{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T16:44:36Z","timestamp":1751388276292,"version":"3.40.5"},"reference-count":69,"publisher":"Wiley","issue":"4","license":[{"start":{"date-parts":[[2022,12,9]],"date-time":"2022-12-09T00:00:00Z","timestamp":1670544000000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"funder":[{"DOI":"10.13039\/501100004055","name":"King Fahd University of Petroleum and Minerals","doi-asserted-by":"publisher","award":["DF201007"],"award-info":[{"award-number":["DF201007"]}],"id":[{"id":"10.13039\/501100004055","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["Softw Pract Exp"],"published-print":{"date-parts":[[2023,4]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The heart of the application's secure operation is its software code. If the code contains flaws, the entire program might be hacked. The issue with software vulnerabilities is that they reveal coding flaws that hackers could exploit. The prevention of cybersecurity issues begins with the program code itself. When writing software code, a software developer must consider expressing the application's architecture and design requirements, keeping the code streamlined and efficient, and ensuring the code is safe. Secure code helps save the system from various cyber\u2010attacks by eliminating the weaknesses that many hacks rely on. To assist the software organization in Secure Software Coding (SSC), this article proposes a readiness model for SSC, namely SSCRM. The proposed model has five levels; SSC challenges and best practices (BP) are mapped at each level. The proposed model will help the organizations better understand SSC challenges and BPs and provide a roadmap for developing secure software code. The proposed model was evaluated using three case studies. The findings demonstrate that the proposed approach helps determine an organization's SSC level.<\/jats:p>","DOI":"10.1002\/spe.3175","type":"journal-article","created":{"date-parts":[[2022,12,9]],"date-time":"2022-12-09T13:41:19Z","timestamp":1670593279000},"page":"1013-1035","update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Toward a readiness model for secure software coding"],"prefix":"10.1002","volume":"53","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6339-2257","authenticated-orcid":false,"given":"Mamoona","family":"Humayun","sequence":"first","affiliation":[{"name":"Department of Information Systems, College of Computer and Information Sciences Jouf University  Al\u2010Jouf Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mahmood","family":"Niazi","sequence":"additional","affiliation":[{"name":"Department of Information and Computer Science King Fahd University of Petroleum and Minerals  Saudi Arabia"},{"name":"Interdisciplinary Research Centre for Intelligent Secure Systems King Fahd University of Petroleum and Minerals  Dhahran Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Noor Zaman","family":"Jhanjhi","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (SCE) Taylor's University  Selangor Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5786-5118","authenticated-orcid":false,"given":"Sajjad","family":"Mahmood","sequence":"additional","affiliation":[{"name":"Department of Information and Computer Science King Fahd University of Petroleum and Minerals  Saudi Arabia"},{"name":"Interdisciplinary Research Centre for Intelligent Secure Systems King Fahd University of Petroleum and Minerals  Dhahran Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7950-0099","authenticated-orcid":false,"given":"Mohammad","family":"Alshayeb","sequence":"additional","affiliation":[{"name":"Department of Information and Computer Science King Fahd University of Petroleum and Minerals  Saudi Arabia"},{"name":"Interdisciplinary Research Centre for Intelligent Secure Systems King Fahd University of Petroleum and Minerals  Dhahran Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2022,12,9]]},"reference":[{"volume-title":"Software Engineering Research and Practice","year":"2004","author":"Fernandez EB","key":"e_1_2_11_2_1"},{"volume-title":"Software engineering for secure software\u2010state of the art: A survey","year":"2005","author":"Jayaram K","key":"e_1_2_11_3_1"},{"key":"e_1_2_11_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-95189-8_13"},{"key":"e_1_2_11_5_1","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/1566\/1\/012020"},{"key":"e_1_2_11_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICECA.2018.8474668"},{"first-page":"2019","volume-title":"Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems","author":"Assal H","key":"e_1_2_11_7_1"},{"key":"e_1_2_11_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3052311"},{"key":"e_1_2_11_9_1","doi-asserted-by":"crossref","unstructured":"KhanRA KhanSU IlyasM IdrisMY.The state of the art on secure software engineering: a systematic