A comprehensive initiative to enhance the security posture of open-source software
M. Antonacci*, V. Ciaschini, G. Donvito and B. Martelli
Published on:
October 29, 2024
Abstract
In the dynamic landscape of digital security, safeguarding information assets stands as a paramount concern for organizations. This paper presents a comprehensive initiative undertaken by INFN, a prominent player in research, to bolster the security posture of its open-source components within the DataCloud production middleware. Central to this initiative is the recognition of the pivotal role security plays in the software development lifecycle (SDLC). The paper outlines INFN’s strategic approach to align with industry standards such as OWASP SAMM and ISO/IEC 27002 frameworks. Through collaboration and proactive measures, INFN aims to establish virtuous processes aimed at enhancing security governance, self-assessment, continuous monitoring, and timely responses to emerging vulnerabilities. The ultimate goal is to cultivate a more secure and resilient software ecosystem tailored to scientific data analysis.
DOI: https://doi.org/10.22323/1.458.0012
How to cite
Metadata are provided both in "article" format (very similar to INSPIRE) as this helps creating
very compact bibliographies which can be beneficial to authors and
readers, and in "proceeding" format
which is more detailed and complete.