Security measurements within the framework of quality assessment models for free/libre open source software

Autor: Kirsten Haaland, Anna Tannenberg, Arne-Kristian Groven, Ruediger Glott
Rok vydání: 2010
Předmět:
Zdroj: ECSA Companion Volume
DOI: 10.1145/1842752.1842796
Popis: This article, presents a comparison of a first generation software quality assessment model (OpenBRR) and a second generation model (QualOSS) by applying them to the case of Asterisk, a FLOSS implementation of a telephone private branch exchange (PBX, VoIP). The key trend in the evolution of FLOSS quality assessment models is the movement from manual and descriptive to more automated and analytical models, and from the involvement of a few metrics to hundreds of metrics. Concerning the security measurements, they are much more sophisticated in QualOSS than in OpenBRR. Where OpenBRR have only three security metrics, QualOSS has nine security indicator with altogether 30-40 security metrics. This article shows how security are measured in the two assessment models, putting it into the overall context of the two approaches.
Databáze: OpenAIRE