<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Identifying usability activities integrated into the planning phase of the Secure Software Development Cycle through a systematic review</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Juan R. Lipán Mella</string-name>
          <email>juan.lipan@mayor.cl</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yenny A. Méndez A.</string-name>
          <email>yenny.mendez@umayor.cl</email>
        </contrib>
      </contrib-group>
      <abstract>
        <p>Security and usability represent essential aspects to consider in the process of the development of technological solutions. However, there is evidence of a great separation of these aspects that requires special attention. Before generating research on usable security issues, this article presents a systematic review whose purpose was to identify related works that propose usability activities in the planning phase of the life cycle of secure software development.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Requirements Engineering corresponds to the branch of Software Engineering that
deals with documenting information systems'needs and establishing their
functionalities and limitations [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Therefore, it is essential to establish usable and
safe requirements, allowing us to generate systems that are more understandable by
the user, and in this way, avoid that people commit on errors in their use or that they
may be vulnerable. Since usable security is a poorly understood and addressed topic, a
review of the existing literature was required. The following work presents a
systematic review to learn about related works on usability activities, in the early
stages of software development, as part of a secure software development
methodology.
      </p>
      <p>The next section presents the related issue. Next, section 2 presents the conceptual
basis on which this review is supported. Section 3 presents information on the process
that was carried out to carry out the systematic review. Section 4 Information on the
results obtained, and finally, in Section V, conclusions of the work carried out are
presented.</p>
      <p>Copyright c 2020 for this paper by its authors. Use permitted under Creative Commons</p>
      <sec id="sec-1-1">
        <title>1.1 The problem</title>
        <p>
          Every day, modern information systems (IS) grow in size and become more
complex, making their monitoring and security considerably more difficult.
Organizations that implement these information systems to manage day-to-day
operations are spending billions of dollars on security technologies such as firewalls,
encryption software, and more to ensure their data security. Most of the time,
organizations and information stakeholders forget to address issues related to the
security chain's weakest link: human or usability concerns [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <p>
          Requirements are a nexus between HCI and information security, however, it is
often confused about the security requirements, how they should be expressed, and
how they should best be obtained and analyzed. Techniques and frameworks are
lacking to address usability, requirements, and security concerns jointly. Existing tool
support for usability engineering is weak, and existing tool support for security
engineering suffers from scalability when integrated with complementary approaches
[
          <xref ref-type="bibr" rid="ref1">1</xref>
          ].
        </p>
        <p>
          Over the years, different security mechanisms have been incorporated to achieve
these goals, such as authentication and authorization. However, the rate of attacks on
computer systems increases, and the situation can be critical, especially for large
systems. Because of this, many researchers pay attention to the field of software
security to produce a high-security system [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ].
        </p>
        <p>
          There are significant financial and reputational losses related to security issues that
could have been addressed during requirements specification. While various
approaches have been proposed for specifying security requirements, there is a
definite lack of support during testing [
          <xref ref-type="bibr" rid="ref4">4</xref>
          ].
        </p>
        <p>
          To investigate and contribute to the integration of usability activities in the
requirements analysis phase in a secure development methodology, it begins with the
search for literature through a systematic review, supported by the methodology
proposed by Kitchenham and Charters [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2 Definitions</title>
      <sec id="sec-2-1">
        <title>2.1 Usability</title>
        <p>
          Definitions that are considered necessary to recognize before presenting the results of
the systematic review are presented below:
The International Standard Organization (ISO) defines usability “extent to which a
system, product or service can be used by specified users to achieve specified goals
with effectiveness, efficiency and satisfaction in a specified context of use [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ].
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2 Defining Usability for Security</title>
        <p>
          “Security software is usable if people who are expected to use it: are reliably made
aware of the security tasks they need to perform; are able to figure out how to
successfully perform those tasks; don’t make dangerous errors; are sufficiently
comfortable with the interface to continue using it” [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ].
