<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Technical Reports</title><link>http://www.sei.cmu.edu//library/reportspapers.cfm</link><description>Library - Reports and Papers</description><lastBuildDate>Thu, 24 May 2012 22:51:37 +0000</lastBuildDate><generator>CommonSpot Content Server</generator><copyright>Software Engineering Institute</copyright><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SoftwareEngineeringInstituteTechnicalPublications" /><feedburner:info uri="softwareengineeringinstitutetechnicalpublications" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item><title>A Pattern for Increased Monitoring for Intellectual Property Theft by Departing Insiders</title><description>This report presents an example of an enterprise architectural pattern, Increased Monitoring for Intellectual Property (IP) Theft by Departing Insiders, to help organizations plan, prepare, and implement a means to mitigate the risk of insider theft of IP.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr008.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr008.cfm</link><pubDate>Thu, 03 May 2012 14:35:45 +0000</pubDate></item><item><title>Source Code Analysis Laboratory (SCALe)</title><description>This report details the CERT Program's Source Code Analysis Laboratory (SCALe), a proof-of-concept demonstration that software systems can be conformance tested against secure coding standards, and provides an analysis of selected software systems.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn013.cfm</link><pubDate>Tue, 01 May 2012 20:19:48 +0000</pubDate></item><item><title>Insider Threat Security Reference Architecture</title><description>This technical report describes the Insider Threat Security Reference Architecture (ITSRA), an enterprise-wide solution to the threat to organizations from its own insiders. The ITSRA draws from existing best practices and standards as well as from analysis of real insider threat cases to provide actionable guidance for organizations to improve their posture against the insider threat.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tr007.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tr007.cfm</link><pubDate>Tue, 01 May 2012 14:21:10 +0000</pubDate></item><item><title>CERT&amp;reg; Resilience Management Model (CERT&amp;reg;-RMM) V1.1: NIST Special Publication Crosswalk Version 1</title><description>This technical note maps CERT&amp;reg; Resilience Management Model (CERT&amp;reg;-RMM) process areas to certain National Institute of Standards and Technology (NIST) special publications in the 800 series.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn028.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn028.cfm</link><pubDate>Tue, 27 Mar 2012 12:25:58 +0000</pubDate></item><item><title>What&amp;rsquo;s New in V2 of the Architecture Analysis &amp; Design Language Standard?</title><description>This report provides an overview of changes and improvements to the Architecture Analysis &amp; Design Language (AADL) standard for describing both the software architecture and the execution platform architectures of performance-critical, embedded, real-time systems. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11sr011.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11sr011.cfm</link><pubDate>Thu, 22 Mar 2012 19:42:02 +0000</pubDate></item><item><title>Principles of Trust for Embedded Systems</title><description>This paper gives substance and explicit meaning to the terms trust and trustworthy as they relate to automated systems and to embedded systems in particular. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn007.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn007.cfm</link><pubDate>Mon, 05 Mar 2012 18:55:22 +0000</pubDate></item><item><title>Mission Risk Diagnostic (MRD) Method Description</title><description>The SEI has developed the Mission Risk Diagnostic (MRD) to assess risk in interactively complex, socio-technical systems across the life cycle and supply chain. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn005.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn005.cfm</link><pubDate>Mon, 27 Feb 2012 13:12:38 +0000</pubDate></item><item><title>Risk-Based Measurement and Analysis: Application to Software Security</title><description>This report presents the foundational concepts of a risk-based approach for software security measurement and analysis and provides an overview of the IMAF and the MRD.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn004.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn004.cfm</link><pubDate>Mon, 13 Feb 2012 22:01:57 +0000</pubDate></item><item><title>Spotlight On: Malicious Insiders and Organized Crime Activity</title><description>This report defines malicious insiders and organized crime and provides a snapshot of who malicious insiders are, what and how they strike, and why.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/12tn001.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/12tn001.cfm</link><pubDate>Fri, 20 Jan 2012 19:38:08 +0000</pubDate></item><item><title>Interoperability in the e-Government Context</title><description>This report describes a proposed model through which to understand interoperability in the e-government context.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn014.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn014.cfm</link><pubDate>Thu, 19 Jan 2012 14:16:57 +0000</pubDate></item><item><title>Best Practices for Artifact Versioning in Service-Oriented Systems</title><description>This report describes some of the challenges of software versioning in an SOA environment and provides guidance on how to meet these challenges by following industry guidelines and recommended practices. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn009.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn009.cfm</link><pubDate>Wed, 18 Jan 2012 19:38:10 +0000</pubDate></item><item><title>An Investigation of Techniques for Detecting Data Anomalies in Earned Value Management Data </title><description>This research demonstrated the effectiveness of various statistical techniques for discovering quantitative data anomalies. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr027.