Protection Poker: The New Software Security "Game";

  • Authors:
  • Laurie Williams;Andrew Meneely;Grant Shipley

  • Affiliations:
  • North Carolina State University;North Carolina State University;Red Hat

  • Venue:
  • IEEE Security and Privacy
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Tracking organizations such as the US CERT show a continuing rise in security vulnerabilities in software. But not all discovered vulnerabilities are equal—some could cause much more damage to organizations and individuals than others. In the inevitable absence of infinite resources, software development teams must prioritize security fortification efforts to prevent the most damaging attacks. Protection Poker is a collaborative means of guiding this prioritization. A case study of a Red Hat IT software maintenance team demonstrates Protection Poker's potential for improving software security practices and team software security knowledge.