEC 17799 standard.

It establishes guidelines and general principles for initi-

ating, implementing, maintaining, and improving informa-

tion security management in an organization. The control

objectives and controls of this international standard pro-

vide general guidance on the commonly accepted goals of

information security management. This standard may serve

as a practical guideline for developing organizational secu-

rity standards and effective security management practices

and to help to build confidence in inter-organizational ac-

tivities. ISO/IEC 27002 contains 14 security control clauses

collectively containing a total of 35 security categories and

114 controls. Table 1 summarizes the structure of the

standard.

Each category contains a control objective, stating what is

to be achieved, and one ormore controls that can be applied to

achieve the control objective. Control descriptions are struc-

tured into three different fields: control, implementation

guidance and other information. Table 2 shows this Category

structure.

Table 1 e ISO/IEC 27002 structure.

ISO/IEC 27002 clauses Categories Controls

5 Information security policies 1 2

6 Organization of information security 2 7

7 Human resource security 3 6

8 Asset management 3 10

9 Access control 4 14

10 Cryptography 1 2

11 Physical and environmental security 2 15

12 Operations security 7 14

13 Communications security 2 7

14 System acquisition, development and

maintenance

3 13

15 Supplier relationships 2 5

16 Information security incident

management

1 7

17 Information security aspects of

business continuity management

2 4

18 Compliance 2 8

Total 35 114

3.1.2. ISO/IEC 15504 ISO/IEC 15504 Information technology e Process assessment

(ISO/IEC, 2004b), also known as SPICE (Software Process

Improvement and Capability dEtermination), is an Interna-

tional Standard for process assessment and improvement. It

can be used by any organization to determine the current and

potential capability of its own processes, and also to define

areas and priorities for process improvement. ISO/IEC 15504 is

composed of ten parts that provide guidance to process

assessment. In order to perform a process assessment con-

formant with ISO/IEC 15504-2 (ISO/IEC, 2004c) a Process

Assessment Model (PAM), based upon a suitable Process

Reference Model (PRM), needs to be properly defined.

ISO/IEC 15504-5 (ISO/IEC, 2006) describes an exemplar PAM

for the particular case of the software lifecycle processes

defined in ISO/IEC 12207 Software life cycle processes (ISO/IEC,

2004a). In this part the standard defines process performance

indicators, also known as Base Practices (BP), for each one of

the 48 software lifecycle processes which are structured in 9

process groups. Table 3 shows these nine process groups, the

number of processes and the number of base practices per

group.

ISO/IEC 12207 describes each process in terms of a process

name, a process purpose and process outcomes. ISO/IEC

15504-5 extends this definition of a process by adding infor-

mation in the form of a set of base practices, which provide a

definition of the tasks and activities needed to accomplish the

process purpose and fulfil the process outcomes, and a num-

ber of input and output work products related to the process

outcomes. The complete structure of a process is shown in

Table 4.

3.2. Analysis of the relations between ISO/IEC 27002 and ISO/IEC 15504-5

The analysis of the relations between the two standards was

done by following an iterative and evolving strategy in which

each one of the ISO/IEC 27002 information security controls

Table 3 e ISO/IEC 15504-5 summary of process groups.

ISO/IEC 15504-5 process groups Processes Base practices

Acquisition (ACQ) 5 23

Supply (SPL) 3 25

Engineering (ENG) 12 66

Operation (OPE) 2 11

Management (MAN) 6 52

Process improvement (PIM) 3 23

Resource & infrastructure (RIN) 4 29

Reuse (REU) 3 26

Support (SUP) 10 73

Total 48 328

Table 4 e ISO/IEC 15504-5 process structure.

Process ID

Process Name

Process Purpose

Process Outcomes

Base Practices

Work Products

Inputs Outputs

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 4 23

was compared with the base practices of the ISO/IEC 15504-5

processes. Fig. 2 shows the procedure used to detect the re-

lations between these two standards. This successive refine-

ment process flow consists of three activities, which are

described below.

1. With the aim of sharing knowledge and contrasting the

different points of view of the authors, the relations be-

tween the standards were analysed as a group. It took

several working sessions (joint meetings) to obtain a pre-

liminary version of the whole mapping. During each

meeting two or three of the 14 ISO/IEC 27002 clauses were

analysed. As sown in Fig. 3, for each of the 114 security

controls in the 35 categories, the fields Description, Imple-

mentation guidance and Other information were analysed in

depth. It should be noted that the authors' knowledge of

the ISO/IEC 15504 standard facilitated the initial selection

of the set of processes related to the control under

consideration. After a detailed analysis of the base prac-

tices of the ISO/IEC 15504-5 selected processes, it was

possible to determine the existence or not of a connection

between the ISO/IEC 27002 control and a particular ISO/IEC

15504-5 process.

2. In the second activity, and with the aim of consolidating

the results of the joint meetings, the first version of the

mapping was again examined individually to confirm the

decisions reached or, conversely, make modifications on

the preliminary version.

3. Finally, during the joint review activity, the proposals from

each of the authors were discussed thoroughly, until a

general consensus to accept or reject each proposal was

reached.

3.2.1. Types of correspondence between ISO/IEC 27002 and ISO/IEC 15504-5 From the analysis of the relations between ISO/IEC 27002

controls and ISO/IEC 15504-5 base practices, five different

Fig. 2 e The mappin

types of correspondence between both standards were

established:

1. Correspondence between a control and thewhole set of the

base practices of a process. The connection between the

12.1.2 Change Management control and the base practices of

the SUP.10 Change request management process can be

considered an example of this case. Although this set of

base practices is performed in order to ensure that changes

to products in development are managed and controlled,

the same set of base practices could be performed in order

to manage changes to information processing facilities in

the manner indicated by the control.

Another example of this case can be observed in the

connection between the 12.1.1 Documented operating procedures

control and the SUP.7 Documentation process.

2. Correspondence between the control and part of the set of

the base practices of a process. This is the case of the 12.3.1

Information backup control which is clearly related to

SUP.8.BP10 Manage the backup, storage, archiving,

handling and delivery of configured items and RIN.4.BP2

Define the infrastructure requirements. The description of

this control states that backup copies of information,

software and system images shall be taken and tested

regularly in accordance with the agreed backup policy.

This description fits with SUP.8.BP10 description: Ensure

the integrity and consistency of configured items through

appropriate scheduling and resourcing of backup, storage and

archiving. Control the handling and delivery of configured

items.

Likewise, the control description also fits with RIN.4.BP2

description: Define the infrastructure requirements to support

the performance of appropriate processes. Infrastructure

process requirements may include: security, throughput and

data sharing requirements, backup and recovery, remote ac-

cess facility, physical workspace and equipment, user support

requirements and maintenance requirements.

3. Correspondence between a control and a process. In this

case there is a correspondence between a control and a

process without an explicit connection with a particular

base practice of the process. The relation has been identi-

fied by comparing the control description with the process

purpose.

g process flow.