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr027.cfm</link><pubDate>Wed, 08 Feb 2012 21:14:48 +0000</pubDate></item><item><title>Quantifying Uncertainty in Early Lifecycle Cost Estimation (QUELCE)</title><description>The method of quantifying uncertainty described in this report synthesizes scenario building, Bayesian Belief Network (BBN) modeling and Monte Carlo simulation into an estimation method that quantifies uncertainties, allows subjective inputs, visually depicts influential relationships among program change drivers and outputs, and assists with the explicit description and documentation underlying an estimate.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr026.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr026.cfm</link><pubDate>Wed, 08 Feb 2012 20:36:11 +0000</pubDate></item><item><title>A Closer Look at 804: A Summary of Considerations for DoD Program Managers</title><description>The information in this report is intended to help program managers reason about actions they may need to take to adapt and comply with the Section 804 NDAA for 2010 and associated guidance.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11sr015.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11sr015.cfm</link><pubDate>Thu, 16 Feb 2012 18:37:15 +0000</pubDate></item><item><title>Using Defined Processes as a Context for Resilience Measures</title><description>This technical note, which builds on two previous reports, describes how implementation-level processes can provide the necessary context for identifying and defining measures of operational resilience.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn029.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn029.cfm</link><pubDate>Wed, 21 Dec 2011 19:19:30 +0000</pubDate></item><item><title>Standards-Based Automated Remediation: A Remediation Manager Reference Implementation, 2011 Update</title><description>This report describes the Software Engineering Institute&amp;rsquo;s (SEI&amp;rsquo;s) 2011 work for the National Security Agency (NSA) to develop standards for automated remediation of vulnerabilities and compliance issues on Department of Defense (DoD) networked systems. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11sr016.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11sr016.cfm</link><pubDate>Fri, 16 Dec 2011 20:23:25 +0000</pubDate></item><item><title>Agile Methods: Selected DoD Management and Acquisition Concerns</title><description>This technical note addresses some of the key issues that either must be understood to ease the adoption of Agile or are seen as potential barriers to adoption of Agile in the DoD acquisition context. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn002.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn002.cfm</link><pubDate>Mon, 31 Oct 2011 18:49:00 +0000</pubDate></item><item><title>CERT&amp;reg; Resilience Management Model Capability Appraisal Method (CAM) Version 1.1</title><description>This report demonstrates that the SCAMPI Version 1.2 method can be adapted and applied to CERT-RMM V1.1 as the reference model for a process appraisal. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr020.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr020.cfm</link><pubDate>Tue, 21 Feb 2012 19:22:46 +0000</pubDate></item><item><title>CERT&amp;reg; Resilience Management Model (RMM) v1.1: Code of Practice Crosswalk Commercial Version 1.1</title><description>CERT&amp;reg; Resilience Management Model (CERT-RMM) provides a reference model that allows organizations to make sense of their practice deployment in a process context. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn012.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn012.cfm</link><pubDate>Tue, 21 Feb 2012 17:29:06 +0000</pubDate></item><item><title>Insider Threat Control: Using Centralized Logging to Detect Data Exfiltration Near Insider Termination</title><description>This technical note presents an insider threat pattern on how organizations can combat insider theft of intellectual property. The technical note describes how to use the centralized log storage and indexing engine Splunk to detect malicious insider behavior on a network.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn024.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn024.cfm</link><pubDate>Tue, 11 Oct 2011 17:18:12 +0000</pubDate></item><item><title>An Acquisition Perspective on Product Evaluation</title><description>This technical note focuses on software acquisition and development practices related to the evaluation of products before, during, and after implementation. From engagements with numerous DoD acquisition programs, it has been observed that a number of recurring issues reduce the effectiveness of how software-reliant products are evaluated. An acquisition effort consists of identifying the customer&amp;rsquo;s needs, selecting or developing a product that is responsive to those needs, and then evaluating the product to determine if it properly addresses the identified needs. This technical note describes the Product Evaluation (verification, validation, and certification) process including test, reviews, and formal methods. It also makes the argument that Product Evaluation should not be deferred until after a product has been built, but should begin as soon as the customer&amp;rsquo;s needs have been identified and should continue throughout the acquisition effort</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn007.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn007.cfm</link><pubDate>Thu, 06 Oct 2011 12:37:36 +0000</pubDate></item><item><title>2010 CERT Research Report</title><description>The CERT Research Report highlights our accomplishments and activities in successfully executing our research strategy.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/2010-cert-research-report.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/2010-cert-research-report.cfm</link><pubDate>Mon, 03 Oct 2011 12:16:11 +0000</pubDate></item><item><title>Smart Grid Maturity Model, Version 1.2: Model Definition</title><description>The Smart Grid Maturity Model (SGMM) is a business tool stewarded by the Software Engineering Institute at Carnegie Mellon University. It was originally developed by electric power utilities for use by electric power utilities. The model provides a framework for understanding the current extent of smart grid deployment and capability within an electric utility, a context for establishing strategic objectives and implementation plans in support of grid modernization, and a means to evaluate progress over time toward those objectives. 
