Cristin-resultat-ID: 1451123
Sist endret: 7. juni 2018, 14:14
Resultat
Vitenskapelig artikkel
2010

Agile Software Development: The Straight and Narrow Path to Secure Software?

Bidragsytere:
  • Torstein Nicolaysen
  • Richard Sassoon
  • Maria Bartnes og
  • Martin Gilje Jaatun

Tidsskrift

International Journal of Secure Software Engineering (IJSSE)
ISSN 1947-3036
e-ISSN 1947-3044
NVI-nivå 1

Om resultatet

Vitenskapelig artikkel
Publiseringsår: 2010
Volum: 1
Hefte: 3
Sider: 71 - 85
Open Access

Beskrivelse Beskrivelse

Tittel

Agile Software Development: The Straight and Narrow Path to Secure Software?

Sammendrag

In this article, we contrast the results of a series of interviews with agile software development organizations with a case study of a distributed agile development effort, focusing on how information security is taken care of in an agile context. The interviews indicate that small and medium-sized agile software development organizations do not use any particular methodology to achieve security goals, even when their software is web-facing and potential targets of attack, and our case study confirms that even in cases where security is an articulated requirement, and where security design is fed as input to the implementation team, there is no guarantee that the end result meets the security objectives. We contend that security must be built as an intrinsic software property and emphasize the need for security awareness throughout the whole software development lifecycle. We suggest two extensions to agile methodologies that may contribute to ensuring focus on security during the complete lifecycle

Bidragsytere

Torstein Nicolaysen

  • Tilknyttet:
    Forfatter
    ved Norges teknisk-naturvitenskapelige universitet

Richard Sassoon

  • Tilknyttet:
    Forfatter
    ved Norges teknisk-naturvitenskapelige universitet

Maria Bartnes

  • Tilknyttet:
    Forfatter
    ved Software Engineering, Safety and Security ved SINTEF AS
Aktiv cristin-person

Martin Gilje Jaatun

  • Tilknyttet:
    Forfatter
    ved Software Engineering, Safety and Security ved SINTEF AS
1 - 4 av 4