A Study on the Challenges of Human-Centric Cyber-Security and the Guarantee of Information Quality — Oak Academic Publishing
Research ArticleOpen AccessGoogle Scholar indexed
A Study on the Challenges of Human-Centric Cyber-Security and the Guarantee of Information Quality
Department of Cyber-Security, National Events Center, Riyadh, Saudi Arabia
,
Department of Computer and Information Technologies, Technical College of Telecommunication and Information Riyadh TCTI, Technical and Vocational Training Corporation TVTC, Riyadh, Saudi Arabia
,
School of Science & Technology, University of New England, Armidale, Australia
,
Department of Computer Science, Higher Institute of Applied Sciences of Sousse, University of Sousse, Sousse, Tunisia
1 Department of Cyber-Security, National Events Center, Riyadh, Saudi Arabia
2 Department of Computer and Information Technologies, Technical College of Telecommunication and Information Riyadh TCTI, Technical and Vocational Training Corporation TVTC, Riyadh, Saudi Arabia
3 School of Science & Technology, University of New England, Armidale, Australia
4 Department of Computer Science, Higher Institute of Applied Sciences of Sousse, University of Sousse, Sousse, Tunisia
Information security and quality management are often considered two different fields. However, organizations must be mindful of how software security may affect quality control. This paper examines and promotes methods through which secure software development processes can be integrated into the Systems Software Development Life-cycle (SDLC) to improve system quality. Cyber-security and quality assurance are both involved in reducing risk. Software security teams work to reduce security risks, whereas quality assurance teams work to decrease risks to quality. There is a need for clear standards, frameworks, processes, and procedures to be followed by organizations to ensure high-level quality while reducing security risks. This research uses a survey of industry professionals to help identify best practices for developing software with fewer defects from the early stages of the SDLC to improve both the quality and security of software. Results show that there is a need for better security awareness among all members of software development teams.
Coburn, A., Leverett, E. and Woo, G. (2018) Solving Cyber Risk: Protecting Your Company and Society. John Wiley & Sons, Hoboken.
Salin, H. and Lundgren, M. (2022) Towards Agile Cybersecurity Risk Management for Autonomous Software Engineering Teams. Journal of Cybersecurity and Priv a cy , 2, 276-291. https://doi.org/10.3390/jcp2020015
Cissé, M. (2019) An ISO 27001 Compliance Project for a Cyber Security Service Team. Cyber Security : A Peer - Reviewed Journal , 2, 346-359.
Harmer, G. (2014) Governance of Enterprise IT Based on COBIT®5. IT Governance Publishing, Ely. https://www.itgovernance.co.uk/download/governance-of-enterprise-it-based-on-cobit-5-book-sample.pdf https://doi.org/10.2307/j.ctt7zsxfv
Blokdyk, G. (2017) Java Machine Learning Complete Self-Assessment Guide. CreateSpace Independent Publishing Platform, North Charleston. https://dl.acm.org/doi/10.5555/3164673
Alshammari, B., Fidge, C. and Corney, D. (2016) Developing Secure Systems: A Comparative Study of Existing Methodologies. Lecture Notes on Software Eng i neering , 4, 139-146.
Bahl, S. and Wali, O.P. (2014) Perceived Significance of Information Security Governance to Predict the Information Security Service Quality in Software Service Industry: An Empirical Analysis. Information Management & Computer Security , 22, 2-23. https://doi.org/10.1108/IMCS-01-2013-0002
Bokhari, S.A.A. and Myeong, S. (2023) The Impact of AI Applications on Smart Decision-Making in Smart Cities as Mediated by the Internet of Things and Smart Governance. IEEE Access , 11, 120827-120844. https://doi.org/10.1109/ACCESS.2023.3327174
Abed-Alguni, B.H. and Paul, D. (2022) Island-Based Cuckoo Search with Elite Opposition-Based Learning and Multiple Mutation Methods for Solving Optimization Problems. Soft Computing , 26, 3293-3312. https://doi.org/10.1007/s00500-021-06665-6
Alkhalifah, A. and Denden, M. (2023) Investigating the Impact of Covid-19 on the Morale of Deaf and Hearing-Impaired Students in Saudi Arabia Technical Colleges: Lessons Learned and Future Implications. Journal for Educators , Teachers and Trainers , 14, 420-428. https://doi.org/10.47750/jett.2023.14.03.051
Denden, M. and Alkhalifah, A. (2023) Assessing the Impact of Covid-19 on the Psychology of Saudi Technical College Students: Lessons and Tips. Creative Educ a tion , 14, 518-529. https://doi.org/10.4236/ce.2023.143036
Jemmali, M., Denden, M., Boulila, W., Srivastava, G., Jhaveri, R.H. and Gadekallu, T.R. (2022) A Novel Model Based on Window-Pass Preferences for Data Emergency Aware Scheduling in Computer Networks. IEEE Transactions on Industrial Info r matics , 18, 7880-7888. https://doi.org/10.1109/TII.2022.3149896
Alsmadi, I., Easttom, C., Tawalbeh, L. and Alsmadi, I. (2020) It Risk and Security Management. In: Alsmadi, I., Easttom, C. and Tawalbeh, L., Eds., the NICE Cyber Security Framework : Cyber Security Management , Springer, Cham, 55-78. https://doi.org/10.1007/978-3-030-41987-5
Andress, J. (2014) The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice. Syngress, Rockland.
