Research With Practical Impact
PhD Research is focused on a pressing challenge in modern software delivery: how to improve software assurance and supply-chain resilience without disrupting the way teams already build and release software. This research project develops a strategic framework that connects everyday engineering evidence to clear assurance obligations, helping organizations strengthen trust, traceability, and release confidence.
As software systems become more interconnected, open-source components, automated pipelines, and distributed development practices create both opportunity and risk. Teams are expected to demonstrate compliance, explain decisions, and maintain auditable records, yet many existing approaches add manual overhead and duplicate work. This project explores how assurance can be generated as a natural outcome of normal engineering activity rather than as a separate, burdensome process.
The Core Research Problem
Many organizations still treat assurance as something assembled late in the lifecycle, often under time pressure and with incomplete evidence. That creates gaps in visibility, slows release decisions, and makes regulatory readiness harder to sustain. PhD Research addresses this by investigating how software-development artifacts, decisions, and workflows can be linked directly to explicit assurance requirements from the start.
The goal is not to ask teams to work differently for compliance, but to make existing engineering work more explainable, auditable, and reusable for assurance.
What the Framework Explores
- Continuous assurance generated alongside normal software engineering activity
- Explainable evidence that supports trust, review, and accountability
- Auditable records that improve traceability across the software supply chain
- Ontology-based models that connect technical evidence to assurance obligations
- Smart-contract automation to reduce repeated compliance effort
- Tamper-evident records that strengthen confidence in release decisions
Why It Matters
This work is relevant to researchers, software engineering leaders, compliance stakeholders, and organizations operating in environments where assurance and resilience matter. By reducing repeated compliance work and improving the visibility of trustworthy evidence, the framework aims to support faster decision-making, stronger governance, and better preparedness for evolving regulatory expectations.
It also contributes to a broader conversation about how software assurance should evolve in response to modern development realities. Instead of relying on fragmented documentation and retrospective checks, the research promotes a more integrated model where assurance is continuous, transparent, and grounded in the real flow of engineering work.
Looking Ahead
Through this site, PhD Research will share insights, publications, and resources related to software assurance and supply-chain resilience. The aim is to make the research accessible to both academic and professional audiences while contributing practical value to ongoing discussions in secure and dependable software engineering.
If you are interested in the research, its methodology, or its potential applications, explore the Publications and Resources sections or get in touch through the Contact page.