Fig. 3 e Procedure used to detect the relations between ISO/IEC 27002 and ISO/IEC 15504-5.

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 424

This is the case of the 6.1.5 Information security in project

management control with the MAN.3 Project Management pro-

cess. The description of this control states that information

security shall be addressed in projectmanagement, regardless

of the type of the project. The purpose of MAN.3 is to identify,

establish, co-ordinate, and monitor the activities, tasks, and

resources necessary for a project to produce a product and/or

service, in the context of the project's requirements and con-

straints. In this case, in order to include the security aspects

considered by the control in the related process two possible

solutions could be undertaken. On the one hand, a new base

practice could be added to the process in order to satisfy the

control objective. The description of this new base practice

could be adapted from the control implementation guidance.

On the other hand, the description of the existent base prac-

tices and the process purpose could be modified or expanded.

For the particular of case of MAN.3, MAN.3.BP1 Define the

scope of work, MAN.3.BP4 Determine and maintain estimates

for project attributes, MAN.3.BP5 Determine project activities

and tasks, MAN.3.BP9 Allocate responsibilities, MAN.3.BP10

Establish project plan and MAN.3.BP11 Implement the project

plan should be expanded in order to meet the control objec-

tive. Moreover, the process purpose could also be changed to

“to identify, establish, co-ordinate, and monitor the activities,

tasks, resources and information security implications

necessary for a project to produce a product and/or service, in

the context of the project's requirements and constraints”.

4. Nonexistence of a correspondence between a control and a

process. This is the case of controls 12.4.3 Administrator and

operator logs and 12.4.4 Clock synchronization. Because of its

particular nature, these controls are related to system

administration activities which are not covered by ISO/IEC

15504-5.

5. Correspondence between a control and the RIN.4 Infra-

structure process. In this case, a control is only related to

the RIN.4 Infrastructure process which purpose is to main-

tain a stable and reliable infrastructure that is needed to

support the performance of any other process. The RIN.4

base practices most frequently connected are RIN.4.BP2

Define the infrastructure requirements and RIN.4.BP4

Establish the infrastructure.

An example of this case can be observed in the first control

of the category 12.4 Logging and monitoring, 12.4.1 Event log-

ging, which objective is to produce, keep and regularly review

event logs recording user activities, exceptions, faults and

information security events. If this objective is understood as

a security infrastructure requirement, the control should be

related to RIN.4.BP2 and RIN.4.BP4.

3.2.2. Summary of the relations between ISO/IEC 27002 and ISO/IEC 15504-5 Table 5 shows a high level view of the relations between the

ISO/IEC 27002 clauses and the ISO/IEC 15504-5 process groups.

Appendix 1 shows at a more detailed level the complete

mapping between the ISO/IEC 27002 controls and the ISO/IEC

15504-5 base practices.

Table 5 can be analysed from two different points of view.

On the one hand, an analysis by columns gives information

about the relations from the perspective of ISO/IEC 15504 pro-

cessgroups.On theotherhand,ananalysisby rowsdetermines

the relations from the perspective of ISO/IEC 27002 controls.

Beginning with an analysis of Table 5 by columns, it can be

seen that the Resource and Infrastructure process group (RIN) is

the only process group that is related to almost all ISO/IEC

27002 clauses, except clause 10 Cryptography. This process

group consists of processes performed in order to provide

adequate human resources and the necessary infrastructure

as required by any other process. Not surprisingly, the re-

lations established between this process group and the ISO/

IEC 27002 clauses are quite evident.

Table 5 e Summary of the relations between the ISO/IEC 27002 Clauses and the ISO/IEC 15504-5 process groups.

ISO/IEC 27002 clauses ISO/IEC 15504-5 process groups

ACQ SPL ENG OPE MAN PIM RIN REU SUP

5 Information security policies ✓ ✓

6 Organization of information security ✓ ✓

7 Human resource security ✓ ✓

8 Asset management ✓ ✓

9 Access control ✓ ✓ ✓

10 Cryptography

11 Physical and environmental security ✓

12 Operations security ✓ ✓ ✓ ✓

13 Communications security ✓ ✓ ✓

14 System acquisition, development and maintenance ✓ ✓ ✓ ✓ ✓ ✓

15 Supplier relationships ✓ ✓ ✓

16 Information security incident management ✓ ✓ ✓

17 Information security aspects of business continuity management ✓ ✓ ✓

18 Compliance ✓ ✓ ✓ ✓ ✓ ✓

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 4 25

On the contrary, the Operation process group (OPE) and the

Reuse process group (REU) have a weak or non-existent

connection with any clause in ISO/IEC 27002. The OPE pro-

cess group contains base practices for the correct operation

and use of the software product and/or service. Consequently,

it is hardly surprising that no relation with the ISO/IEC 27002

standard has been found.

The purpose of the REU processes is to manage the life of

reusable assets and to plan, establish, manage, control, and

monitor an organization's reuse program to systematically

exploit reuse opportunities. These activities are better related

to the ISO/IEC 27001 standard than to ISO/IEC 27002. That is

the reason why no evidences of REU base practices in ISO/IEC

27002 controls have been identified.

Finally, analysing Table 5 from the perspective of the ISO/

IEC 27002 clauses, it can be observed that the clause 11 Physical

and environmental security has only weak connections with the

RIN process group. Moreover, clauses 5 Information security

policies, 6 Organization of information security and 7 Human

resource security are only related to the MAN and RIN process

groups and clause 8 Asset management is only related to the

RIN and SUP process groups. Conversely, clauses 14 System

acquisition, development and maintenance and 18 Compliance are

related to six different process groups.

Controls in clause 14 System acquisition, development and

maintenance are aimed at ensuring that information security is

an integral part of information systems across the entire

lifecycle and is designed and implemented within the devel-

opment lifecycle of information systems. Being such a

Table 6 e Kinds of actions proposed by the ISO/IEC 15504 Secu

Kind of action

1 To use the ISO/IEC 15504-5 process purpose or its base pract

manage the security requirements of the related control

2 To modify or extend ISO/IEC 15504-5 base practices

3 To add a new base practice from the related control objectiv

linked to the existent base practices

4 To modify or extend the purpose of an ISO/IEC 15504 process

transversal clause, its controls are applicable to base practices

of procurement, engineering, management and support pro-

cesses during the whole software development lifecycle.

The clause 18 Compliance contains controls for avoiding

breaches of legal, statutory, regulatory or contractual obliga-

tions related to information security and ensuring that infor-

mation security is implemented and operated in accordance

with the organizational policies and procedures. Conse-

quently, these controls are also applicable during the entire

software development lifecycle.

4. The ISO/IEC 15504 Security Extension

The ISO/IEC 15504 Security Extension details the changes

needed to be made in the ISO/IEC 15504-5 processes in order

make them compliant with the security requirements of the

related ISO/IEC 27002 controls. This extension has been

developed from the relations detected between the base

practices proposed by ISO/IEC 15504-5 and the security con-

trols of the ISO/IEC 27002 standard.

