search menu icon-carat-right cmu-wordmark

Software Assurance Measurement – State of the Practice

November 2013 Technical Note
Dan Shoemaker (University of Detroit Mercy), Nancy R. Mead

In this report, the authors describe the current state of the practice and emerging trends in software assurance measurement.

Publisher:

Software Engineering Institute

CMU/SEI Report Number

CMU/SEI-2013-TN-019

DOI (Digital Object Identifier):
10.1184/R1/6584057.v1

Abstract

This report identifies and describes the current state of the practice in software assurance measurement. This discussion focuses on the methods and technologies that are applicable in the domain of existing software products, software services, and software processes. This report is not meant to be prescriptive; instead it attempts to provide an end-to-end discussion of the state of the practice in software assurance measurement. In addition, it points out significant emerging trends in the field. The overall discussion touches on the existing principles, concepts, methods, tools, techniques, and best practices for detection of defects and vulnerabilities in code.