mapping study. EASE '20: Proceedings of the Evaluation and Assessment in Software EngineeringApril2020;487\u2010492.","DOI":"10.1145\/3383219.3383290"},{"key":"e_1_2_11_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/NCG.2018.8593135"},{"volume-title":"Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF) (Draft)","year":"2019","author":"Dodson D","key":"e_1_2_11_11_1"},{"issue":"5","key":"e_1_2_11_12_1","first-page":"909","article-title":"CIA\u2010Level Driven Secure SDLC Framework for Integrating Security into SDLC Process","volume":"30","author":"Kang S","year":"2020","journal-title":"J Korea Ins Informat Security Cryptol"},{"key":"e_1_2_11_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3040220"},{"key":"e_1_2_11_14_1","unstructured":"EianIC YongLK LiMYX HasmaddiNABN ZahraF\u2010t.Integration of Security Modules in Software Development Lifecycle Phases. arXiv preprint arXiv:2012.05540.2020."},{"key":"e_1_2_11_15_1","doi-asserted-by":"publisher","DOI":"10.32604\/csse.2021.015206"},{"key":"e_1_2_11_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICVES.2018.8519496"},{"issue":"5","key":"e_1_2_11_17_1","first-page":"29","article-title":"Secure coding: building security into the software development life cycle","volume":"13","author":"Jones RL","year":"2004","journal-title":"Inf Secur J A Glob Perspect"},{"key":"e_1_2_11_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13369-019-04319-2"},{"key":"e_1_2_11_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2011.259"},{"key":"e_1_2_11_20_1","doi-asserted-by":"crossref","unstructured":"MengN NagyS YaoD ZhuangW Arango\u2010ArgotyG. Secure coding practices in java: Challenges and vulnerabilities. ICSE '18: Proceedings of the 40th International Conference on Software Engineering May ACM;\u00a02018:372\u2010383.","DOI":"10.1145\/3180155.3180201"},{"issue":"10","key":"e_1_2_11_21_1","first-page":"2982","article-title":"Cyber Security Attacks and Challenges in Saudi Arabia during COVID\u201019","volume":"12","author":"Almrezeq N","year":"2021","journal-title":"Turkish J Comput Math Educat"},{"key":"e_1_2_11_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2015.11.139"},{"key":"e_1_2_11_23_1","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1700"},{"key":"e_1_2_11_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/BIGCOMP.2016.7425809"},{"volume-title":"Fourteenth Symposium on Usable Privacy and Security (SOUPS)","year":"2018","author":"Assal H","key":"e_1_2_11_25_1"},{"key":"e_1_2_11_26_1","doi-asserted-by":"crossref","unstructured":"DavisD ZhuF. Understanding and improving secure coding behavior with eye tracking methodologies. ACM SE '20: Proceedings of the 2020 ACM Southeast Conference April2020;107\u2010114: ACM.","DOI":"10.1145\/3374135.3385293"},{"key":"e_1_2_11_27_1","doi-asserted-by":"publisher","DOI":"10.1049\/iet-sen.2019.0180"},{"key":"e_1_2_11_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2016.03.069"},{"key":"e_1_2_11_29_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2872"},{"key":"e_1_2_11_30_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2905"},{"key":"e_1_2_11_31_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2109"},{"volume-title":"Fixing Software Vulnerabilities and Configuration Errors","year":"2018","author":"Huang Z","key":"e_1_2_11_32_1"},{"key":"e_1_2_11_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev.2017.17"},{"volume-title":"24 deadly sins of software security: Programming flaws and how to fix them","year":"2010","author":"Howard M","key":"e_1_2_11_34_1"},{"key":"e_1_2_11_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2009.56"},{"volume-title":"21st National Information Systems Security Conference","year":"1998","author":"Du W","key":"e_1_2_11_36_1"},{"volume-title":"2011 IEEE symposium on visual languages and human\u2010centric computing (VL\/HCC)","year":"2011","author":"Xie J","key":"e_1_2_11_37_1"},{"key":"e_1_2_11_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.159"},{"key":"e_1_2_11_39_1","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/1414\/1\/012017"},{"volume-title":"International Conference on Risks and Security of Internet and Systems","year":"2020","author":"Fredj OB","key":"e_1_2_11_40_1"},{"volume-title":"Vulnerability Assessment Penetration Testing for Web Application","year":"2019","author":"Shahidullah M","key":"e_1_2_11_41_1"},{"key":"e_1_2_11_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-4303-9_6"},{"key":"e_1_2_11_43_1","first-page":"10","article-title":"Investigating websites and web application vulnerabilities: Webmaster's perspective","author":"Appiah V","year":"2017","journal-title":"Int J Appl Informat Syst"},{"key":"e_1_2_11_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341325.3342032"},{"volume-title":"International Conference Europe Middle East & North Africa Information Systems and Technologies