        </p>
      </sec>
      <sec id="sec-2-3">
        <title>2.3 Software engineering</title>
        <p>
          Software engineering is an engineering discipline concerned with all aspects of
software production, from the early stages of system specification to the system's
maintenance after it is put into operation [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ].
        </p>
      </sec>
      <sec id="sec-2-4">
        <title>2.4 Requirements</title>
        <p>
          The requirements specify what the system should do (its functions) and its essential
and desirable properties. The main objective of capturing the requirements is to
understand what customers and users expect the system to do. A requirement
expresses the purpose of the system without considering how it will be implemented.
In other words, requirements identify the what of the system, while the design
establishes the how of the system [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3 Systematic review</title>
      <sec id="sec-3-1">
        <title>3.1 Research question</title>
        <p>
          The literature search was supported by the guidelines for conducting systematic
literature reviews in software engineering [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ]. Each of the steps is described below.
The question that started the literature review was: What usability activities have been
proposed to be integrated into the methodology for the development of secure
software in the requirements analysis stage?
3.1
        </p>
        <p>The key words used in the searches for related works were selected; these words
were: usability, methodology, development, and secure software, to obtain the most
significant documentation search, synonyms, and terms similar to the critical terms. In
this regard, Table 1 shows the list of words in the English and Spanish search
languages.</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2 Databases</title>
        <p>The databases selected to carry out the systematic review are presented in Table 2.
Articles, conferences, books, book chapters that are published, among others, which
are considered to be timely sources of information for searching for information.</p>
        <p>Tabla 2. Selected Databases</p>
        <p>Database</p>
        <p>IEEE Xplore
ACM Digital Library</p>
        <p>Web of Science</p>
        <p>Scopus
Springer</p>
        <p>Link
https://ieeexplore.ieee.org/</p>
        <p>https://dl.acm.org/
https://webofknowledge.com
https://www.scopus.com/
https://www.springer.com</p>
      </sec>
      <sec id="sec-3-3">
        <title>3.3 Inclusion and exclusion criteria</title>
        <p>The inclusion and exclusion criteria considered in the systematic review are
presented below:</p>
        <sec id="sec-3-3-1">
          <title>Inclusion criteria</title>
          <p>1. Documents related to the initial phase of the software development process.
2. Documents that are related to usability activities with the initial phase of the
secure software development process.
3. The searches will be in languages: Spanish and English.</p>
          <p>4. Only articles published after 2009 will be considered.</p>
          <p>Exclusion criteria
1. Articles that do not have full access are not considered.
2. Terms and synonyms other than those defined in the systematic review
process are not considered.
3. Documents other than: Articles (Conferences and Journals) and Magazines
(Magazines) are not considered.
4. Searches other than metadata are not considered: Title, Abstract and Author's
Keywords.</p>
        </sec>
      </sec>
      <sec id="sec-3-4">
        <title>3.4 Query search</title>
        <p>Based on the previously established terms and the purpose of the systematic
review, the following search strings were established:</p>
        <p>Tabla 3. Query search in Spanish and English.</p>
        <p>Language
Spanish
English</p>
        <p>Query search
((Usab*) AND (Metodo* OR Proceso) AND (Desarrollo OR Programación)</p>
        <p>AND ("Software Seguro")) AND (AÑO &gt;= 2009)
((Usab*) AND (Method* OR Model OR Framework) AND (Development)
AND (("Software Secur*") OR ("Application Secur*"))) AND (AÑO &gt;= 2009)</p>
      </sec>
      <sec id="sec-3-5">
        <title>3.5 Search and revision</title>
        <p>The search procedure is carried out by accessing the five defined databases (IEE
Xplore, ACM Digital Library, and Web of Science, Scopus, and Springer), defining
an advanced search string with established keywords. Once the results were obtained,
they were organized in a spreadsheet, assigning a number to each article. From the
search, 44 articles were obtained, distributed in the different databases (see Fig. 1).
