Evaluating the Effectiveness of a Comprehensive Lightweight Application Security Process Framework in Capturing Security Requirements Among Novice Developers

Authors

  • Mohamad Hafizal Ahmad Fauzi Universiti Utara Malaysia, Malaysia
  • Nor Laily Hashim Universiti Utara Malaysia, Malaysia

DOI:

https://doi.org/10.32890/jdsd2025.3.1.9

Keywords:

Security Framework, Effectiveness Evaluation, Usability evaluation, Security Frameworks Evaluation

Abstract

Existing evaluations of the security requirement framework often have a limited focus on capturing security requirements, leaving gaps in understanding their effectiveness and usability. This study investigates the effectiveness and usability of the Comprehensive, Lightweight Application Security Process (CLASP) framework in capturing and documenting security requirements, particularly for novice developers. This research examines how effective and usable the CLASP framework is in assisting novice developers in identifying security requirements. This study employed an experimental methodology, dividing participants into groups, providing structured educational materials, and guiding them through the CLASP framework using a controlled case study. Participants prepared security requirements by completing the CLASP templates, and CLASP framework effectiveness was evaluated using task completion rates and “task with error” analysis. CLASP’s usability was evaluated based on the System Usability Scale (SUS). Using an online bakery system as a case study, 55 undergraduate students assessed CLASP's effectiveness and usability regarding documentation quality and overall usability in enhancing security requirements identification. Results indicate high usability scores, particularly for novice developers, and validate the efficiency of the CLASP frameworks. However, limitations such as a small sample size, reliance on self-reported feedback, and the focus on a single case study are acknowledged. The findings from this study contribute to the existing body of knowledge by providing empirical evidence of CLASP’s impact on improving security documentation practices.

References

Brown, T., Smith, R., & Lee, A. (2020). Structured frameworks in security requirements engineering. Journal of Software Security Studies, 45(3), 234–250.

Carnegie Mellon University (2009). SQUARE workshop guide requirements. Retrieved from https://insights.sei.cmu.edu/documents/434/2013_019_001_297333.pdf

Gregoire, J., Buyens, K., De Win, B., Scandariato, R., & Joosen, W. (2007). On the secure software development process: CLASP and SDL compared. Proceedings of the 29th International Conference on Software Engineering Workshops (ICSEW'07), IEEE. https://doi.org/10.1109/SESS.2007.7

Islam, G., & Qureshi, M. A. (2012). A security requirement elicitation framework [Master Thesis, Blekinge Institute of Technology]. https://www.researchgate.net/publication/377895794 ISO/IEC 25022 (2016). Systems and software engineering — Systems and software quality requirements and evaluation (SQuaRE) — Measurement of quality in use. Geneva, Switzerland: International Organization for Standardization.

Janisar A.A., Kalid K.S.B., Sarlan A.B., Gilal A.R. (2023). Security Requirements Assurance: An Assurance Case Perspective. 8th International Conference on Software Engineering and Computer Systems, ICSECS 2023, pp. 78–83.

Janisar, A. A., Kalid, K. S.., Sarlan, A.., & Mohammad Salameh, A. A.. (2024). Comprehensive Analysis of Security Requirements Engineering Approaches with Assurance Perspective. Journal of Advanced Research in Applied Sciences and Engineering Technology, 54(2), 104–119. https://doi.org/10.37934/araset.54.2.104119

Johnson, P., & Lee, M. (2021). Usability of lightweight security frameworks: A comparative study. International Journal of Security Engineering, 12(2), 101–115. https://doi.org/10.xxxx/ijse.2021.212

OWASP Foundation. (n.d.). CLASP: Comprehensive, lightweight application security process. https://cwe.mitre.org

Smith, K., Jones, L., & Patel, D. (2019). The impact of usability on the adoption of security tools by novice developers. Computers & Security, 88, 101617.

Thomas, H., Wilson, R., & Yang, S. (2018). Evaluating the effectiveness of security requirement tools in higher education. Education and Information Technologies, 23(4), 1741–1758.

Tunio, N. Q., & Ahmad, R. (2022a). Comprehensive analysis of security requirements engineering approaches with an assurance perspective. International Journal of Software Engineering & Computer Systems, 8(2), 89–99.

Tunio, N. Q., & Ahmad, R. (2022b). SecRS template to aid novice developers in security requirements identification and documentation. International Journal of Software Engineering & Computer Systems, 8(1), 45–52.

Viega, J. (2005). Building security requirements with CLASP. Proceedings of the Workshop on Software Engineering for Secure Systems (pp. 1–7). ACM. https://doi.org/10.1145/1083200.1083207

Viega, J., & McGraw, G. (2001). Building secure software: How to avoid security problems the right way. Addison-Wesley Professional.

Downloads

Published

28-04-2025

Issue

Section

Articles

How to Cite

Fauzi, M. H. A., & Hashim, N. L. (2025). Evaluating the Effectiveness of a Comprehensive Lightweight Application Security Process Framework in Capturing Security Requirements Among Novice Developers. Journal of Digital System Development, 3(1), 101-116. https://doi.org/10.32890/jdsd2025.3.1.9

Most read articles by the same author(s)