The modifications and amplifications proposed by the ISO/

IEC 15504 Security Extension can affect to different process

components: process purpose, process outcomes, base prac-

tices or work products. Table 6 shows the four different kinds

of actions to be performed on an ISO/IEC 15504-5 process in

order that it covers a specific ISO/IEC 27002 security control.

In order to clarify the meaning and the results of each kind

of action proposed by the ISO/IEC 15504 Security Extension

rity Extension.

ISO/IEC 15504 process component affected

ices to Process purpose (No modification)

Base practice (Expansion)

Process outcomes (Revision)

e, closely Base practice (Creation)

Process purpose (Expansion)

Process outcomes (Revision)

Table 7 e ISO/IEC 27002 controls related to the ACQ.3 Contract agreement process.

ISO/IEC 27002 controls related to the ACQ.3 process

13.1.2 Security of network services

13.2.2 Agreements on information transfer

14.2.7 Outsourced development

15.1.1 Information security policy for supplier relationships

15.1.2 Addressing security within supplier agreements

15.1.3 Information and communication technology supply chain

18.1.2 Intellectual property rights

18.1.4 Privacy and protection of personally identifiable information

18.1.5 Regulation of cryptographic controls

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 426

different examples for some security controls are provided

below.

Kind of action 1: To use the ISO/IEC 15504-5 process pur-

pose or its base practices tomanage the security requirements

of the related control. In this first case, ISO/IEC 15504-5 base

practices can be directly used to satisfy the security aspects of

the related control. No process modification or amplification

needs to be done to completely cover the security control.

One example of this case can be observed in the connection

between the 12.1.2 ChangeManagement control (Changes to the

organization, business processes, information processing fa-

cilities and systems that affect information security shall be

controlled) and the SUP.10 Change request management process

whose purpose is to ensure that changes to products in

development are managed and controlled. The SUP.10 base

practices BP1 to BP9 can be performed in order to manage

changes to information processing facilities and systems that

affect information security in the manner indicated by the

related control.

Another example of this case is the relation between the

12.1.1 Documented operating procedures control (Operating pro-

cedures shall be documented and made available to all users

who need them) and the SUP.7 Documentation process whose

purpose is to develop and maintain the recorded information

produced by a process. The SUP.7 base practices BP1 to BP8 can

be performed in order to develop and make available the

operating procedures.

Kind of action 2: To modify or extend ISO/IEC 15504-5 base

practices. In this case, the related ISO/IEC 15504-5 base prac-

tices could be widened to cover all the security aspects of the

control.

One example of this case can be observed in the relation

between the 16.1.2 Reporting information security events control

(Information security events shall be reported through

appropriatemanagement channels as quickly as possible) and

the RIN.3.BP4 Capture knowledge (Identify and record each

knowledge item according to the classification schema and

asset criteria). In order to cover all the security aspects of the

control, the description of RIN.3.BP4 could be widened with

the underlined sentence: Identify and record each knowledge

item according to the classification schema and asset criteria,

including information security events through appropriate

management channels as quickly as possible.

Another example of this case is in the connection between

the 7.2.2 Information security awareness, education, and training

control (All employees of the organization and, where rele-

vant, contractors shall receive appropriate awareness educa-

tion and training and regular updates in organizational

policies and procedures, as relevant for their job function. On-

going training should include security requirements, legal

responsibilities and business controls, as well as training in

the correct use of information processing facilities) and the

RIN.2.BP2 Identify needs for training (Identify and evaluate skills

and competencies to be provided or improved through

training). As the previous example, the description of this base

practice could be widened to state: Identify and evaluate skills

and competencies to be provided or improved through

training, including security requirements, legal re-

sponsibilities and business controls, as well as training in the

correct use of information processing facilities.

Kind of action 3: To add a new base practice from the

related control objective, closely linked to the existent base

practices. In this case, the related ISO/IEC 15504-5 process

does not have any specific base practice that covers the se-

curity control and, therefore, it is necessary to create a new

one.

One example is the case of the 14.3.1 Protection of test data

control (Test data shall be selected carefully, protected and

controlled. If personally identifiable information or otherwise

confidential information is used for testing purposes, all

sensitive details and content should be protected by removal

or modification). This control is related to the ENG.8 Software

testing processwhose purpose is to confirm that the integrated

software product meets its defined requirements. In this case,

a new base practice has been created: ENG.8.BP0 Protect test

data (Remove or modify beyond recognition before use, pro-

tect and control all personal or sensitive information used for

testing purposes).

A second example can be observed in the 7.1.2 Terms and

conditions of employment control (The contractual agreements

with employees and contractors shall state their and the or-

ganization's responsibilities for information security), which

is related to the RIN.1 Human resource management process

purpose (Provide the organization and projects with in-

dividuals who possess skills and knowledge to perform their

roles effectively and to work together as a cohesive group). In

order to cover the security aspects of the control, the

description of the new base practice, called RIN.1.BP4 Assign

responsibilities for information security, should be: Assign infor-

mation security responsibilities according to the skills and

competencies of recruited staff.

Kind of action 4: Tomodify or extend the purpose of an ISO/

IEC 15504 process. In this case, there is a correspondence be-

tween a control and a process without an explicit connection

with a particular base practice of the process. The relation has

been identified by comparing the control description with the

process purpose. Consequently, the action to be performed

should consist on modifying or expanding the process pur-

pose in order to cover the security requirements of the control.

One example of this case can be observed in the ACQ.3

Contract agreement process whose purpose is to negotiate and

approve a contract/agreement that clearly and unambigu-

ously specifies the expectations, responsibilities, work prod-

ucts/deliverables and liabilities of both the supplier(s) and the

acquirer. This process is related to nine different ISO/IEC

27002 security controls, which are shown in Table 7.

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 4 27

In order to satisfy these controls, contracts or agreements

negotiated and approved according to ACQ.3 should be

widened, including specific clauses:

� including all the security features, service levels, and

management requirements of all network services (to

satisfy control 13.1.2)

� treating the exchange of information and software be-

tween the organization and external parties (to satisfy

control 13.2.2)

� including relevant aspects related to licensing arrange-

ments, code ownership, intellectual property rights, rights

of access for audit of the quality and accuracy of work done

and contractual requirements for quality and security

functionality of code, when software development is out-

sourced (to satisfy control 14.2.7)

� involving accessing, processing, communicating or man-

aging the organization's information or information pro-

cess facilities (to satisfy controls 15.1.1, 15.1.2 and 15.1.3)

� ensuring the compliance with legislative, regulatory, and

contractual requirements on the use of material in respect

of which there may be intellectual property rights and on

the use of proprietary software products (to satisfy control

18.1.2)

� ensuring data protection and privacy as required in legis-

lation and regulation agreed (to satisfy control 18.1.4)

� referring to the cryptographic controls that should be used

in compliance with all relevant agreements, laws, and

regulations agreed (to satisfy control 18.1.5)

In this way, if an organization which has implemented the

ACQ.3 base practices adds to the standard contract the former

clauses, it would have also implemented the nine ISO/IEC

27002 security controls related to this process.