The SGMM is composed of eight domains and six maturity levels as detailed in this document, which contains the full definition and description of the model. Introductory material to aid in understanding the purpose and use of the SGMM is also provided. 
The primary audiences for the SGMM, and for this document, are electric power utilities that are seeking guidance related to the modernization of their operations and practices for delivering electricity. The audience also includes any related stakeholders for such utilities. Currently, the model is better suited for utilities with transmission and distribution operations than for pure generation utilities.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr025.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr025.cfm</link><pubDate>Fri, 07 Oct 2011 11:59:03 +0000</pubDate></item><item><title>Understanding and Leveraging a Supplier&amp;rsquo;s CMMI Efforts: A Guidebook for Acquirers (Revised for V1.3)</title><description>This guidebook helps acquisition organizations  formulate questions for their suppliers related to CMMI. It also helps organizations interpret responses to identify and evaluate risks for a given supplier.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr023.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr023.cfm</link><pubDate>Mon, 17 Oct 2011 11:48:56 +0000</pubDate></item><item><title>Software Assurance Curriculum Project Volume IV: Community College Education</title><description> The fourth volume in the Software Assurance Curriculum Project led by a team at the Software Engineering Institute, this report focuses on community college courses for software assurance.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr017.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr017.cfm</link><pubDate>Tue, 27 Sep 2011 16:34:04 +0000</pubDate></item><item><title>Proceedings of the Fourth International Workshop on a Research Agenda for Maintenance and Evolution of Service-Oriented Systems (MESOA 2010)</title><description>This report summarizes the proceedings from the 2010 MESOA workshop and includes the accepted papers that were the basis for the presentations given during the workshop.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11sr008.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11sr008.cfm</link><pubDate>Mon, 19 Sep 2011 13:58:36 +0000</pubDate></item><item><title>Architecting Service-Oriented Systems</title><description>This report presents guidelines for architecting service-oriented systems and the effect of architectural principles on system quality attributes.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn008.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn008.cfm</link><pubDate>Fri, 05 Aug 2011 13:23:45 +0000</pubDate></item><item><title>Measures for Managing Operational Resilience</title><description>In this report, Resilient Enterprise Management (REM) team members suggest a set of top ten strategic measures for managing operational resilience. These measures derive from high-level objectives of the ORM system defined in the CERT&amp;reg; Resilience Management Model, Version 1.1 (CERT&amp;reg;-RMM). </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr019.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr019.cfm</link><pubDate>Tue, 26 Jul 2011 17:19:37 +0000</pubDate></item><item><title>Standards-Based Automated Remediation: A Remediation Manager Reference Implementation</title><description>This report describes the Software Engineering Institute's 2010 work to develop standards for vulnerability and compliance remediation on Department of Defense networked systems.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11sr007.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11sr007.cfm</link><pubDate>Wed, 20 Jul 2011 14:46:32 +0000</pubDate></item><item><title>A Decision Framework for Selecting Licensing Rights for Noncommercial Computer Software in the DoD Environment</title><description>This report describes standard noncommercial software licensing alternatives as defined by U.S. government and Department of Defense (DoD) regulations. It also suggests an approach for objectively identifying agency needs for license rights and the appropriate license type for systems with noncommercial computer software or as standalone software in the DoD environment.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr014.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr014.cfm</link><pubDate>Wed, 20 Jul 2011 14:26:27 +0000</pubDate></item><item><title>A Preliminary Model of Insider Theft of Intellectual Property</title><description>This report presents research about insider theft of intellectual property.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tn013.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tn013.cfm</link><pubDate>Thu, 02 Jun 2011 14:44:21 +0000</pubDate></item><item><title>Trusted Computing in Embedded Systems Workshop</title><description>This report describes the November 2010 Trusted Computing in Embedded Systems Workshop held at Carnegie Mellon University. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11sr002.