BP: Security Concerns and Best Practices for Automation of Software Deployment Processes An Industrial Case Study

被引:18
|
作者
Mohan, Vaishnavi [1 ]
ben Othmane, Lotfi [2 ]
Kres, Andre [3 ]
机构
[1] Deloitte Analyt Inst, Berlin, Germany
[2] Iowa State Univ, Ames, IA USA
[3] IBM Corp, Berlin, Germany
关键词
D O I
10.1109/SecDev.2018.00011
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
SecDevOps is a paradigm for integrating the software development and operation processes considering security and compliance requirements. Organizations are reluctant to transform their development and operation processes to SecDevOps because of the expectation of incompatibility between security and DevOps. This paper reports about a study performed at IBM on transformation of five Business Intelligence (BI) projects to SecDevOps. The study revealed that main security concerns for the automation of the deployment process are: separation of roles, enforcement of access controls, manual security tests, audit, security guidelines, management of security issues, and participation of the security team. The major recommended best practices for a transformation of current processes to SecDevOps are: good documentation and logging, strong collaboration and communication, automation of the processes, and enforcement of separation of roles. Based on the empirical results, we conclude that separation of roles is the main aspect to be considered when planning to automate deployment processes. The results of the study are being used by IBM BI Unit and may be used by other organizations when planning to migrate to SecDevOps, especially for BI projects.
引用
收藏
页码:21 / 28
页数:8
相关论文
共 50 条
  • [21] Collecting large biometric datasets: A case study in applying software best practices
    Etter, Delores M.
    Webb, Jennifer
    Howard, John
    CrossTalk, 2014, 27 (03): : 4 - 8
  • [22] An Empirical Study of Automation in Software Security Patch Management
    Dissanayake, Nesara
    Jayatilaka, Asangi
    Zahedi, Mansooreh
    Babar, Muhammad Ali
    PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,
  • [23] Software Evolution in an Industrial Automation Ecosystem: An Exploratory Study
    Lettner, Daniela
    Angerer, Florian
    Gruenbacher, Paul
    Praehofer, Herbert
    2014 40TH EUROMICRO CONFERENCE SERIES ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2014), 2014, : 336 - 343
  • [24] Software Architecture Decision-Making Practices and Challenges: An Industrial Case Study
    Dasanayake, Sandun
    Markkula, Jouni
    Aaramaa, Sanja
    Oivo, Markku
    2015 24TH AUSTRALASIAN SOFTWARE ENGINEERING CONFERENCE (ASWEC 2015), 2015, : 88 - 97
  • [25] Observed effects of software processes change in three software firms: Industrial exploratory case study
    Yilmaz, Murat
    PAMUKKALE UNIVERSITY JOURNAL OF ENGINEERING SCIENCES-PAMUKKALE UNIVERSITESI MUHENDISLIK BILIMLERI DERGISI, 2019, 25 (02): : 240 - 246
  • [26] Software-as-a-Service Security Challenges and Best Practices: A Multivocal Literature Review
    Humayun, Mamoona
    Niazi, Mahmood
    Almufareh, Maram Fahhad
    Jhanjhi, N. Z.
    Mahmood, Sajjad
    Alshayeb, Mohammad
    APPLIED SCIENCES-BASEL, 2022, 12 (08):
  • [27] Automation software architectures in automated production systems: an industrial case study in the packaging machine industry
    Eva-Maria Neumann
    Birgit Vogel-Heuser
    Juliane Fischer
    Sebastian Diehm
    Michael Schwarz
    Tobias Englert
    Production Engineering, 2022, 16 : 847 - 856
  • [28] Automation software architectures in automated production systems: an industrial case study in the packaging machine industry
    Neumann, Eva-Maria
    Vogel-Heuser, Birgit
    Fischer, Juliane
    Diehm, Sebastian
    Schwarz, Michael
    Englert, Tobias
    PRODUCTION ENGINEERING-RESEARCH AND DEVELOPMENT, 2022, 16 (06): : 847 - 856
  • [29] Evolution in Industrial Plant Automation: A Case Study
    Legat, Christoph
    Folmer, Jens
    Vogel-Heuser, Birgit
    39TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY (IECON 2013), 2013, : 4386 - 4391
  • [30] Security in software architecture: A case study
    Sachitano, A
    Chapman, RO
    Hamilton, JA
    PROCEEDINGS FROM THE FIFTH IEEE SYSTEMS, MAN AND CYBERNETICS INFORMATION ASSURANCE WORKSHOP, 2004, : 370 - 376