Proceedings of the 14th ACM / IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM) 2020
DOI: 10.1145/3382494.3410679
|View full text |Cite
|
Sign up to set email alerts
|

DevOps in an ISO 13485 Regulated Environment

Abstract: Background: Medical device development projects must follow proper directives and regulations to be able to market and sell the end-product in their respective territories. The regulations describe requirements that seem to be opposite to efficient software development and short time-to-market. As agile approaches, like DevOps, are becoming more and more popular in software industry, a discrepancy between these modern methods and traditional regulated development has been reported. Although examples of success… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
4
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
7
2

Relationship

1
8

Authors

Journals

citations
Cited by 13 publications
(5 citation statements)
references
References 14 publications
0
4
0
Order By: Relevance
“…The answers we gathered for this question surprised us. Indeed, security standards are a staple element of industries and organisations that want to impose and guarantee a certain level of security on their members and collaborators (often also for certification purposes – Stewart, Chapple & Gibson, 2012 , Lie, Sánchez-Gordón & Colomo-Palacios, 2020 ). Despite their widespread use in practice, only 7 publications mention security standards.…”
Section: Review Resultsmentioning
confidence: 99%
“…The answers we gathered for this question surprised us. Indeed, security standards are a staple element of industries and organisations that want to impose and guarantee a certain level of security on their members and collaborators (often also for certification purposes – Stewart, Chapple & Gibson, 2012 , Lie, Sánchez-Gordón & Colomo-Palacios, 2020 ). Despite their widespread use in practice, only 7 publications mention security standards.…”
Section: Review Resultsmentioning
confidence: 99%
“…It can also be understood as a conglomerate or amalgam of these, which is characterized by breaking down the walls that obstruct and separate the development of operations, in order to direct them to common goals based on collaboration and continuous improvements [14]. DevOps can be understood as a culture and philosophy for a successful organization [15,16]. Such a culture allows the reduction in delivery time in each development flow and, in addition, ensures the quality of the development, demonstrating the benefits in the data record in a detailed way.…”
Section: Methods and Analysismentioning
confidence: 99%
“…Compliance is one of the identified aspects besides the DevSecOps definition, security best practices, process automation, tools for DevSecOps, software configuration, team collaboration, availability of activity data, and information secrecy. Lie et al [55] carried out a Multivocal Literature Review (MLR) to identify the regulatory compliance of DevOps in a regulated medical device context. They concluded that DevOps for such a context is a highly appealing approach and noted specific contradictions between DevOps and IEC 62304 medical device software.…”
Section: Related Workmentioning
confidence: 99%