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11sr002.cfm</link><pubDate>Fri, 29 Apr 2011 11:58:00 +0000</pubDate></item><item><title>Best Practices for National Cyber Security: Building a National Computer Security Incident Management Capability, Version 2.0</title><description>This document, first in the Best Practices for National Cyber Security series, provides information that interested organizations and governments can use to develop a national incident management capability.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr015.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr015.cfm</link><pubDate>Thu, 21 Apr 2011 11:55:00 +0000</pubDate></item><item><title>Appraisal Requirements for CMMI Version 1.3 (ARC, V1.3)</title><description>The Appraisal Requirements for CMMI, Version 1.3 (ARC, V1.3), defines the requirements for appraisal methods intended for use with Capability Maturity Model Integration (CMMI) and with the People CMM. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr006.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr006.cfm</link><pubDate>Tue, 12 Apr 2011 11:33:59 +0000</pubDate></item><item><title>Issues and Opportunities for Improving the Quality and Use of Data in the Department of Defense</title><description>The Office of the Secretary of Defense for Acquisition, Technology, and Logistics (OSD [AT&amp;L]), Director, Defense Research &amp; Engineering (DDR&amp;E) sponsored a workshop to bring together leading researchers and practitioners to identify opportunities for research focused on data quality, data analysis, and data use. During workshop discussion participants were asked to identify challenging areas that would address technology gaps and to discuss research ideas that would support future DoD policies and practices. The Software Engineering Institute formed three primary recommendations for areas of further research from the information produced at the workshop. These areas were integrating data from disparate sources, employing provenance analytics, and developing models, methods, and tools that support data quality by design. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11sr004.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11sr004.cfm</link><pubDate>Mon, 02 May 2011 18:39:00 +0000</pubDate></item><item><title>Software Assurance Curriculum Project Volume III: Master of Software Assurance Course Syllabi</title><description>This report, the third volume in the Software Assurance Curriculum Project sponsored by the U.S. Department of Homeland Security, provides sample syllabi for the nine core courses in the Master of Software Assurance Reference Curriculum. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr013.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr013.cfm</link><pubDate>Fri, 01 Apr 2011 15:17:00 +0000</pubDate></item><item><title>IEEE Computer Society/Software Engineering Institute Software Process Achievement (SPA) Award 2009</title><description>Infosys Technologies Limited received the IEEE Computer Society/Software Engineering Institute Software Process Achievement (SPA) Award 2009 for establishing a cost-effective, sustained, and culturally integrated quality and productivity improvement program during a period of extraordinary corporate growth. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr008.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr008.cfm</link><pubDate>Tue, 22 Mar 2011 09:15:00 +0000</pubDate></item><item><title>Standard CMMI Appraisal Method for Process Improvement (SCAMPI)  A, Version 1.3: Method Definition Document</title><description>The SCAMPI Method Definition Document describes the requirements, activities, and practices associated with each of the processes that compose the SCAMPI method. It is intended to be one of the elements of the infrastructure within which SCAMPI Lead Appraisers conduct a SCAMPI appraisal.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11hb001.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11hb001.cfm</link><pubDate>Fri, 18 Mar 2011 18:37:00 +0000</pubDate></item><item><title>CMMI for Acquisition (CMMI-ACQ) Primer, Version 1.3</title><description>Acquisition practices for the project level that help you get started with CMMI for Acquisition practices without using the whole model.</description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/11tr010.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/11tr010.cfm</link><pubDate>Fri, 04 Mar 2011 13:19:00 +0000</pubDate></item><item><title>A Framework for Evaluating Common Operating Environments: Piloting, Lessons Learned, and Opportunities </title><description>This report explores the interdependencies among common language, business goals, and soft-ware architecture as the basis for a common framework for conducting evaluations of software technical solutions. </description><guid isPermaLink="true">http://www.sei.cmu.edu/library/abstracts/reports/10sr025.cfm</guid><link>http://www.sei.cmu.edu/library/abstracts/reports/10sr025.cfm</link><pubDate>Tue, 01 Mar 2011 16:57:07 +0000</pubDate></item></channel></rss>