4.1. Application of the ISO/IEC 15504 Security Extension

The ISO/IEC 15504 Security Extensionhas a double application. It

could be used, on the one hand:

� To facilitate the implementation of the ISO/IEC 27001

standard in software organizations which are or have been

involved in SPI programmes according to ISO/IEC 15504 or,

on the other hand,

� To facilitate the simultaneous implementation of both ISO/

IEC 27001 and ISO/IEC 15504 standards, avoiding the

Table 8 e Actions proposed by the ISO/IEC 15504 Security Exten

ISO/IEC 15504-5 process Kind of action

SUP.9 Problem resolution management

process

4. To modify or extend the pu

of an ISO/IEC 15504 process.

MAN.5 Risk Management process 4. To modify or extend the pu

of an ISO/IEC 15504 process.

RIN.3 Knowledge Management process 2. To modify or extend ISO/IE

15504-5 base practices

repetition of similar tasks included in both standards, and

therefore, reducing the amount of effort required by the

organization.

In both cases, the organization must firstly select the ISO/

IEC 27002 applicable controls, depending on the kind of or-

ganization and its main activities. For each of these selected

security controls, the ISO/IEC 15504 Security Extension proposes

a set of actions on the ISO/IEC 15504-5 processes to meet the

security requirements of the control.

In order to illustrate the use of this security extension, we

consider, as an example, the implementation of the control

16.1.6 Learning from information security incidents, which

description is: Knowledge gained from analysing and

resolving information security incidents shall be used to

reduce the likelihood or impact of future incidents. There

should be mechanisms in place to enable the types, volumes,

and costs of information security incidents to be quantified

and monitored. The evaluation of information security in-

cidents may indicate the need for enhanced or additional

controls to limit the frequency, damage, and cost of future

occurrences or to be taken into account in the security policy

review process.

In order to satisfy the security requirements related to this

control, the ISO/IEC 15504 Security Extension proposes to

perform different actions in three ISO/IEC 15504-5 processes:

SUP.9 Problem resolution management process, MAN.5 Risk

management process and RIN.3 Knowledge management process.

Table 8 lists the actions to perform on these processes.

Regarding the two first processes, SUP.9 and MAN.5, their

purposes should bemodified or expanded as shown in Section

4 (kind of action 4). Regarding the RIN.3 process, RIN.3.BP4

should be extended, as shown in Section 4 (kind of action 2).

5. Validation of the ISO/IEC 15504 Security Extension

During the second iteration, case studies were conducted in a

small sample of software development organizations in order

to:

1. Evaluate the validity of the ISO/IEC 15504 Security Exten-

sion and

2. Determine what security controls they apply or could be

easily deployed on their development processes.

sion to satisfy control 16.1.6.

Description (guidelines)

rpose SUP.9 Problem resolution management process must

ensure that information security incidents are identified,

analysed, managed and controlled to resolution in the

manner indicated by the security policy

rpose MAN.5 Risk Management process must ensure that

information security incidents are continuously identified,

analysed, quantified, treated and monitored.

C RIN.3.BP4 Capture knowledge should also be extended to

include the capture of information gained from the

evaluation of information security incidents.

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 428

To select organizations to participate in the evaluation we

used a convenience sample drawing on the authors' industry contacts of IT managers known to have conducted process

assessments according to ISO/IEC 15504. Next subsection

presents the results of the application of the ISO/IEC 15504

Security Extension in one of the companies that participated in

its validation.

5.1. Case study: validation of the ISO/IEC 15504 Security Extension in a company

This company began its activity in 2000 with a staff of six.

Today, it has 120 employees dedicated to the development of

internet-based marketing and management applications and

the implementation of the infrastructure which supports

them. It provides tailored, unique and global solutions that

include consultancy, training and the technology necessary

for the evolution of customers' businesses and needs. The

implementation of a quality management system and the ISO

9000 certification obtained by the company initiated what has

become one of themain insignias of the company: quality as a

management strategy. In 2005, the company introduced the

EFQM Excellence Model into its quality management system.

The company initiated a software process improvement

programme according to the ISO/IEC 15504 international

standard by the end of 2007. In 2009 the company incorpo-

rated information security management in its existing man-

agement model and obtained the ISO/IEC 27001 certification.

To date, the company has continued working on the

improvement of its processes and on their deployment in all

its projects. Table 9 shows the capability level of the fourteen

ISO/IEC 15504-5 processes implemented in the organization.

Because the company had already got the ISO/IEC 27001

certification, it applied the ISO/IEC 15504 Security Extension in

order to validate its usefulness, completeness, and suitability.

The company used the security extension to identify and

validate the ISO/IEC 27002 security controls which had been

deployed on each of the ISO/IEC 15504-5 processes imple-

mented in the organization. In addition, the company could

observe that there existed other security controls not covered

so far that could be easily deployed on these processes.

Table 9 e Capability level of the ISO/IEC 15504-5 implemented processes.

ISO/IEC 15504-5 process Capability level

ACQ.3 Contract agreement 1

ACQ.4 Supplier monitoring 1

ACQ.5 Customer acceptance 1

SPL.2 Product release 2

ENG.1 Requirements elicitation 1

ENG.4 Software requirements analysis 1

ENG.8 Software testing 1

ENG.11 Software installation 1

ENG.12 Software and system maintenance 1

MAN.3 Project management 1

MAN.5 Risk management 2

SUP.1 Quality assurance 2

SUP.7 Documentation 2

SUP.9 Problem resolution management 1

Table 10 shows, once applied the ISO/IEC 15504 Security

Extension, the ISO/IEC 27002 security controls deployed on

the ISO/IEC 15504-5 processes implemented in the company.

32 different security controls have been deployed on thirteen

of the fourteen ISO/IEC 15504-5 implemented processes.

ENG.12 Software and system maintenance process could not be

used to facilitate the implementation of any control, not

being this process directly related to information security

management.

5.2. Lessons learned from the validation of the ISO/IEC 15504 Security Extension

In this section, the remarks we have made during the vali-

dation of the ISO/IEC 15504 Security Extension in the participant

companies are described. Regarding general aspects, we can

state that:

� These companies are fully devoted to their productive

work and to solve their day-to-day survival problems. They

are often unable and unwilling to devote time and efforts to

define new processes or to improve the existing ones.

Software engineers are more oriented to product, service

or management instead of establishing new working

practices.

� Participant companies need external consultancy that of-

fers support in information security process deployment

and improvement, issues that they generally unknown and

consider very complex, utopian and distant.

� Software companies not only need to know what to do in

order to improve their processes, but they need to have

specific procedures describing in detail the work they have

to perform, with a clear set of best practices that will help

to carry them out. These procedures should be simple and

applicable to the types of projects that they normally

undertake.

