Prioritizing Industrial Security Findings in Agile Software Development Projects

被引:1
|
作者
Voggenreiter, Markus [1 ]
Schoepp, Ulrich [2 ]
机构
[1] Ludwig Maximilians Univ Munchen, Siemens Technol, Munich, Germany
[2] Fortiss GmbH, Munich, Germany
关键词
agile; security findings; software engineering; prioritization;
D O I
10.1109/ICSE-Companion58688.2023.00106
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Considering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
引用
下载
收藏
页码:375 / 379
页数:5
相关论文
共 50 条
  • [21] Agile Methods Adoption in Large Software Development Projects
    Mishra, Alok
    2016 5TH INTERNATIONAL CONFERENCE ON RELIABILITY, INFOCOM TECHNOLOGIES AND OPTIMIZATION (TRENDS AND FUTURE DIRECTIONS) (ICRITO), 2016, : 16 - 16
  • [22] Adopting threat modelling in agile software development projects
    Bernsmed, Karin
    Cruzes, Daniela Soares
    Jaatun, Martin Gilje
    Iovan, Monica
    JOURNAL OF SYSTEMS AND SOFTWARE, 2022, 183
  • [23] Is There an Optimal Sprint Length on Agile Software Development Projects?
    Nascimento, Nicolas
    Santos, Alan
    Sales, Afonso
    Chanin, Rafael
    ICEIS: PROCEEDINGS OF THE 24TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS - VOL 2, 2022, : 98 - 105
  • [24] The role of the project manager in agile software development projects
    Shastri, Yogeshwar
    Hoda, Rashina
    Amor, Robert
    JOURNAL OF SYSTEMS AND SOFTWARE, 2021, 173
  • [25] A systematic literature review of agile software development projects
    Rath, Soumya Prakash
    Jain, Nikunj Kumar
    Tomer, Gunjan
    Singh, Alok Kumar
    Information and Software Technology, 2025, 182
  • [26] The Missing Framework for Adaptation of Agile Software Development Projects
    Suryaatmaja, Kevin
    Wibisono, Dermawan
    Ghazali, Achmad
    EURASIAN BUSINESS PERSPECTIVES, 2019, 11 (02): : 113 - 127
  • [27] Development of software projects in thesis using an agile methodology
    Rivera S., Gustavo A.
    Forero S, Pedro A.
    Simanca H, Fredys A.
    Fabian Blanco, G.
    2022 8TH INTERNATIONAL ENGINEERING, SCIENCES AND TECHNOLOGY CONFERENCE, IESTEC, 2022, : 293 - 298
  • [28] A Paradox Lens to Systems Development Projects: The Case of the Agile Software Development
    Iivari, Juhani
    COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2021, 49 : 1 - 37
  • [29] Influencing the security prioritisation of an agile software development project
    Tondel, Inger Anne
    Cruzes, Daniela Soares
    Jaatun, Martin Gilje
    Sindre, Guttorm
    COMPUTERS & SECURITY, 2022, 118
  • [30] Integrating software development security activities with agile methodologies
    Keramati, Hossein
    Mirian-Hosseinabadi, Seyed-Hassan
    2008 IEEE/ACS INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS, VOLS 1-3, 2008, : 749 - 754