{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,17]],"date-time":"2025-11-17T03:03:48Z","timestamp":1763348628549,"version":"3.40.3"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031532269"},{"type":"electronic","value":"9783031532276"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,2,9]],"date-time":"2024-02-09T00:00:00Z","timestamp":1707436800000},"content-version":"vor","delay-in-days":39,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Cybersecurity is becoming increasingly important from a software business perspective. The software that is produced and sold generally becomes part of a complex landscape of customer applications and enlarges the risk that customer organizations take. Increasingly, software producing organizations are realizing that they are on the front lines of the cybersecurity battles. Maintaining security in a software product and software production process directly influences the livelihood of a software business. There are many models for evaluating security of software products. The product security maturity model is commonly used in the industry but has not received academic recognition. In this paper we report on the evaluation of the product security maturity model on usefulness, applicability, and effectiveness. The evaluation has been performed through 15\u00a0case studies. We find that the model, though rudimentary, serves medium to large organizations well and that the model is not so applicable within smaller organizations.<\/jats:p>","DOI":"10.1007\/978-3-031-53227-6_23","type":"book-chapter","created":{"date-parts":[[2024,2,8]],"date-time":"2024-02-08T06:02:41Z","timestamp":1707372161000},"page":"327-343","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["An Evaluation of\u00a0the\u00a0Product Security Maturity Model Through Case Studies at 15 Software Producing Organizations"],"prefix":"10.1007","author":[{"given":"Elena","family":"Baninemeh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Harold","family":"Toomey","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Katsiaryna","family":"Labunets","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gerard","family":"Wagenaar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Slinger","family":"Jansen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,2,9]]},"reference":[{"key":"23_CR1","doi-asserted-by":"publisher","first-page":"215758","DOI":"10.1109\/ACCESS.2020.3040220","volume":"8","author":"H Al-Matouq","year":"2020","unstructured":"Al-Matouq, H., Mahmood, S., Alshayeb, M., Niazi, M.: A maturity model for secure software design: a multivocal study. IEEE Access 8, 215758\u2013215776 (2020)","journal-title":"IEEE Access"},{"doi-asserted-by":"crossref","unstructured":"M. Alenezi, H. A. Basit, M. A. Beg, and M. S. Shaukat. Synthesizing secure software development activities for linear and agile lifecycle models. Softw.: Pract. Exp. 52(6), 1426\u20131453 (2022)","key":"23_CR2","DOI":"10.1002\/spe.3072"},{"key":"23_CR3","doi-asserted-by":"publisher","first-page":"567","DOI":"10.1007\/978-3-030-95947-0_40","volume-title":"Information Systems: 18th European, Mediterranean, and Middle Eastern Conference, EMCIS 2021, Virtual Event, December 8\u20139, 2021, Proceedings","author":"AA Ardo","year":"2022","unstructured":"Ardo, A.A., Bass, J.M., Gaber, T.: An empirical investigation of agile information systems development for cybersecurity. In: Themistocleous, M., Papadaki, M. (eds.) Information Systems: 18th European, Mediterranean, and Middle Eastern Conference, EMCIS 2021, Virtual Event, December 8\u20139, 2021, Proceedings, pp. 567\u2013581. Springer International Publishing, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-95947-0_40"},{"unstructured":"Assal, H.: The human dimension of software security and factors affecting security processes. PhD thesis, Carleton University (2018)","key":"23_CR4"},{"unstructured":"Assal, H., Chiasson, S.: Security in the software development lifecycle. In: 14th Symposium on Usable Privacy and Security (SOUPS 2018), pp. 281\u2013296 (2018)","key":"23_CR5"},{"doi-asserted-by":"crossref","unstructured":"Attwood, S., Onumah, N., Paxton-Fear, K., Kharel, R.: Security-focused prototyping: A natural precursor to secure development. In: 2022 13th International Symposium on Communication Systems, Networks and Digital Signal Processing (CSNDSP), pp. 356\u2013361. IEEE (2022)","key":"23_CR6","DOI":"10.1109\/CSNDSP54353.2022.9907931"},{"unstructured":"Bekkers, W., Spruit, M.R., van de Weerd, I., van