� They spend very little effort to improve employee training

on information security and, when done, it is not according

to an established training plan, but as an ad-hoc action

derived from a detected short-term need.

� It is not traditionally accustomed to perform information

security riskmanagement activities. Incidents are assumed

and companies react as they can.

Based on the evaluation of the ISO/IEC 15504 Security

Extension we have observed that the organizations which

already have implemented the ISO/IEC 15504 standard can

reuse previous experiences, knowledge, processes and prac-

tices when implementing the applicable ISO/IEC 27002 secu-

rity controls. The following are themost significant examples:

� The ENG.1 Requirements elicitation process can be also used

to gather, process, and track evolving customer needs and

requirements related to information security throughout

the life of the product and/or service.

� The processes MAN.1 Organizational alignment and MAN.2

Organization management can be also applied to establish

and perform information security management policies

needed for providing software products and services that

are consistent with the business goals of the organization.

Table 10 e ISO/IEC 27002 security controls deployed on the ISO/IEC 15504-5 processes.

ISO/IEC 15504-5 process ISO/IEC 27002 security controls deployed on the ISO/IEC 15504-5 process

ACQ.3 Contract agreement 13.1.2 Security of network services

13.2.1 Information transfer policies and procedures

14.2.7 Outsourced development

15.1.1 Information security policy for supplier relationships

15.1.2 Addressing security within supplier agreements

15.1.3 Information and communication technology supply chain

18.1.2 Intellectual property rights

18.1.4 Privacy and protection of personally identifiable information

18.1.5 Regulation of cryptographic controls

ACQ.4 Supplier monitoring 14.2.7 Outsourced development

15.2.1 Monitoring and review of supplier services

15.2.5 Managing changes to supplier services

ACQ.5 Customer acceptance 14.2.7 Outsourced development

14.2.9 System acceptance testing

SPL.2 Product release 8.3.3 Physical media transfer

ENG.1 Requirements elicitation 14.1.1 Information security requirements analysis and specification

14.1.2 Securing application services on public networks

14.1.3 Protecting application services transactions

18.1.1 Identification of applicable legislation and contractual requirements

18.1.2 Intellectual property rights

18.1.4 Privacy and protection of personally identifiable information

18.1.5 Regulation of cryptographic controls

ENG.4 Software requirements analysis 14.1.1 Information security requirements analysis and specification

14.3.1 Protection of test data

18.1.1 Identification of applicable legislation and contractual requirements

ENG.8 Software testing 12.1.4 Separation of development, testing and operational environments

14.3.1 Protection of test data

ENG.11 Software installation 12.5.1 Installation of software on operational systems

MAN.3 Project management 6.1.5 Information security in project management

MAN.5 Risk management 12.6.1 Management of technical vulnerabilities

16.1.1 Responsibilities and procedures

16.1.2 Reporting information security events

16.1.3 Reporting information security weaknesses

16.1.4 Assessment of and decision on information security events

16.1.5 Response to information security incidents

16.1.6 Learning from information security incidents

SUP.1 Quality assurance 18.2.2 Compliance with security policies and standards

SUP.7 Documentation 12.1.1 Documented operating procedures

18.1.3 Protection of records

SUP.9 Problem resolution management 16.1.1 Responsibilities and procedures

16.1.2 Reporting information security events

16.1.3 Reporting information security weaknesses

16.1.4 Assessment of and decision on information security events

16.1.5 Response to information security incidents

16.1.6 Learning from information security incidents

16.1.7 Collection of evidence

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 4 29

� MAN.3 Project management base practices can be used to

identify, establish, co-ordinate and monitor the activities,

tasks, and resources necessary for information security, in

the context of the project's requirements and constraints.

� Similarly, MAN.5 Risk management process can be applied to

identify, analyse, treat and continuously monitor the risks

related to information security issues.

� Having deployed the PIM.1 Process establishment process

means that the organization has already in place a suite of

organizational processes for all life cycle processes as they

apply to its business activities. Information security best

practices can be easily deployed on these processes.

� Thanks to the PIM.3 Process improvement process the exist-

ing information security policies can be continually

improved andmaintained alignedwith the business needs.

� Information security skills and knowledge for staff to

perform their roles effectively can be defined by taking

advantage of the RIN.1 Human resource management process

assets and tools.

� The information security infrastructure requirements

(backup and recovery, remote access facility, physical

workspace and equipment) can be defined using the base

practices and outcomes of the RIN.4 Infrastructure process.

� SUP.7 Documentation process can be used to develop and

maintain the recorded information produced by the in-

formation security activities.

� The SUP.9 Problem resolution management process can be

applied to ensure that all discovered information security

problems are identified, analysed, managed and controlled

to resolution.

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 430

� SUP.10 Change request management process can be used to

ensure that change requests related to information secu-

rity issues are also managed, tracked and controlled.

As key strengths for the ISO/IEC 15504 Security Extension

validation success it is worth highlighting:

� The active participation, commitment and motivation of

top management in all the participant companies. Top

management has always provided and trained the neces-

sary human resources to achieve the stated objectives and

support the business strategy. Moreover, an important

financial investment to facilitate the implementation and

standardization of new procedures and incorporating new

support tools has been required. These changes have

taken place in all departments and at all levels of the

company.

� The willingness to share knowledge among companies. It

is important to note that these companies are in the same

sector and they sometimes compete to obtain a new proj-

ect/client.

6. Conclusion and further work

This paper presented the ISO/IEC 15504 Security Extension

that may be relevant for a software development company

involved in a process improvement programme according

to the ISO/IEC 15504 international standard. The major

contribution of the work is the development and valida-

tion of this software extension, built from a thorough

mapping between the ISO/IEC 27002 security controls and

the ISO/IEC 15504-5 base practices for software lifecycle

processes.

The ISO/IEC 15504 Security Extension details the changes

that should be made in the software lifecycle processes for

the successful implementation of the related security con-

trols. The quality managers can use the ISO/IEC 15504 Secu-

rity Extension to observe all the actions to be performed on

the ISO/IEC 15504-5 processes in order to meet the security

requirements of the selected ISO/IEC 27002 applicable

control.

The validity of the ISO/IEC 15504 Security Extension has been

evaluated in industry. Naturalistic evaluation methods offer

the possibility of evaluating the extension by practitioners in

reality, not just in theory. The valuation of its application in

different software companies in our country is totally positive.

From the feedback we have received from quality de-

partments, it can be stated that ISO/IEC 15504 processes can

easily be adapted to consider an important number of the

security controls needed to establish an Information Security

Management System. Consequently, the ISO/IEC 15504 Security

Extension can be used to facilitate the implementation of ISO/

IEC 27001 in software companies which are currently, or will

be in the near future, involved in a software process

improvement programme according to ISO/IEC 15504. An in-

tegrated implementation of these two international standards

will impact, in themedium term, in the day to day operation of

the business, resulting in a reduction of workload and du-

plicities and in an optimization of the tasks related to the

implementation and maintenance of the recommended best

practices.