Chakraborty, R.S., Zheng, Y. and Bhunia, S. (2016) Obfuscation-Based Secure Soc Design for Protection Against Piracy and Trojan Attacks. In: Chang, C.H. and Potkonjak, M., Eds., Secure System Design and Trustable Computing , Springer, Cham, 269-299. https://doi.org/10.1007/978-3-319-14971-4_8
Fatima, A., Khan, T.A., Abdellatif, T.M., Zulfiqar, S., Asif, M., Safi, W., Al Hamadi, H. and Al-Kassem, A.H. (2023) Impact and Research Challenges of Penetrating Testing and Vulnerability Assessment on Network Threat. 2023 International Co n ference on Business Analytics for Technology and Security ( ICBATS ), Dubai, 7-8 March 2023, 1-8. https://doi.org/10.1109/ICBATS57792.2023.10111168
Khan, K.M. (2012) Developing and Evaluating Security-Aware Software Systems. IGI Global, Hershey. https://doi.org/10.4018/978-1-4666-2482-5
Dowd, M., McDonald, J. and Schuh, J. (2006) The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities. Pearson Education, Upper Saddle River.
Wiltshire, I., Adapa, S. and Paul, D. (2023) Pandemic Speed: Accelerating Innovation in Cyber Security. In: Adapa, S., McKeown, T., Lazaris, M. and Jurado, T., Eds., Small and Medium - Sized Enterprises , and Business Uncertainty . Palgrave Studies in Global Entrepreneurship , Palgrave Macmillan, Singapore, 151-172. https://doi.org/10.1007/978-981-99-4844-4_9
Kim, L. (2022) Cybersecurity: Ensuring Confidentiality, Integrity, and Availability of Information. In: Hübner, U.H., Mustata Wilson, G., Morawski, T.S. and Ball, M.J., Eds., Nursing Informatics . Health Informatics , Springer, Cham, 391-410. https://doi.org/10.1007/978-3-030-91237-6_26
Melhim, L.K.B. (2023) Intelligent Surveillance Drone System for Health Care Enhancement in a Smart City. Communications in Mathematics and Appli cations , 14, 551-559. https://doi.org/10.26713/cma.v14i2.2153
Eljack, S., Jemmali, M., Denden, M., Sadig, M.A., Algashami, A.M. and Turki, S. (2024) Intelligent Solution System for Cloud Security Based on Equity Distribution: Model and Algorithms. Computers , Materials & Continua , 78, 1461-1479. https://doi.org/10.32604/cmc.2023.040919
Mohsen, D., Ghannay, N. and Samet, A. (2009) A Half Hollow Cylindrical Antenna (HHCA) Analysis Using the CFDTD Algorithm. Progress in Electromagnetics R e search C , 11, 51-60. https://doi.org/10.2528/PIERC09090804
Eljack, S., Jemmali, M., Denden, M., Turki, S., Khedr, W.M., Algashami, A.M. and ALsadig, M. (2023) A Secure Solution Based on Load-Balancing Algorithms Between Regions in the Cloud Environment. PeerJ Computer Science , 9, e1513. https://doi.org/10.7717/peerj-cs.1513
Ghannay, N., Denden, M., Romdhani, F. and Samet, A. (2008) A Novel Technique for Calculating Moment Method Impedance Matrix. IEEE Mediterranean Micr o wave Symposium 2008 Symposium , Damascus, 14-16 October 2008, 77-80.
Ohki, E., Harada, Y., Kawaguchi, S., Shiozaki, T. and Kagaya, T. (2009) Information Security Governance Framework. Proceedings of the First ACM Workshop on I n formation Security Governance , Chicago, 13 November 2009, 1-6. https://doi.org/10.1145/1655168.1655170
Rossi, M., Taisch, M. and Terzi, S. (2012) Lean Product Development: A Five-Steps Methodology for Continuous Improvement. 2012 18 th International ICE Conf e rence on Engineering , Technology and Innovation , Munich, 18-20 June 2012, 1-10. https://doi.org/10.1109/ICE.2012.6297704
Jabbari, R., Bin Ali, N., Petersen, K. and Tanveer, B. (2016) What Is Devops?: A Systematic Mapping Study on Definitions and Practices. Proceedings of the Scie n tific Workshop Proceedings of XP 2016, Edinburgh, 24 May 2016, 1-11. https://doi.org/10.1145/2962695.2962707
Grembi, J. (2008) Secure Software Development: A Security Programmer’s Guide. Cengage Learning, Boston.
Siddiqi, M.A. and Pak, W. (2021) An Agile Approach to Identify Single and Hybrid Normalization for Enhancing Machine Learning-Based Network Intrusion Detection. IEEE Access , 9, 137494-137513. https://doi.org/10.1109/ACCESS.2021.3118361
Gruber, D. (2020) Modern Application Development Security. Enterprise Strategy Group, Newton.
Gallivan, M.J. (2006) Diversity in Studying Gender and IT. In: Trauth, E.M., Ed., Encyclopedia of Gender and Information Technology , IGI Global, Hershey, 216-223. https://doi.org/10.4018/978-1-59140-815-4.ch034
McCormick, M. (2012) Waterfall vs. Agile Methodology. MPCS Inc., Newburgh.