Large-scale agile security practices in software engineering

被引:0
|
作者
Ascencao, Claudia [1 ]
Teixeira, Henrique [1 ]
Goncalves, Joao [1 ]
Almeida, Fernando [2 ]
机构
[1] ISPGAYA, Sch Sci & Technol, Vila Nova De Gaia, Portugal
[2] Univ Porto, INESC TEC Lab, Porto, Portugal
关键词
Security; Agile methodologies; Large-scale agile; Privacy; MANAGEMENT; METHODOLOGY; DESIGN;
D O I
10.1108/ICS-07-2023-0136
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
PurposeSecurity in large-scale agile is a crucial aspect that should be carefully addressed to ensure the protection of sensitive data, systems and user privacy. This study aims to identify and characterize the security practices that can be applied in managing large-scale agile projects.Design/methodology/approachA qualitative study is carried out through 18 interviews with 6 software development companies based in Portugal. Professionals who play the roles of Product Owner, Scrum Master and Scrum Member were interviewed. A thematic analysis was applied to identify deductive and inductive security practices.FindingsThe findings identified a total of 15 security practices, of which 8 are deductive themes and 7 are inductive. Most common security practices in large-scale agile include penetration testing, sensitive data management, automated testing, threat modeling and the implementation of a DevSecOps approach.Originality/valueThe results of this study extend the knowledge about large-scale security practices and offer relevant practical contributions for organizations that are migrating to large-scale agile environments. By incorporating security practices at every stage of the agile development lifecycle and fostering a security-conscious culture, organizations can effectively address security challenges in large-scale agile environments.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] An Empirical Perspective on Security Challenges in Large-Scale Agile Software Development
    van der Heijden, Amber
    Broasca, Cosmin
    Serebrenik, Alexander
    [J]. PROCEEDINGS OF THE 12TH ACM/IEEE INTERNATIONAL SYMPOSIUM ON EMPIRICAL SOFTWARE ENGINEERING AND MEASUREMENT (ESEM 2018), 2018,
  • [2] Requirements engineering challenges and practices in large-scale agile system development
    Kasauli, Rashidah
    Knauss, Eric
    Horkoff, Jennifer
    Liebel, Grischa
    de Oliveira Neto, Francisco Gomes
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 2021, 172
  • [3] Agile software testing in a large-scale project
    Talby, David
    Keren, Aria
    Hazzan, Orit
    Dubinsky, Yael
    [J]. IEEE SOFTWARE, 2006, 23 (04) : 30 - +
  • [4] Coordination in Large-Scale Agile Software Development
    Berntzen, Marthe
    [J]. AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING - WORKSHOPS, 2019, 364 : 123 - 133
  • [5] Software Product Management in Large-Scale Agile
    Moe, Nils Brede
    Berntzen, Marthe
    Barbala, Astri
    Stray, Viktoria
    [J]. AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING, XP 2024, 2024, 512 : 53 - 69
  • [6] Adoption of Information Security Practices in Large-Scale Agile Software Development: A Case Study in the Finance Industry Sascha Nagele
    Naegele, Sascha
    Korn, Lorena
    Matthes, Florian
    [J]. 18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [7] What Is Large in Large-Scale? A Taxonomy of Scale for Agile Software Development
    Dingsoyr, Torgeir
    Faegri, Tor Erlend
    Itkonen, Juha
    [J]. PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROFES 2014, 2014, 8892 : 273 - 276
  • [8] Challenges in Large-Scale Agile Software Development Projects
    Saeeda, Hina
    Ahmad, Muhammad Ovais
    Gustavsson, Tomas
    [J]. 38TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2023, 2023, : 1030 - 1037
  • [9] Large-Scale Agile Software Development at SAP AG
    Schnitter, Joachim
    Mackert, Olaf
    [J]. EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING, 2011, 230 : 209 - 220
  • [10] Industry Agile Practices in Large-scale Capstone Projects
    Schneider, Jean-Guy
    Eklund, Peter W.
    Lee, Kevin
    Chen, Feifei
    Cain, Andrew
    Abdelrazek, Mohamed
    [J]. 2020 ACM/IEEE 42ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS (ICSE-COMPANION 2020), 2020, : 326 - 327