2011 Sixth International Conference on Availability, Reliability and Security 2011
DOI: 10.1109/ares.2011.82
|View full text |Cite
|
Sign up to set email alerts
|

Practitioners' Perspectives on Security in Agile Development

Abstract: Agile methods are widely employed to develop high-quality software, but theoretical analyses argue that agile methods are inadequate for security-critical projects. However, most agile-developed software today needs to satisfy baseline security requirements, so that we need to focus on how to achieve this this level for typical agile projects. In this paper, we provide insights from the practitioner's perspective on security in agile development and report on exploratory, qualitative findings from interviews. … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

1
42
1

Year Published

2013
2013
2021
2021

Publication Types

Select...
6
3

Relationship

0
9

Authors

Journals

citations
Cited by 65 publications
(44 citation statements)
references
References 26 publications
1
42
1
Order By: Relevance
“…There are a few discussions about implementing security in agile models like XP and Scrum [19]- [21].This is the part where the students that have complete their phases in the FDD to voice out their opinion about the weaknesses that they find in the existing FDD model to adapt with security 1) Through your experience in FDD process development, explain briefly weaknesses in FDD modeling. 2) When the lecturer asked you to add security features/elements inside your system, do you think that it slowed down your system development progress?…”
Section: Recommendationsmentioning
confidence: 99%
“…There are a few discussions about implementing security in agile models like XP and Scrum [19]- [21].This is the part where the students that have complete their phases in the FDD to voice out their opinion about the weaknesses that they find in the existing FDD model to adapt with security 1) Through your experience in FDD process development, explain briefly weaknesses in FDD modeling. 2) When the lecturer asked you to add security features/elements inside your system, do you think that it slowed down your system development progress?…”
Section: Recommendationsmentioning
confidence: 99%
“…They propose the idea of a security backlog that helps to deal with the security issues in the Scrum methodology. Bartsch presents a report on interviews with practitioners on the effects of agile methods for developing secure software [7]. They also study the implications of security awareness and developer expertise on how security practices are employed.…”
Section: Related Workmentioning
confidence: 99%
“…A survey by Forrester a few years ago showed that more than two thirds of the organizations canvassed either already had a mature implementation of agile methods or were midway in implementing such methods [5]. Even though the agile approach is becoming popular, it is reported to have disadvantages related to secure software development [6,7]. In order to build secure software, security-enhanced processes and practices are needed [23].…”
Section: Introductionmentioning
confidence: 99%
“…However, another case study indicates that sometimes onsite customers could not be consistently available and were not actively involved [120]. However, it has been pointed out that the customer is the only person who knows the business domain well and can decide on the resources, scope, and schedule, and clarify vague complex projects [124], [125].…”
Section: B Customer Involvementmentioning
confidence: 99%