Prioritizing Industrial Security Findings in Agile Software Development Projects

被引:1
|
作者
Voggenreiter, Markus [1 ]
Schoepp, Ulrich [2 ]
机构
[1] Ludwig Maximilians Univ Munchen, Siemens Technol, Munich, Germany
[2] Fortiss GmbH, Munich, Germany
关键词
agile; security findings; software engineering; prioritization;
D O I
10.1109/ICSE-Companion58688.2023.00106
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Considering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
引用
下载
收藏
页码:375 / 379
页数:5
相关论文
共 50 条
  • [31] Software security in agile software development: A literature review of challenges and solutions
    Riisom, Klaus Reche
    Hubel, Martin Slusarczyk
    Alradhi, Hasan Mousa
    Nielsen, Niels Bonde
    Kuusinen, Kati
    Jabangwe, Ronald
    19TH INTERNATIONAL CONFERENCE ON AGILE SOFTWARE DEVELOPMENT (XP '18), 2018,
  • [32] A Competency Model for Customer Representatives in Agile Software Development Projects
    Matook, Sabine
    Maruping, Likoebe M.
    MIS QUARTERLY EXECUTIVE, 2014, 13 (02) : 77 - 95
  • [33] A multicriteria approach for selection of agile methodologies in software development projects
    Silva, Vanessa B. S.
    Schramm, Fernando
    Damasceno, Adriana C.
    2016 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2016, : 2056 - 2060
  • [34] Survey on Risk Classification in Agile Software Development Projects in Latvia
    Nikiforova, Oksana
    Babris, Kristaps
    Kristapsons, Janis
    APPLIED COMPUTER SYSTEMS, 2020, 25 (02) : 105 - 116
  • [35] Agile practices in software development Experiences from student projects
    Schneider, Jean-Guy
    Vasa, Rajesh
    2006 AUSTRALIAN SOFTWARE ENGINEERING CONFERENCE, PROCEEDINGS, 2006, : 401 - +
  • [36] Issues and Challenges of Cost Management in Agile Software Development Projects
    Mansor, Zulkefli
    Razali, Rozilawati
    Yahaya, Jamaiah
    Yahya, Saadiah
    Arshad, Noor Habibah
    ADVANCED SCIENCE LETTERS, 2016, 22 (08) : 1981 - 1984
  • [37] Measuring Success in Agile Software Development Projects: a GQM Approach
    Aldahmash, Abdullah
    Graven, Andy
    THIRTEENTH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING ADVANCES (ICSEA 2018), 2018, : 38 - 44
  • [38] Agile software development approach for 'ad-hoc' IT projects
    Kuciapski, Michal
    Marcinkowski, Bartosz
    IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT, 2023, 11 (04): : 28 - 51
  • [39] Challenges in Large-Scale Agile Software Development Projects
    Saeeda, Hina
    Ahmad, Muhammad Ovais
    Gustavsson, Tomas
    38TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2023, 2023, : 1030 - 1037
  • [40] Towards a Better Understanding of Simplicity in Agile Software Development Projects
    Santos, Wylliams
    PROCEEDINGS OF THE 20TH INTERNATIONAL CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING 2016 (EASE '16), 2016,