Prioritizing Industrial Security Findings in Agile Software Development Projects

被引:1
|
作者
Voggenreiter, Markus [1 ]
Schoepp, Ulrich [2 ]
机构
[1] Ludwig Maximilians Univ Munchen, Siemens Technol, Munich, Germany
[2] Fortiss GmbH, Munich, Germany
关键词
agile; security findings; software engineering; prioritization;
D O I
10.1109/ICSE-Companion58688.2023.00106
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Considering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
引用
下载
收藏
页码:375 / 379
页数:5
相关论文
共 50 条
  • [41] MANAGEMENT OF SOFTWARE DEVELOPMENT PROJECTS IN BRAZIL USING AGILE METHODS
    Ravaglia, Claudia Carrijo
    Mexas, Mirian Picinini
    Dias, Ana Claudia
    Correia da Silveira Batista, Haydee Maria
    Nunes, Kleber da Silva
    INDEPENDENT JOURNAL OF MANAGEMENT & PRODUCTION, 2021, 12 (05): : 1357 - 1374
  • [42] Coordination in co-located agile software development projects
    Strode, Diane E.
    Huff, Sid L.
    Hope, Beverley
    Link, Sebastian
    JOURNAL OF SYSTEMS AND SOFTWARE, 2012, 85 (06) : 1222 - 1238
  • [43] Uses of business process modeling in agile software development projects
    Moyano, Cielo Gonzalez
    Pufahl, Luise
    Weber, Ingo
    Mendling, Jan
    INFORMATION AND SOFTWARE TECHNOLOGY, 2022, 152
  • [44] Understanding the Use of Reference Architectures in Agile Software Development Projects
    Galster, Matthias
    Angelov, Samuil
    SOFTWARE ARCHITECTURE (ECSA 2015), 2015, 9278 : 268 - 276
  • [45] Handling Requirements Dependencies in Agile Projects: A Focus Group with Agile Software Development Practitioners
    Martakis, Aias
    Daneva, Maya
    2013 IEEE SEVENTH INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN INFORMATION SCIENCE (RCIS), 2013,
  • [46] Managing Uncertainty in Software Development Projects: An Assessment of the Agile Development Method Scrum
    Doenmez, Denniz
    Grote, Gudela
    AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING, 2011, 77 : 326 - 328
  • [47] Independent Security Testing on Agile Software Development: a Case Study in a Software Company
    Choliz, Jesus
    Vilas, Julian
    Moreira, Jose
    PROCEEDINGS 10TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY ARES 2015, 2015, : 522 - 531
  • [49] Security Compliance in Agile Software Development: A Systematic Mapping Study
    Moyon, Fabiola
    Almeida, Pamela
    Riofrio, Daniel
    Mendez, Daniel
    Kalinowski, Marcos
    2020 46TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2020), 2020, : 413 - 420
  • [50] Towards Continuous Security Compliance in Agile Software Development at Scale
    Moyon, Fabiola
    Beckers, Kristian
    Klepper, Sebastian
    Lachberger, Philipp
    Bruegge, Bernd
    PROCEEDINGS 2018 IEEE/ACM 4TH INTERNATIONAL WORKSHOP ON RAPID CONTINUOUS SOFTWARE ENGINEERING (RCOSE), 2018, : 31 - 34