Vliet, R. and Mahieu, A., et al.: A situational assessment method for software product management. In: Proceedings of the 18th European Conference on Information Systems (ECIS2010) (2010)","key":"23_CR7"},{"key":"23_CR8","volume-title":"Contributions to Securing Software Updates in IoT","author":"PN Bideh","year":"2022","unstructured":"Bideh, P.N.: Contributions to Securing Software Updates in IoT. Department of Electrical and Information Technology, Faculty of Engineering (2022)"},{"doi-asserted-by":"crossref","unstructured":"Bugeja, J., Vogel, B., Jacobsson, A., Varshney, R.: IoTSM: an end-to-end security model for IoT ecosystems. In: 2019 International Conference on Pervasive Computing and Communications Workshops, pp. 267\u2013272. IEEE (2019)","key":"23_CR9","DOI":"10.1109\/PERCOMW.2019.8730672"},{"unstructured":"Farshidi, S.: Multi-criteria decision-making in software production. PhD thesis, Utrecht University (2020)","key":"23_CR10"},{"unstructured":"Hathaway, O.A., et al.: The law of cyber-attack. California law review, pp. 817\u2013885 (2012)","key":"23_CR11"},{"doi-asserted-by":"crossref","unstructured":"Hevner, A., Chatterjee, S., Hevner, A., Chatterjee, S.: Design science research in information systems. Design research in information systems, pp. 9\u201322 (2010)","key":"23_CR12","DOI":"10.1007\/978-1-4419-5653-8_2"},{"doi-asserted-by":"crossref","unstructured":"H\u00f6st, M., Hell, M.: Evaluation of the havoss software process maturity model. In: 2020 46th Euromicro Conference on Software Engineering and Advanced Applications (SEAA), pp. 137\u2013140. IEEE (2020)","key":"23_CR13","DOI":"10.1109\/SEAA51224.2020.00031"},{"issue":"1","key":"23_CR14","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1007\/s10664-022-10238-y","volume":"28","author":"F Hou","year":"2023","unstructured":"Hou, F., Jansen, S.: A systematic literature review on trust in the software ecosystem. Empir. Softw. Eng. 28(1), 8 (2023)","journal-title":"Empir. Softw. Eng."},{"doi-asserted-by":"crossref","unstructured":"Iovan, M., Cruzes, D.S., Johansen, E.A.: A framework for a sustainable software security program. Evolving Software Processes, pp. 47\u201369 (2022)","key":"23_CR15","DOI":"10.1002\/9781119821779.ch2"},{"doi-asserted-by":"crossref","unstructured":"Jaatun, M.G.: The building security in maturity model as a research tool. In: Empirical Research for Software Security, pp. 201\u2013208. CRC Press (2017)","key":"23_CR16","DOI":"10.1201\/9781315154855-7"},{"doi-asserted-by":"crossref","unstructured":"Jansen, S.: A focus area maturity model for software ecosystem governance. Inform. Softw. Technol. 1, 118 (2020)","key":"23_CR17","DOI":"10.1016\/j.infsof.2019.106219"},{"unstructured":"Kudriavtseva, A., Gadyatskaya, O.: Secure software development methodologies: a multivocal literature review. arXiv preprint arXiv:2211.16987 (2022)","key":"23_CR18"},{"issue":"3","key":"23_CR19","first-page":"7","volume":"30","author":"G McGraw","year":"2015","unstructured":"McGraw, G.: Software security and the building security in maturity model (bsimm). J. Comput. Sci. Coll. 30(3), 7\u20138 (2015)","journal-title":"J. Comput. Sci. Coll."},{"key":"23_CR20","doi-asserted-by":"publisher","first-page":"403","DOI":"10.1007\/978-3-030-38919-2_33","volume-title":"SOFSEM 2020: Theory and Practice of Computer Science: 46th International Conference on Current Trends in Theory and Practice of Informatics, SOFSEM 2020, Limassol, Cyprus, January 20\u201324, 2020, Proceedings","author":"F Moy\u00f3n","year":"2020","unstructured":"Moy\u00f3n, F., Bayr, C., Mendez, D., D\u00e4nnart, S., Beckers, K.: A light-weight tool for the self-assessment of security compliance in software development \u2013 an industry case. In: Chatzigeorgiou, A., Dondi, R., Herodotou, H., Kapoutsis, C., Manolopoulos, Y., Papadopoulos, G.A., Sikora, F. (eds.) SOFSEM 2020: Theory and Practice of Computer Science: 46th International Conference on Current Trends in Theory and Practice of Informatics, SOFSEM 2020, Limassol, Cyprus, January 20\u201324, 2020, Proceedings, pp. 403\u2013416. Springer International Publishing, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-38919-2_33"},{"key":"23_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1007\/978-3-030-03673-7_6","volume-title":"Product-Focused Software Process Improvement","author":"P Nikbakht Bideh","year":"2018","unstructured":"Nikbakht Bideh, P., H\u00f6st, M., Hell, M.: HAVOSS: a maturity model for handling vulnerabilities in third party OSS components. In: Kuhrmann, M., Schneider, K., Pfahl, D., Amasaki, S., Ciolkowski, M., Hebig, R., Tell, P., Kl\u00fcnder, J., K\u00fcpper, S. (eds.) PROFES 2018. LNCS, vol. 11271, pp. 81\u201397. