Unlock instant, AI-driven research and patent intelligence for your innovation.

Software research and development security capability dynamic evaluation and promotion method and system

A security capability and dynamic evaluation technology, applied in computer security devices, instruments, electrical digital data processing, etc., can solve problems such as inability to improve the R&D team's security R&D capabilities, more training content, R&D security capability assessment, etc., to improve R&D security problems, improve training efficiency, and improve the effect of R&D security capabilities

Active Publication Date: 2020-12-01
SECZONE TECH CO LTD
View PDF5 Cites 3 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, in the process of software security lifecycle management, there is no automated solution for the assessment and improvement of R&D security capabilities, and more security awareness training for the entire R&D team
However, only relying on security awareness training cannot improve the security R&D capabilities of the R&D team, nor can it analyze the security R&D capabilities of each R&D personnel in a targeted manner. In this way, each training may affect different R&D personnel bring different effects, such as: for some groups of people, it is repeated training, but for other groups of people, the training may not be strong enough, or the training content is too much to be well grasped

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Software research and development security capability dynamic evaluation and promotion method and system
  • Software research and development security capability dynamic evaluation and promotion method and system
  • Software research and development security capability dynamic evaluation and promotion method and system

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0025] In order to describe the technical content, structural features, achieved goals and effects of the present invention in detail, the following will be described in detail in conjunction with the embodiments and accompanying drawings.

[0026] In order to conduct security assessment and improvement of R&D capability for each R&D personnel in the software R&D team, this embodiment discloses a method for dynamically evaluating and improving the security capability of software R&D. The software R&D in this embodiment is based on The software security research and development platform of the architecture, so that in the research and development process, each link can communicate in real time. The software security research and development platform can be built based on the S-SDLC concept. The software security research and development platform includes a storage module, a processing module 10 and an operation terminal. Specifically, as figure 1 with image 3 , the dynamic ev...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a software research and development security capability dynamic evaluation and promotion method and system. The method comprises the following steps: performing software research and development based on a software security research and development platform with a full life cycle management architecture, wherein a research and development task management tool and a plurality of types of safety test tools which are in communication connection with the software safety research and development platform through data interfaces are integrated in the software safety researchand development platform; dynamically acquiring security vulnerability information and task allocation information by the software security research and development platform; dynamically counting thetask allocation information of any research and development personnel to evaluate the research and development safety capability of the research and development personnel; when the research and development safety capability of the research and development personnel is lower than a set target, pushing orientation capability improvement data. By means of the method, the research and development safety capacity of each individual in a research and development team can be subjected to differentiated evaluation and targeted improvement, repeated capacity improvement training on unnecessary personnel is avoided, and the research and development safety capacity of research and development personnel and the training efficiency of enterprises are effectively improved.

Description

technical field [0001] The present invention relates to the technical field of software research and development security capability evaluation, in particular to a method and system for dynamically evaluating and improving software research and development security capability. Background technique [0002] At present, the core issue in the field of application security lies in the R&D process. For R&D security, technical personnel in the field have gradually reached a consensus that the full lifecycle management of software security should be implemented. However, in the process of software security lifecycle management, there is no automated solution for the assessment and improvement of R&D security capabilities, and more security awareness training for the entire R&D team. However, only relying on security awareness training cannot improve the security R&D capabilities of the R&D team, nor can it analyze the security R&D capabilities of each R&D personnel in a targeted ma...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): G06F21/57
CPCG06F21/577G06F2221/033
Inventor 潘志祥万振华王颉董燕李华
Owner SECZONE TECH CO LTD