This study has its limitations. Firstly, it has to be noted

that, although some ISO/IEC 15504-5 processes can be easily

adapted to cover 93 different ISO/IEC 27002 security controls,

there is still 21 security controls that do not have any relation

to ISO/IEC 15504-5 processes, and therefore, they must be

implemented as indicated in the ISO/IEC 27002 standard.

Secondly, although the case studies were diverse, they were

similar in terms of their market domain. Selecting cases from

various industries may have provided stronger support for the

definition of specific recommendations included in the secu-

rity extension.

Further work is expected to be performed in order to

improve the developed ISO/IEC 15504 Security Extension by

considering the lessons learned from its application in more

software development companies. To date, the extension has

been refined based on the evaluation suggesting additional

clarifications on the terms used by the standards that in-

tegrates. Moreover, the process reference model will be

updated to align to the last version of ISO/IEC 15504-5. As a

result of this new iteration, we will propose a refined ISO/IEC

15504 Security Extension.

The authors plan to continue the research to understand

the benefits and feasibility of widen the scope of the provided

ISO/IEC 15504 Security Extension in order to align it with COBIT 5

(ISACA, 2012). Themain goal of this next iteration is to analyse

the relations among the software lifecycle processes of the

ISO/IEC 15504-5 standard, the information security manage-

ment requirements of the ISO/IEC 27001 standard and the best

practices for the governance andmanagement of enterprise IT

defined by COBIT. As the last two frameworks follow a process

approach and are also based on the Plan-Do-Check-Act (PDCA)

cycle, we intuitively think that the creation of synergies be-

tween the management systems they define and the inte-

gration of their organizational policies and operational

controls is very viable.

Finally, we have initiated the development of a software

tool to support the application of the ISO/IEC 15504 Security

Extension in software development companies.

Acknowledgements

This research has been supported by CICYT-TIN2010-20057-

C03-03 “Simulaci�on aplicada a la gesti�on de equipos, proc-

esos y servicios”, Sim4Gest.

Appendix 1. Mapping between the ISO/IEC 27002 security controls and ISO/IEC 15504-5 base practices

From the analysis of the rows in Table 5, this appendix shows

all the relations detected between the controls in each of the

fourteen clauses of ISO/IEC 27002 and the base practices of

ISO/IEC 15504-5. In case a control is related to all the base

practices of a process, the table only shows the process name.

5 Information security policies

5.1 Management direction for information security

5.1.1 Policies for information security MAN.1.BP1, BP3,

BP4-BP5

RIN.4.BP2

5.1.2 Review of the policies for information

security

MAN.1 Level 2

6 Organization of information security

6.1 Internal organization

6.1.1 Information security roles and

responsibilities

MAN.1

MAN.2 Level 2 (GP 2.1.4)