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03673-7_6"},{"doi-asserted-by":"crossref","unstructured":"N\u00fa\u00f1ez, J.C.S., Lindo, A.C., Rodr\u00edguez, P.G.: A preventive secure software development model for a software factory: a case study. IEEE Access, 8, 77653\u201377655 (2020)","key":"23_CR22","DOI":"10.1109\/ACCESS.2020.2989113"},{"doi-asserted-by":"crossref","unstructured":"Onumah, N., Attwood, S., Kharel, R.: Towards secure application development: A cyber security centred holistic approach. In: 2020 12th International Symposium on Communication Systems, Networks and Digital Signal Processing (CSNDSP), pp. 1\u20136. IEEE (2020)","key":"23_CR23","DOI":"10.1109\/CSNDSP49049.2020.9249631"},{"key":"23_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2022.106890","volume":"147","author":"M Overeem","year":"2022","unstructured":"Overeem, M., Mathijssen, M., Jansen, S.: Api-m-famm: a focus area maturity model for API management. Inform. Software Tech. 147, 106890 (2022)","journal-title":"Inform. Software Tech."},{"doi-asserted-by":"crossref","unstructured":"Palma, F., Realista, N., Serr\u00e3o, C., Nunes, L., Oliveira, J., Almeida, A.: Automated security testing of android applications for secure mobile development. In: 2020 IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW), pp. 222\u2013231. IEEE (2020)","key":"23_CR25","DOI":"10.1109\/ICSTW50294.2020.00046"},{"doi-asserted-by":"crossref","unstructured":"Ramirez, A., Aiello, A., Lincke, S.J.: A survey and comparison of secure software development standards. In: 2020 13th CMI Conference on Cybersecurity and Privacy, pp. 1\u20136. IEEE (2020)","key":"23_CR26","DOI":"10.1109\/CMI51275.2020.9322704"},{"doi-asserted-by":"crossref","unstructured":"Ransome, J., Misra, A.: Core software security. CRC Press (2018)","key":"23_CR27","DOI":"10.1201\/b16134"},{"doi-asserted-by":"crossref","unstructured":"Rindell, K., Holvitie, J.: Security risk assessment and management as technical debt. In: 2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security), pp. 1\u20138. IEEE (2019)","key":"23_CR28","DOI":"10.1109\/CyberSecPODS.2019.8885100"},{"doi-asserted-by":"crossref","unstructured":"Rindell, K., Hyrynsalmi, S., Lepp\u00e4nen, V.: Aligning security objectives with agile software development. In: Proceedings of the 19th International Conference on Agile Software Development: Companion, pp. 1\u20139 (2018)","key":"23_CR29","DOI":"10.1145\/3234152.3234187"},{"key":"23_CR30","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2020.106488","volume":"131","author":"K Rindell","year":"2021","unstructured":"Rindell, K., Ruohonen, J., Holvitie, J., Hyrynsalmi, S., Lepp\u00e4nen, V.: Security in agile software development: a practitioner survey. Inf. Softw. Technol. 131, 106488 (2021)","journal-title":"Inf. Softw. Technol."},{"doi-asserted-by":"crossref","unstructured":"Rindell, K., Ruohonen, J., Hyrynsalmi, S.: Surveying secure software development practices in finland. In: Proceedings of the 13th International Conference on Availability, Reliability and Security, pp. 1\u20137 (2018)","key":"23_CR31","DOI":"10.1145\/3230833.3233274"},{"key":"23_CR32","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/s10664-008-9102-8","volume":"14","author":"P Runeson","year":"2009","unstructured":"Runeson, P., H\u00f6st, M.: Guidelines for conducting and reporting case study research in software engineering. Empir. Softw. Eng. 14, 131\u2013164 (2009)","journal-title":"Empir. Softw. Eng."},{"doi-asserted-by":"crossref","unstructured":"Ryan, I., Roedig, U., Stol, K.-J.: Insecure software on a fragmenting internet. In: 2022 Cyber Research Conference-Ireland (Cyber-RCI), pp. 1\u20139. IEEE (2022)","key":"23_CR33","DOI":"10.1109\/Cyber-RCI55324.2022.10032675"},{"doi-asserted-by":"crossref","unstructured":"Ryan, I., Roedig, U., Stol, K.