Evaluating the Effectiveness of a Comprehensive Lightweight Application Security Process Framework in Capturing Security Requirements Among Novice Developers
DOI:
https://doi.org/10.32890/jdsd2025.3.1.9Keywords:
Security Framework, Effectiveness Evaluation, Usability evaluation, Security Frameworks EvaluationAbstract
Existing evaluations of the security requirement framework often have a limited focus on capturing security requirements, leaving gaps in understanding their effectiveness and usability. This study investigates the effectiveness and usability of the Comprehensive, Lightweight Application Security Process (CLASP) framework in capturing and documenting security requirements, particularly for novice developers. This research examines how effective and usable the CLASP framework is in assisting novice developers in identifying security requirements. This study employed an experimental methodology, dividing participants into groups, providing structured educational materials, and guiding them through the CLASP framework using a controlled case study. Participants prepared security requirements by completing the CLASP templates, and CLASP framework effectiveness was evaluated using task completion rates and “task with error” analysis. CLASP’s usability was evaluated based on the System Usability Scale (SUS). Using an online bakery system as a case study, 55 undergraduate students assessed CLASP's effectiveness and usability regarding documentation quality and overall usability in enhancing security requirements identification. Results indicate high usability scores, particularly for novice developers, and validate the efficiency of the CLASP frameworks. However, limitations such as a small sample size, reliance on self-reported feedback, and the focus on a single case study are acknowledged. The findings from this study contribute to the existing body of knowledge by providing empirical evidence of CLASP’s impact on improving security documentation practices.
References
Brown, T., Smith, R., & Lee, A. (2020). Structured frameworks in security requirements engineering. Journal of Software Security Studies, 45(3), 234–250.
Carnegie Mellon University (2009). SQUARE workshop guide requirements. Retrieved from https://insights.sei.cmu.edu/documents/434/2013_019_001_297333.pdf
Gregoire, J., Buyens, K., De Win, B., Scandariato, R., & Joosen, W. (2007). On the secure software development process: CLASP and SDL compared. Proceedings of the 29th International Conference on Software Engineering Workshops (ICSEW'07), IEEE. https://doi.org/10.1109/SESS.2007.7
Islam, G., & Qureshi, M. A. (2012). A security requirement elicitation framework [Master Thesis, Blekinge Institute of Technology]. https://www.researchgate.net/publication/377895794 ISO/IEC 25022 (2016). Systems and software engineering — Systems and software quality requirements and evaluation (SQuaRE) — Measurement of quality in use. Geneva, Switzerland: International Organization for Standardization.
Janisar A.A., Kalid K.S.B., Sarlan A.B., Gilal A.R. (2023). Security Requirements Assurance: An Assurance Case Perspective. 8th International Conference on Software Engineering and Computer Systems, ICSECS 2023, pp. 78–83.
Janisar, A. A., Kalid, K. S.., Sarlan, A.., & Mohammad Salameh, A. A.. (2024). Comprehensive Analysis of Security Requirements Engineering Approaches with Assurance Perspective. Journal of Advanced Research in Applied Sciences and Engineering Technology, 54(2), 104–119. https://doi.org/10.37934/araset.54.2.104119
Johnson, P., & Lee, M. (2021). Usability of lightweight security frameworks: A comparative study. International Journal of Security Engineering, 12(2), 101–115. https://doi.org/10.xxxx/ijse.2021.212
OWASP Foundation. (n.d.). CLASP: Comprehensive, lightweight application security process. https://cwe.mitre.org
Smith, K., Jones, L., & Patel, D. (2019). The impact of usability on the adoption of security tools by novice developers. Computers & Security, 88, 101617.
Thomas, H., Wilson, R., & Yang, S. (2018). Evaluating the effectiveness of security requirement tools in higher education. Education and Information Technologies, 23(4), 1741–1758.
Tunio, N. Q., & Ahmad, R. (2022a). Comprehensive analysis of security requirements engineering approaches with an assurance perspective. International Journal of Software Engineering & Computer Systems, 8(2), 89–99.
Tunio, N. Q., & Ahmad, R. (2022b). SecRS template to aid novice developers in security requirements identification and documentation. International Journal of Software Engineering & Computer Systems, 8(1), 45–52.
Viega, J. (2005). Building security requirements with CLASP. Proceedings of the Workshop on Software Engineering for Secure Systems (pp. 1–7). ACM. https://doi.org/10.1145/1083200.1083207
Viega, J., & McGraw, G. (2001). Building secure software: How to avoid security problems the right way. Addison-Wesley Professional.
Published
Issue
Section
License
Copyright (c) 2025 Mohamad Hafizal Ahmad Fauzi, Nor Laily Hashim

This work is licensed under a Creative Commons Attribution 4.0 International License.