RIN.1

6.1.2 Segregation of duties RIN.4.BP2

6.1.3 Contact with authorities RIN.4.BP1-BP2

6.1.4 Contact with special interest groups RIN.4.BP1-BP2

6.1.5 Information security in project

management

MAN.3

6.2 Mobile devices and teleworking

6.2.1 Mobile device policy RIN.4.BP1-BP2,BP4

6.2.2 Teleworking RIN.4.BP1-BP2,BP4

7 Human resource security

7.1 Prior to employment

7.1.1 Screening RIN.1

7.1.2 Terms and conditions of employment RIN.1

7.2 During employment

7.2.1 Management responsibilities MAN.1

RIN.1.BP2

7.2.2 Information security awareness,

education and training

RIN.1.BP4

RIN.2.BP1-BP7

7.2.3 Disciplinary process e

7.3 Termination or change of employment

7.3.1 Termination or change of employment

responsibilities

e

8 Asset management

8.1 Responsibility for assets

8.1.1 Inventory of assets e

8.1.2 Ownership of assets RIN.4.BP2

8.1.3 Acceptable use of assets RIN.2.BP2,BP5

RIN.4.BP1

8.1.4 Return of assets RIN.4.BP2

8.2 Information classification

8.2.1 Classification of information e

8.2.2 Labelling of information e

8.2.3 Handling of assets RIN.4.BP2

SUP.8.BP10

8.3 Media handling

8.3.1 Management of removable media RIN.4.BP1-BP2

8.3.2 Disposal of media e

8.3.3 Physical media transfer SPL.2.BP8

11 Physical and environmental security

11.1 Secure areas

11.1.1 Physical security perimeter e

11.1.2 Physical entry controls e

11.1.3 Securing offices, rooms and facilities e

11.1.4 Protecting against external and

environmental threats

e

11.1.5 Working in secure areas e

11.1.6 Delivery and loading areas e

11.2 Equipment

11.2.1 Equipment siting and protection RIN.4

11.2.2 Supporting utilities RIN.4

11.2.3 Cabling security RIN.4

11.2.4 Equipment maintenance RIN.4.BP6

11.2.5 Removal of assets RIN.4

11.2.6 Security of equipment and assets off-

premises

RIN.4.BP1-BP2

11.2.7 Secure disposal or re-use of

equipment

RIN.4.BP2

11.2.8 Unattended user equipment RIN.2.BP5

11.2.9 Clear desk and clear screen policy RIN.4.BP2

9 Access control

9.1 Business requirements of access control

9.1.1 Access control policy RIN.4.BP1-BP2,BP4,BP6

9.1.2 Access to networks and network

services

RIN.4.BP2

9.2 User access management

9.2.1 User registration and de-registration RIN.1.BP10

9.2.2 User access provisioning RIN.1.BP10

9.2.3 Management of privileged access

rights

RIN.1.BP10

9.2.4 Management of secret authentication

information of users

RIN.1.BP10

9.2.5 Review of user access rights RIN.1.BP10

9.2.6 Removal or adjustment of access rights RIN.4.BP2

9.3 User responsibilities

9.3.1 Use of secret authentication

information

RIN.2.BP5

9.4 System and application access control

9.4.1 Information access restriction RIN.4.BP1-BP2,BP4

9.4.2 Secure log-on procedures e

9.4.3 Password management system e

9.4.4 Use of privileged utility programs e

9.4.5 Access control to program source code SUP.8

10 Cryptography

10.1 Cryptographic controls

10.1.1 Policy on the use of cryptographic

controls

e

10.1.2 Key management e

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 4 31

12 Operations security

12.1 Operational procedures and responsibilities

12.1.1 Documented operating procedures SUP.7

12.1.2 Change management SUP.10

12.1.3 Capacity management e

12.1.4 Separation of development, testing

and operational environments

ENG.7

ENG.8

ENG.9

ENG.10

12.2 Protection from malware

12.2.1 Controls against malware RIN.4.BP2

12.3 Backup

12.3.1 Information backup SUP.8.BP10

RIN.4.BP2

12.4 Logging and monitoring

12.4.1 Event logging RIN.4.BP2,BP4

12.4.2 Protection of log information e

12.4.3 Administrator and operator logs e

12.4.4 Clock synchronisation e

12.5 Control of operational software

12.5.1 Installation of software on

operational systems

ENG.11

12.6 Technical vulnerability management

12.6.1Management of technical

vulnerabilities

MAN.5

12.6.2 Restrictions on software installation RIN.1.BP10

12.7 Information systems audit considerations

12.7.1 Information systems audit controls SUP.5.BP1-BP4

13 Communications security

13.1 Network security management

13.1.1 Network controls RIN.4.BP4,BP6

13.1.2 Security of network services ACQ.3.BP1

13.1.3 Segregation in networks RIN.4.BP2

13.2 Information transfer

13.2.1 Information transfer policies and

procedures

RIN.4.BP1-BP2,BP4

13.2.2 Agreements on information transfer ACQ.3.BP1,BP2

SPL.1.BP9-BP10

RIN.4.BP1-BP2

13.2.3 Electronic messaging RIN.4.BP2

13.2.4 Confidentiality or non-disclosure

agreements

RIN.1.BP1

14 System acquisition, development and maintenance

14.1 Security requirements of information systems

14.1.1 Information security requirements

analysis and specification

ENG.1.BP1-BP6

ENG.2.BP1-BP6

ENG.3.BP1-BP7

ENG.4.BP1-BP6

14.1.2 Securing application services on

public networks

ENG.1.BP1-BP6

ENG.2.BP1-BP6

RIN.4.BP2

14.1.3 Protecting application services

transactions

ENG.1.BP1-BP6

ENG.2.BP1-BP6

RIN.4.BP2

14.2 Security in development and support processes

14.2.1 Secure development policy PIM.1

MAN.2

14.2.2 System change control procedures SUP.8

SUP.10

14.2.3 Technical review of applications after

operating platform changes

ENG.7

14.2.4 Restrictions on changes to software

packages

SUP.10

14.2.5 Secure system engineering principles PIM.1

14.2.6 Secure development environment RIN.4

14.2.7 Outsourced development ACQ.1

ACQ.2

ACQ.3

ACQ.4

ACQ.5

14.2.8 System security testing ENG.10

14.2.9 System acceptance testing ACQ.5.BP3

14.3 Test data

14.3.1 Protection of test data ENG.4.BP3

ENG.8

15 Supplier relationships

15.1 Information security in supplier relationships

15.1.1 Information security policy for

supplier relationships

ACQ.2.BP3

ACQ.3.BP1

RIN.4.BP2

15.1.2 Addressing security within supplier

agreements

ACQ.2.BP3

ACQ.3.BP1

RIN.4.BP2

15.1.3 Information and communication

technology supply chain

ACQ.2.BP3

ACQ.3.BP1

15.2 Supplier service delivery management

15.2.1 Monitoring and review of supplier

services

ACQ.4.BP3,BP4

15.2.2 Managing changes to supplier

services

ACQ.4.BP5

SUP.10.BP1-BP9

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 432

16 Information security incident management

16.1 Management of information security incidents and

improvements

16.1.1 Responsibilities and procedures SUP.9 Level 2

MAN.5 Level 2

16.1.2 Reporting information security events SUP.9

MAN.5

RIN.3.BP4

16.1.3 Reporting information security

weaknesses

SUP.9

MAN.5

16.1.4 Assessment of and decision on

information security events

SUP.9

MAN.5

16.1.5 Response to information security

incidents

SUP.9

MAN.5

16.1.6 Learning from information security

incidents

SUP.9

MAN.5

RIN.3.BP4

16.1.7 Collection of evidence SUP.9

RIN.3.BP4

17 Information security aspects of business continuity management

17.1 Information security continuity

17.1.1 Planning information security

continuity

MAN.2

RIN.4

17.1.2 Implementing information security

continuity

PIM.1

17.1.3 Verify, review and evaluate

information security continuity

MAN.2

RIN.4

17.2 Redundancies

17.2.1 Availability of information processing

facilities

MAN.2

RIN.4

18 Compliance

18.1 Compliance with legal and contractual requirements

18.1.1 Identification of applicable legislation

and contractual requirements

ENG.1

ENG.2

ENG.4

18.1.2 Intellectual property rights ACQ.3.BP1-BP3

ENG.1.BP3

SPL.1.BP9-BP10

PIM.1.BP3

18.1.3 Protection of records SUP.7.BP1,BP3,BP6-BP8

SUP.8.BP10

18.1.4 Privacy and protection of personally

identifiable information

ACQ.3.BP1-BP3

ENG.1.BP3

SPL.1.BP9-BP10

RIN.4.BP1-BP4

18.1.5 Regulation of cryptographic controls ACQ.3.BP1-BP3

ENG.1.BP3

SPL.1.BP9-BP10

18.2 Information security reviews

18.2.1 Independent review of information

security

SUP.5.BP1-BP3

18.2.2 Compliance with security policies and

standards

SUP.1.BP1-BP5

18.2.3 Technical compliance review SUP.2.BP3

SUP.3.BP3

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 4 33

r e f e r e n c e s

Amengual E, Mas A. Software process improvement in small companies: an experience. In: 14th European Software Process Improvement Conference; 2007. 11.11e8.

Amengual E, Mas A. A new method of ISO/IEC TR 15504 and ISO 9001:2000 simultaneous application on software SMEs. In: 3rd International SPICE Conference on Process Assessment and Improvement; 2003. p. 87e92.

Barafort B, Humbet J-P, Poggi S. Information security management and ISO/IEC 15504: the link opportunity between security and quality. In: International SPICE Conference on Process Assessment and Improvement; 2006.

Bernard R. Information lifecycle security risk assessment: a tool for closing security gaps. Comput Secur 2007;26:26e30.

Boynton BC. Identification of process improvement methodologies with application in information security. In: Proceedings of the 4th annual conference on Information security curriculum development InfoSecCD; 2007.

Da Veiga A, Eloff JHP. A framework and assessment instrument for information security culture. Comput Secur 2010;29:196e207.

Garz�as J, Pino FJ, Piattini M, Fern�andez CM. A maturity model for the Spanish software industry based on ISO standards. Comput Stand Interfaces November 2013;35(6):616e28.

Gerber M, von Solms R. Information security requirements e

interpreting the legal aspects. Comput Secur 2008;27:124e35. Gregor S, Hevner AR. Positioning and presenting design science

research for maximum impact. MIS Q 2013;37(2):341e55. Hevner AR, March ST, Park J, Ram S. Design science in

information systems research. MIS Q 2004;28(1):75e105. ISACA. COBIT 5. Information Systems Audit and Control

Association; 2012. ISO/IEC. ISO/IEC 12207:1995/Amd1:2002/Amd2:2004 information

technology e software life cycle processes. 2004. ISO/IEC. ISO/IEC 15504-1:2004 information technology e process

assessment e part 1: concepts and vocabulary. 2004. ISO/IEC. ISO/IEC 15504-2:2003/Cor1:2004 software engineering e

process assessment e part 2: performing an assessment. 2004. ISO/IEC. ISO/IEC 15504-5:2006 information technology e software

process assessment e part 5: an exemplar process assessment model. 2006.