The selection of papers was supported by two search filters that are detailed below:</p>
        <sec id="sec-3-5-1">
          <title>First filter results</title>
          <p>A first review of the documents is carried out, reviewing the documents' abstracts
and considering the first two inclusion criteria.</p>
          <p>1. Documents related to the initial phase of the software development process.
2. Documents related to usability activities in the initial phase of the software
development process.</p>
          <p>Table 4 presents information on the number of articles included and articles
excluded from the first filter.</p>
          <p>Introductions and conclusions of the 15 articles resulting from the first filter were
reviewed, and the first two inclusion criteria were considered. Table 5 shows the list
of articles included and articles excluded from the second filter.</p>
          <p>The second filter results in 6 articles, which are reviewed in their entirety. From
this review, 3 articles have been selected that answer the research question. The
relationship between the number of articles and the year of publication is presented in
Fig 2.</p>
        </sec>
      </sec>
      <sec id="sec-3-6">
        <title>3.5 Results</title>
        <p>It is important to note that no articles were found in Spanish; all articles were
accessed, the articles were written entirely in English, and no repeated articles were
found.</p>
        <sec id="sec-3-6-1">
          <title>About selected articles</title>
          <p>The most critical points of the 3 articles that are part of the research process, which
will allow us to answer the systematic review question, are described below.</p>
          <p>
            The article "Closing the Feedback Loop Between UX Design, Software
Development, Security Engineering, and Operations" [
            <xref ref-type="bibr" rid="ref10">10</xref>
            ], proposes an adaptation of
the Secure Development Lifecycle (SDL) and the DevSecOps model for agile
development. Usability (UX) designers and researchers are included in the
Technology Development Lifecycle.
          </p>
          <p>
            The paper “Developer-centered security and the symmetry of ignorance” [
            <xref ref-type="bibr" rid="ref11">11</xref>
            ],
presents a proposal for changes in the culture of developments, processes, and
technology to address developer-centric security.
          </p>
          <p>
            The paper “Secure and Usable Requirements Engineering” [
            <xref ref-type="bibr" rid="ref12">12</xref>
            ], proposes the Safe
Usable Requirements Engineering (SURE) technique, which aims to increase the
usability of software requirements in their development stages. It serves as a support
to elicit, analyze and specify security requirements and documents in the early stages
of development, misuse processes, and possible threats to the system. It seeks to
increase the usability of the specified security requirements to be traceable in
development, and usability is increased.
The systematic review made it possible to identify the existing literature related to
"usability activities have been proposed to integrate into the methodology for the
development of secure software in the requirements analysis stage." It is evidenced
that there is not enough information in the selected databases on related research.
Forty-four articles were found in the five databases used, selecting only 3 that directly
contribute to answer the question that gave rise to the systematic review.
The selected articles describe usability and security activities that can be included in
the initial phases of software development, which could contribute to generate
solutions that are easier to use and more secure, avoiding exposing the user to risks or
misuse of the software.
          </p>
          <p>This systematic review is a basis for developing other research on issues related to
usability activities in the requirements gathering stages, as part of a secure
development methodology.</p>
        </sec>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>S.</given-names>
            <surname>Faily</surname>
          </string-name>
          , “
          <article-title>Usable and Secure Software Design: The State-of-the-</article-title>
          <string-name>
            <surname>Art</surname>
          </string-name>
          ,
          <article-title>” in Designing Usable and Secure Software with IRIS and CAIRIS,</article-title>
          <year>2018</year>
          , pp.
          <fpage>9</fpage>
          -
          <lpage>53</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>B.</given-names>
            <surname>Naqvi</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Seffah</surname>
          </string-name>
          , “
          <article-title>A Methodology for Aligning Usability and Security in Systems</article-title>
          and Services,
          <source>” Proc. - 2018 3rd Int. Conf. Inf. Syst. Eng. ICISE</source>
          <year>2018</year>
          , pp.
          <fpage>61</fpage>
          -
          <lpage>66</lpage>
          ,
          <year>2019</year>
          , doi: 10.1109/ICISE.
          <year>2018</year>
          .
