Proceedings of the 2011 International Conference on Software and Systems Process 2011
DOI: 10.1145/1987875.1987900
|View full text |Cite
|
Sign up to set email alerts
|

Agile development with security engineering activities

Abstract: Agile software development has been used by industry to create a more flexible and lean software development process, i.e making it possible to develop software at a faster rate and with more agility during development. There are however concerns that the higher development pace and lack of documentation are creating less secure software. We have therefore looked at three known Security Engineering processes, Microsoft SDL, Cigatel touchpoints and Common Criteria and identified what specific security activitie… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

1
20
0

Year Published

2013
2013
2022
2022

Publication Types

Select...
4
1
1

Relationship

2
4

Authors

Journals

citations
Cited by 55 publications
(32 citation statements)
references
References 20 publications
(21 reference statements)
1
20
0
Order By: Relevance
“…Ge et al [12] integrate feature-driven development and high-profile security methods, namely risk analysis, to address the development of secure web applications. Baca and Carlsson identify security activities from three SE processes; Microsoft SDL, Cigital touchpoints and Common Criteria [3,9]. Then, they compare those security activities with a specific agile development process, Scrum, which is used in industry.…”
Section: Related Workmentioning
confidence: 99%
See 3 more Smart Citations
“…Ge et al [12] integrate feature-driven development and high-profile security methods, namely risk analysis, to address the development of secure web applications. Baca and Carlsson identify security activities from three SE processes; Microsoft SDL, Cigital touchpoints and Common Criteria [3,9]. Then, they compare those security activities with a specific agile development process, Scrum, which is used in industry.…”
Section: Related Workmentioning
confidence: 99%
“…Security engineering (SE) processes can be defined as the set of activities performed to develop, maintain and deliver a secure software product; security activities may be either sequential or iterative. Due to constraints such as a lack of a complete overview of a product, higher development pace and lack of documentation inherent to agile processes [6,8,9], existing SE processes are difficult to implement in such a setting. Moreover, existing SE processes are designed for a traditional waterfall development approach, i.e.…”
Section: Introductionmentioning
confidence: 99%
See 2 more Smart Citations
“…Baca and Carlsson proposed an agile security process in an industrial setting (Baca & Carlsson, 2011). Security issues were addressed using three well-known security tools; Microsoft SDL, Cigital Touchpoints, and the Common Criteria (Common Criteria, 2017).…”
Section: Introductionmentioning
confidence: 99%