-J.: Measuring secure coding practice and culture: A finger pointing at the moon is not the moon. In 2023 IEEE\/ACM 45th Int\u2019l Conference on Software Engineering (ICSE), pp. 1622\u20131634. IEEE (2023)","key":"23_CR34","DOI":"10.1109\/ICSE48619.2023.00140"},{"doi-asserted-by":"crossref","unstructured":"Teodoro, N., Serr\u00e3o, C.: Web application security: improving critical web-based applications quality through in-depth security analysis. In: International Conference on Information Society (i-Society 2011), pp. 457\u2013462 (2011)","key":"23_CR35","DOI":"10.1109\/i-Society18435.2011.5978496"},{"unstructured":"T\u00f8ndel, I.A.: Prioritisation of security in agile soft. dev. projects (2022)","key":"23_CR36"},{"key":"23_CR37","volume-title":"and C","author":"M van de Werfhorst","year":"2020","unstructured":"van de Werfhorst, M., Poll, E., Schoemaker, H.: and C. Kop, Security recommendations for agile and devops development at ridder data systems (2020)"},{"key":"23_CR38","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1007\/978-3-642-13335-0_22","volume-title":"Global Perspectives on Design Science Research","author":"M van Steenbergen","year":"2010","unstructured":"van Steenbergen, M., Bos, R., Brinkkemper, S., van de Weerd, I., Bekkers, W.: The design of focus area maturity models. In: Winter, R., Zhao, J.L., Aier, S. (eds.) Global Perspectives on Design Science Research, pp. 317\u2013332. Springer Berlin Heidelberg, Berlin, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-13335-0_22"},{"issue":"2","key":"23_CR39","first-page":"35","volume":"25","author":"M van Steenbergen","year":"2013","unstructured":"van Steenbergen, M., Bos, R., Brinkkemper, S., van de Weerd, I., Bekkers, W.: Improving is functions step by step: the use of focus area maturity models. Scand. J. Inf. Syst. 25(2), 35\u201356 (2013)","journal-title":"Scand. J. Inf. Syst."},{"key":"23_CR40","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1057\/ejis.2014.36","volume":"25","author":"J Venable","year":"2016","unstructured":"Venable, J., Pries-Heje, J., Baskerville, R.: Feds: a framework for evaluation in design science research. Eur. J. Inf. Syst. 25, 77\u201389 (2016)","journal-title":"Eur. J. Inf. Syst."},{"doi-asserted-by":"crossref","unstructured":"Venson, E., Alfayez, R., Gomes, M.M., Figueiredo, R.M., Boehm, B.: The impact of software security practices on development effort: An initial survey. In: 2019 ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), pages 1\u201312. IEEE (2019)","key":"23_CR41","DOI":"10.1109\/ESEM.2019.8870153"},{"doi-asserted-by":"crossref","unstructured":"Von Solms, R., Van Niekerk, J.: From information security to cyber security. Comput. Secur. 38, 97\u2013102 (2013)","key":"23_CR42","DOI":"10.1016\/j.cose.2013.04.004"},{"doi-asserted-by":"crossref","unstructured":"Wen, S.-F.: Software security in open source development: a systematic literature review. In: 2017 21st Conference of Open Innovations, pp. 364\u2013373. IEEE (2017)","key":"23_CR43","DOI":"10.23919\/FRUCT.2017.8250205"},{"doi-asserted-by":"crossref","unstructured":"White, C.A.: Root causes of insecure internet of things and holistically addressing them. In: 2020 International Conference on Computational Science and Computational Intelligence (CSCI), pp. 1066\u20131074. IEEE (2020)","key":"23_CR44","DOI":"10.1109\/CSCI51800.2020.00198"},{"unstructured":"Williams, L.: Secure software lifecycle knowledge area issue. The National Cyber Security Center (2019)","key":"23_CR45"}],"container-title":["Lecture Notes in Business Information Processing","Software Business"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-53227-6_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,7]],"date-time":"2024-03-07T20:05:24Z","timestamp":1709841924000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-53227-6_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031532269","9783031532276"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-53227-6_23","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"type":"print","value":"1865-1348"},{"type":"electronic","value":"1865-1356"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"9 February 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICSOB","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Software Business","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lahti","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Finland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 November 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 November 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icsob2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.lut.fi\/en\/icsob2023","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"79","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"8","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"34% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4,07","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3,21","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}