Software Assurance vs. Security Compliance: Why is Compliance Not Enough Open PDF Document Details Document Type Technical Report Publication Date Apr 26, 2012 Accession Number AD1014718 Entities People Carol C. Woody Organizations Carnegie Mellon University Tags Communities of Interest Air Platforms DTIC Thesaurus Topics Acquisition Application Software Case Studies Computer Programming Computers Contractors Department Of Homeland Security Engineering Governments Operating Systems Risk Risk Management Software Assurance Software Development Supply Chain Systems Engineering Vulnerability