inklap

METHOD OF INTEGRATION OF CYBERSECURITY REQUIREMENTS INTO THE SOFTWARE DEVELOPMENT LIFECYCLE

Sergiy Gnatyuk, Zarina Poberezhna, Anatolii Skurativskyi · Cybersecurity Education Science Technique · 2026

In modern conditions, it is important not only to develop software to protect information systems and data, but also to integrate security functions (cybersecurity) into the phases of the software development life cycle. In view of this, the work formalized in a general form the well-known models of the software development life cycle and formed a unified SDLC model. Also, a method for integrating cybersecurity requirements into the SDLC was developed, which allows integrating cybersecurity requirements into a specific phase (pipeline) of the software development life cycle in accordance with the DevSecOps model, and also allows for formal optimization of the choice of cybersecurity controls depending on the system context and resource constraints. The results obtained can be used for the systematic integration of cybersecurity requirements (according to regulatory documents ISO/IEC, NIST, PCI DSS, PSD2, GDPR, MITRE ATT&CK) into software development processes in organizations that create or operate critical infrastructure information systems, cloud services, and corporate information and communication systems.

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً