|
This Government Insights report examines a U.S. Air Force initiative to implement application security/software assurance practices following the massive breach of an Air Force information system. The breach prompted the Air Force Electronic Systems Center (ESC) to establish the Application Software Assurance Center of Excellence (ASACoE), which has implemented programs in application security awareness, application monitoring, and training and mentoring software developers to identify and repair existing vulnerabilities and incorporate security into software coding practices. This ProveIT case study analyzes the approach that the Air Force and the ASACoE have taken and the success of that approach in addressing the issue of application security and software assurance. As a ProveIT case study, it also provides government end users with comparable, consistent, and independent IT solutions impact assessments across four primary components critical to successful IT value outcomes: return on investment, risk, innovation, and transformation.
"Government Insights believes that the approach taken in creating the ASACoE and its approach to implementing software security in the Air Force provide other government organizations and managers with a sound model and a road map for emulation and the best practices for a successful outcome," says Mark Kagan, research manager at Government Insights, who wrote the ProveIT case study.
|