          <volume>00019</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>O. M.</given-names>
            <surname>Surakhi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Hudaib</surname>
          </string-name>
          , M. AlShraideh, and M. Khanafseh, “
          <article-title>A Survey on Design Methods for Secure Software Development,”</article-title>
          <string-name>
            <given-names>Int. J.</given-names>
            <surname>Comput</surname>
          </string-name>
          . Technol., vol.
          <volume>16</volume>
          , no.
          <issue>7</issue>
          , pp.
          <fpage>7047</fpage>
          -
          <lpage>7064</lpage>
          ,
          <year>2017</year>
          , doi: 10.24297/ijct.v16i7.
          <fpage>6467</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>J.</given-names>
            <surname>Romero-Mariona</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Ziv</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Richardson</surname>
          </string-name>
          , “ASSURE:
          <article-title>Automated support for secure and Usable Requirements Engineering</article-title>
          ,” ISSTA'
          <fpage>10</fpage>
          -
          <lpage>Proc</lpage>
          .
          <year>2010</year>
          Int. Symp. Softw. Test. Anal., no.
          <source>Mc</source>
          , pp.
          <fpage>279</fpage>
          -
          <lpage>282</lpage>
          ,
          <year>2010</year>
          , doi: 10.1145/1831708.1831744.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. Kitchenham, “
          <article-title>Guidelines for performing systematic literature reviews in software engineering</article-title>
          ,
          <source>” Tech. report, Ver. 2.3 EBSE Tech. Report. EBSE</source>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6. International Organization for Standardization, “ISO 9241-
          <fpage>11</fpage>
          :
          <year>2018</year>
          <article-title>(en) Ergonomics of human-system interaction”</article-title>
          , International Organization for Standardization,”
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>A.</given-names>
            <surname>Whitten</surname>
          </string-name>
          and
          <string-name>
            <given-names>J. D.</given-names>
            <surname>Tygar</surname>
          </string-name>
          , “Why Johnny
          <string-name>
            <surname>Can't Encrypt</surname>
          </string-name>
          ,” USENIX Secur. Symp., pp.
          <fpage>679</fpage>
          -
          <lpage>702</lpage>
          ,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>I. Sommerville</surname>
          </string-name>
          , Ingeniería de Software, Novena edición.
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>M.</given-names>
            <surname>Gómez</surname>
          </string-name>
          ,
          <string-name>
            <surname>Notas Del Curso: Análisis de Requerimientos</surname>
          </string-name>
          .
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <given-names>J.</given-names>
            <surname>Nguyen</surname>
          </string-name>
          and
          <string-name>
            <given-names>M.</given-names>
            <surname>Dupuis</surname>
          </string-name>
          , “
          <article-title>Closing the Feedback Loop Between UX Design, Software Development</article-title>
          , Security Engineering, and Operations,”
          <source>in Proceedings of the 20th Annual SIG Conference on Information Technology Education</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>93</fpage>
          -
          <lpage>98</lpage>
          , doi: 10.1145/3349266.3351420.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <given-names>O.</given-names>
            <surname>Pieczul</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Foley</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M. E.</given-names>
            <surname>Zurko</surname>
          </string-name>
          , “
          <article-title>Developer-Centered Security and the Symmetry of Ignorance,”</article-title>
          <source>in Proceedings of the 2017 New Security Paradigms Workshop</source>
          ,
          <year>2017</year>
          , pp.
          <fpage>46</fpage>
          -
          <lpage>56</lpage>
          , doi: 10.1145/3171533.3171539.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>J.</surname>
          </string-name>
          Romero-Mariona, “Secure and Usable Requirements Engineering,”
          <source>in Proceedings of the 2009 IEEE/ACM International Conference on Automated Software Engineering</source>
          ,
          <year>2009</year>
          , pp.
          <fpage>703</fpage>
          -
          <lpage>706</lpage>
          , doi: 10.1109/ASE.
          <year>2009</year>
          .
          <volume>81</volume>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>