Information security aspects of public software

  • Authors:
  • Henrique Soares;Raphael Machado;Bruno Salgado;Rafael Soares;Jarbas Lopes Cardoso, Jr;Luis Felipe Costa

  • Affiliations:
  • Clavis Segurança da Informação, Rio de Janeiro -- RJ -- Brazil;Clavis Segurança da Informação, Rio de Janeiro -- RJ -- Brazil;Clavis Segurança da Informação, Rio de Janeiro -- RJ -- Brazil;Clavis Segurança da Informação, Rio de Janeiro -- RJ -- Brazil;CTI Renato Archer, Campinas -- SP -- Brasil;Ministério do Planejamento, Orçamento e Gestão, Secretaria de Logística e Tecnologia da Informação

  • Venue:
  • Proceedings of the Fifth International Conference on Management of Emergent Digital EcoSystems
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Public Software can be defined as any software that is endorsed by a Public Agent and distributed for wide use by the society. The concept of Public Software is an outspread of the idea that "software" is an important asset for the welfare of society, and therefore providing citizens with proper software tools is a task of public interest, which in some cases should be performed by the government itself. When a Public Agent endorses a software and gives it the "seal" of Public Software, he is -- explicitly or implicitly -- declaring that such software complies with minimum technical requirements, and stimulates its wide use by the society In the present paper, we discuss the importance that such requirements encompasses Information Security and we propose a validation model that is strongly based on security evaluation. In a world where cyber-crime is a reality and cyber-war becomes more and more relevant, it is fundamental that the Public Agent verify the Information Security aspects of a software before declaring it a Public Software, for otherwise, this Public Agent can be stimulating that security flaws and vulnerabilities are spread in the society, possibly in critical applications. We additionally discuss the importance of a strong validation procedure to assure the appropriate behavior of software regarding its functionalities and Information Security aspects. We conclude describing the Brazilian experience with the "Brazilian Public Software Portal" Public Software repository of open-source software.