I need an 3-4 page software assurance guidelines document . It is a continuation of week 1. I would like to preview the answer before I pay.

profilesmitty4eva
guidelines_1___abc_0.docx

Running Head: SOFTWARE ASSURANCE GUIDELINES 1

SOFTWARE ASSURANCE GUIDELINES 8

Software Assurance CSS321

Security Development Model Overview

28 February 2017

Table of Contents BACKGROUND 3 Product Overview 3 Departmental Organisation 3 System Design Life Cycle 4 ASSURANCE GUIDELINES 4 Desktop applications 5 Web Application and Database Application 6 Week 3 7 Week 4 7 Week 5 7 References 8

BACKGROUND

ABC is a software development company. It is a medium enterprise that has a wide range of clients from all over the country. The company has its headquarters in Miami, Florida and branches in the United States. The company is making plans to expand out of the United States beginning with Mexico and Canada. ABC focuses on the development of customer made application software. This means that most of the software created in the firm is specifically requested by the clients. However, some generic software is also created which can later be purchased by a client and re-engineered to fit their specific needs. The software assurance guidelines used by the company are specific to the type of software made. Desktop applications have different assurance specifications from web applications. The guidelines specified will be implemented from development all the way to the client organisation. The software guidelines can only be efficient when both the developers and the users adhere to them.

Product Overview

The company does provide a number of software applications for the government. These applications include Account Pro which is accounting software. It is desktop software and it is very optimal. The company also provides the government with a police record system. This application is web based and it relies heavily on the internet and the local area networks of the police stations. The application is optimised by a database that stores all of the information.

Departmental Organisation

The firm is organised into four different departments. The first department deals with installation and maintenance of software. This is the after sale services department. This department is vital in the company since software often require patchwork and maintenance. The second department is the specifications research department. This department work hand in hand with the clients to determine the software that the clients require most and they communicate these requirements to the development department that is made up of developers who code and test the applications. The marketing and sales department ensures that the company has good public relations and stays relevant among the clients.

System Design Life Cycle

The system design life cycle that is used in the organization is quite traditional and standard. The first phase is planning and information gathering. In this phase the system requirements are gathered and information is gathered from the users. In the next phase, this information is organised and the system is proposed that will be able to solve the problems. Next is the design phase where the coding is done to develop the system. After coding, the system is taken into testing and debugging. If it optimal, it is taken into the implementation phase where it is introduced to the clients. Maintenance is the last phase that requires updates and patches which leads us back to the first stage and it becomes a cycle (Avison and Shah, 2007).

ASSURANCE GUIDELINES

The guidelines are applied in the phases by ensuring that the specifications gathered are exactly what the client wants. The system design and coding is optimised by debugging and testing and the people who will be in contact with the system are supposed to be trained in the implementation phase so that they are able to use the system optimally and avoid performing tasks that may be detrimental to the application.

ABC Company produces software that is consumed by the American government. The company produces desktop, web and database applications. The software that the company produces will be analyzed in this section to determine the security and performance risks associated with all of these applications as well as the possible implications that these risks may have to the clients. For each risk, techniques for software assurance will be proposed and how these techniques can be applied to ensure that the application is optimised at all times.

Desktop applications

ABC Company offers a wide range of desktop applications. However, the most robust of all these applications that have been sold to the government is the Account Pro application. This is software that is installed to a work station computer and it enables the user to be able to perform complex accounting functions rather easily. However, the person manipulating it must have both accounting and information technology knowledge so that he or she can be able to manipulate the software wellness the software doesn't do all the accounting independently and it requires the expertise of an accountant to be able to operate best. This accountant must also be well versed with information technology knowledge so as to operate the application.

The application has all the characteristics of a desktop application. This means that it is at a lower risk of intrusion from the internet and other forms of attacks. However, it is still cumbersome to install and maintain. This is so since maintenance and installation has to be done independently in every work station. The ease of access is also reduced since the user has to move to the physical location of the computer with the application so as to be able to access it (Lee et.al, 2008). This makes the use of desktop applications to be unfavourable due to the cumbersome nature.

However, the application is very robust and optimised as far as security is concerned. Guidelines such as the use of user authentication have been put in place to make sure that unauthorised users don't get access to the application. The main threat that the clients face while using this application is however, not from third party intrusion but rather from it becoming out-dated (Lee et.al, 2008). This can reduce the general productivity of the application making it harder for it to be used to solve most if not all of the accounting problems of the client. This will make it inefficient.

The application can become out-dated and after five to 10 years, it will no longer satisfy the organisation needs that had been identified. This, to mitigate this threat, regular maintenance is done on the application and any new requirements are added to the application. This maintenance and patchwork is an aftersales service that the government is happy to pay for.

Web Application and Database Application

The web applications sold by the company are often optimised by a database thus making them two in one. The developers prefer php platform to develop these web based application and the database server most used is SQL. The two platforms work well together once linked to create an optimal application. The company sold a web based application to the police department in south Miami that has been able to help them keep records of the statements made by the public and the arrests that have been made on these statements. This system has also helped them keep record of the development of these cases.

Such a system is easier to use than a desktop application since you can be able to access it from anywhere as long as you have internet connection and access the police local area network. It is also easier to install and maintain since the installation is done on a central server and all the users access it in a client-server architecture. This means that the users access it through a web browser (Meier et.al, 2013).

However, this application comes with a high risk of third party intrusion. This means that the application can be accessed by an unauthorised third party. Such access can cause the organisation of the client to be vulnerable and their records to be tampered with. This can cause unprecedented losses. To handle this, the application does have user authentication and user accounts with logs to help monitor the activities of each user and identify unusual activity. However, the LAN in the police department also needs to be optimised with firewalls and honeypots (Meier et.al, 2013) to ensure that any third party that tries to access the network and thus the application through hacking or cracking is not able to do so.

Another threat that the clients may experience is the need for scaling. The records will increase in number and with time, the department will require a larger database with a larger capacity so as to be able to hold all the records available. This scaling is done through maintenance by slowly expanding the database as the requirements of the user increase. The functionality of the application is also updated regularly.

Week 3

Week 4

Week 5

References

Meier, J. D., Mackman, A., Dunner, M., Vasireddy, S., Escamilla, R., & Murukan, A. (2013). Improving web application security: threats and countermeasures. Microsoft Corporation, 3.

Lee, D. C., Crowley, P. J., Baer, J. L., Anderson, T. E., & Bershad, B. N. (2008, April). Execution characteristics of desktop applications on Windows NT. In ACM SIGARCH Computer Architecture News (Vol. 26, No. 3, pp. 27-38). IEEE Computer Society.

Avison, D. E., & Shah, H. U. (2007). The information systems development life cycle: A first course in information systems. McGraw-Hill.