to Support Learning","year":"2018","author":"Ayachi Y","key":"e_1_2_11_45_1"},{"key":"e_1_2_11_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2855321.2855368"},{"issue":"18","key":"e_1_2_11_47_1","first-page":"39","article-title":"Identification and illustration of insecure direct object references and their countermeasures","volume":"114","author":"KumarShrestha A","year":"2015","journal-title":"Int J Comput Appl"},{"key":"e_1_2_11_48_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2019.106960"},{"key":"e_1_2_11_49_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2014.07.010"},{"issue":"2","key":"e_1_2_11_50_1","first-page":"6.1","article-title":"Broken authentication and session management vulnerability: a case study of web application","volume":"19","author":"Hassan MM","year":"2018","journal-title":"Int J Simulat Syst Sci Technol"},{"issue":"6","key":"e_1_2_11_51_1","first-page":"26","article-title":"Protection web applications using real\u2010time technique to detect structured query language injection attacks","volume":"149","author":"Ali NS","year":"2016","journal-title":"Int J Comput Appl"},{"issue":"1","key":"e_1_2_11_52_1","first-page":"38","article-title":"Moving beyond coding: why secure coding should be implemented","volume":"9","author":"Grover M","year":"2016","journal-title":"J Informat Syst Appl Res"},{"key":"e_1_2_11_53_1","first-page":"3","article-title":"Benchmarking approach to compare web applications static analysis tools detecting OWASP top ten security vulnerabilities","volume":"64","author":"Higuera JRB","year":"2020","journal-title":"Comput Mater Continua"},{"key":"e_1_2_11_54_1","first-page":"1","article-title":"Vulnerabilities mapping based on OWASP\u2010SANS: a survey for static application security testing (SAST)","author":"Li J","year":"2020","journal-title":"Ann Emerg Technol Comput"},{"issue":"3","key":"e_1_2_11_55_1","first-page":"885","article-title":"Analysis of web application code vulnerabilities using secure coding standards","volume":"42","author":"Sahu DR","year":"2020","journal-title":"Arabian J Sci Eng"},{"volume-title":"The CERT Oracle Secure Coding Standard for Java","year":"2011","author":"Long F","key":"e_1_2_11_56_1"},{"key":"e_1_2_11_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev.2016.022"},{"key":"e_1_2_11_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC48747.2019.00019"},{"volume-title":"SEI CERT","year":"2016","author":"Standard CC","key":"e_1_2_11_59_1"},{"key":"e_1_2_11_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/CESSER-IP.2019.00015"},{"key":"e_1_2_11_61_1","unstructured":"https:\/\/wiki.sei.cmu.edu\/confluence\/display\/seccode\/Top+10+Secure+Coding+Practices."},{"key":"e_1_2_11_62_1","unstructured":"https:\/\/www.securecoding.com\/blog\/owasp\u2010secure\u2010coding\u2010checklist\/."},{"key":"e_1_2_11_63_1","unstructured":"https:\/\/www.whitehatsec.com\/glossary\/content\/secure\u2010coding\u2010standards."},{"key":"e_1_2_11_64_1","doi-asserted-by":"publisher","DOI":"10.1002\/smr.2323"},{"volume-title":"Software outsourcing vendors' readiness model (SOVRM)","year":"2011","author":"Khan SU","key":"e_1_2_11_65_1"},{"volume-title":"CMMI for development: guidelines for process integration and product improvement","year":"2011","author":"Chrissis MB","key":"e_1_2_11_66_1"},{"volume-title":"RiSE reference model for software reuse adoption in Brazilian companies","year":"2010","author":"Garcia VC","key":"e_1_2_11_67_1"},{"key":"e_1_2_11_68_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2003.10.017"},{"key":"e_1_2_11_69_1","doi-asserted-by":"publisher","DOI":"10.1177\/1609406919862424"},{"key":"e_1_2_11_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/52.300079"}],"container-title":["Software: Practice and Experience"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/spe.3175","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/full-xml\/10.1002\/spe.3175","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/spe.3175","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,18]],"date-time":"2023-08-18T13:09:09Z","timestamp":1692364149000},"score":1,"resource":{"primary":{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/10.1002\/spe.3175"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,9]]},"references-count":69,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,4]]}},"alternative-id":["10.1002\/spe.3175"],"URL":"https:\/\/doi.org\/10.1002\/spe.3175","archive":["Portico"],"relation":{},"ISSN":["0038-0644","1097-024X"],"issn-type":[{"type":"print","value":"0038-0644"},{"type":"electronic","value":"1097-024X"}],"subject":[],"published":{"date-parts":[[2022,12,9]]},"assertion":[{"value":"2021-11-03","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-11-18","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-12-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}