ISO/IEC. ISO/IEC TS 15504-10:2011 information technology e

process assessment e part 10: safety extension. 2011. ISO/IEC. ISO/IEC 27001:2013 information technology e security

techniques e information security management systems e

requirements. 2013. ISO/IEC. ISO/IEC 27002:2013 information technology e security

techniques e code of practice for information security controls. 2013.

ITmark. ITmark certification scheme for IT SMEs. http://it- mark.eu.2013.

J€arvinen P. On research methods. Tampere: Juvenes Print; 2001. Karabacak B, Sogukpinar I. A quantitative method for ISO 17799

gap analysis. Comput Secur 2006;25:413e9. Knapp KJ, Morris RF, Marshall TE, Byrd TA. Information security

policy: an organizational-level process model. Comput Secur 2009;28:493e508.

Lai Y-P, Dai R-H. The implementation guidance for practicing network isolation by referring to ISO-17799 standard. Comput Stand Interfaces 2009;31:748e56.

Lepmets M, McBride T, Ras E. Goal alignment in process improvement. J Syst Softw 2012;85:1440e52.

March ST, Smith GF. Design and natural science research on information technology. Decis Support Syst 1995;15:251e66.

Mas A, Amengual E. La mejora de los procesos de software en las peque~nas y medianas empresas (pyme). Un nuevo modelo y

c om p u t e r s & s e c u r i t y 4 8 ( 2 0 1 5 ) 1 9e3 434

su aplicaci�on en un caso real. Rev Esp Innov Calid Ing Software (REICIS) December 2005;1(2):7e29.

Mas A, Amengual E. Amethod for the implementation of a quality management system in software SMEs. In: 12th International Conference on Software Quality Management. British Computer Society; March 2004. p. 61e74.

Mas A, Amengual E, Mesquida AL. Application of ISO/IEC 15504 in very small enterprises. Syst Softw Serv Process Improv Commun Comput Inf Sci 2010;99:290e301.

Mas A, Flux�a B, Amengual E. Lessons learned from an ISO/IEC 15504 SPI programme in a company. J Softw Evol Process 2012;24(5):493e500.

Mellado D, Blanco C, S�anchez LE, Fern�andez-Medina E. A systematic review of security requirements engineering. Comput Stand Interfaces 2010a;32:153e65.

Mellado D, Fern�andez-Medina E, Piattini M. Security requirements engineering framework for software product lines. Inf Softw Technol 2010b;52:1094e117.

Mellado D, Fern�andez-Medina E, Piattini M. Towards security requirements management for software product lines: a security domain requirements engineering process. Comput Stand Interfaces 2008;30:361e71.

Mesquida AL, Mas A, Amengual E, Calvo-Manzano JA. IT service management process improvement based on ISO/IEC 15504: a systematic review. Inf Softw Technol 2012;54(3):239e47.

Mesquida AL, Mas A, Amengual E. La madurez de los servicios TI. Rev Esp Innov Calid Ing del Softw (REICIS) September 2009;5(2):77e87.

Oktaba H, Garcı́a F, Piattini M, Ruiz F, Pino FJ, Alquicira C. Software process improvement: the competisoft project. Computer Oct. 2007;40(10):21e8.

Pardo C, Pino FJ, Garcı́a F, Piattini M, Baldassarre MT. An ontology for the harmonization of multiple standards and models. Comput Stand Interfaces 2012;34:48e59.

SEI. CMMI® for development, CMMI-DEV version 1.3. Software Engineering Institute; November 2010.

Tudor. ITSM process assessment supporting ITIL, public research centre Henri Tudor. In: Barafort B, Betry V, Cortina S, Picard M, St-Jean M, Renault A, et al., editors. Zaltbommel: Van Haren Publishing; December 2009.

Valdevit T, Mayer N, Barafort B. Tailoring 27001 for SMEs: a guide to implement an information security management system in small settings. Softw Process Improv Commun Comput Inf Sci 2009;42:201e12.

Venable J, Pries-Heje J, Baskerville R. A comprehensive framework for evaluation in design science research. Des Sci Res Inf Syst Adv Theory Pract Lect Notes Comput Sci 2012;7286:423e38.

von Solms B, von Solms R. Incremental information security certification. Comput Secur 2001;20:308e10.

Xiao-yan G, Yu-qing Y, Li-lei L. An information security maturity evaluation mode. Procedia Eng 2011;24:335e9.

Zuccatoy A. Holistic security management framework applied in electronic commerce. Comput Secur 2007;26:256e65.

Zvanut B, Bajec M. A tool for IT process construction. Inf Softw Technol 2010;52:397e410.

Antoni Lluı́s Mesquida is an assistant lecturer of software engi- neering and project management at the University of the Balearic Islands. His research interests include software process improve- ment, project management and service management. He has participated in the QuaSAR project, a software process improve- ment programme in small software companies in the Balearic Islands. He received his PhD in Computer Science from the Uni- versity of the Balearic Islands. He has served as program com- mitteemember and industry chair of scientific conferences related to software quality.

Antonia Mas is a university lecturer of software engineering and project management at the University of the Balearic Islands. Her research interests include software process improvement, project management and service management. She has promoted and coordinated the QuaSAR Project, a software process improvement initiative in small software companies in the Balearic Islands. She received her degree in Computer Science from UAB (Catalonia, Spain) and her PhD in Computer Science from the University of the Balearic Islands. She has served as program committee member of scientific conferences and workshops related to soft- ware quality. She is an ISO/IEC 15504 assessor.

  • Implementing information security best practices on software lifecycle processes: The ISO/IEC 15504 Security Extension
    • 1. Introduction
    • 2. Research method and approach
    • 3. Development of the ISO/IEC 15504 Security Extension
      • 3.1. Standards used
        • 3.1.1. ISO/IEC 27000 series
        • 3.1.2. ISO/IEC 15504
      • 3.2. Analysis of the relations between ISO/IEC 27002 and ISO/IEC 15504-5
        • 3.2.1. Types of correspondence between ISO/IEC 27002 and ISO/IEC 15504-5
        • 3.2.2. Summary of the relations between ISO/IEC 27002 and ISO/IEC 15504-5
    • 4. The ISO/IEC 15504 Security Extension
      • 4.1. Application of the ISO/IEC 15504 Security Extension
    • 5. Validation of the ISO/IEC 15504 Security Extension
      • 5.1. Case study: validation of the ISO/IEC 15504 Security Extension in a company
      • 5.2. Lessons learned from the validation of the ISO/IEC 15504 Security Extension
    • 6. Conclusion and further work
    • Acknowledgements
    • Appendix 1. Mapping between the ISO/IEC 27002 security controls and ISO/IEC 15504-5 base practices
    • References