The Team Software Process and Security
The security of a software-intensive system is directly related to the quality of its software.
- Over 90% of software security incidents are caused by attackers exploiting known software defects.
- Analysis of 45 e-business applications showed that 70% of security defects were design defects.
- Experienced and capable software engineers inject, on average, one defect every nine lines of code.
- A one million line of code systems typically contains 1,000-5,000 defects when shipped.
TSP fosters good practices based on engineering principles. With TSP, software teams
- build detailed, accurate plans
- manage and track their commitments
- produce nearly defect-free software (<0.1 defects/KSLOC)
TSP for Secure Systems
TSP for Secure Systems is an applied research effort to enhance TSP by incorporating processes for
- secure design
- secure implementation
- secure review and inspection
- secure testing
TSP for Secure Systems is a collaborative effort between the TSP program and the Networked Systems Survivability program at the SEI.
For More Information
For more information, see the presentation, Team Software Process for Secure Systems Development, or contact us at tsp@sei.cmu.edu.

