BP: Security Concerns and Best Practices for Automation of Software Deployment Processes An Industrial Case Study

被引:18
|
作者
Mohan, Vaishnavi [1 ]
ben Othmane, Lotfi [2 ]
Kres, Andre [3 ]
机构
[1] Deloitte Analyt Inst, Berlin, Germany
[2] Iowa State Univ, Ames, IA USA
[3] IBM Corp, Berlin, Germany
关键词
D O I
10.1109/SecDev.2018.00011
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
SecDevOps is a paradigm for integrating the software development and operation processes considering security and compliance requirements. Organizations are reluctant to transform their development and operation processes to SecDevOps because of the expectation of incompatibility between security and DevOps. This paper reports about a study performed at IBM on transformation of five Business Intelligence (BI) projects to SecDevOps. The study revealed that main security concerns for the automation of the deployment process are: separation of roles, enforcement of access controls, manual security tests, audit, security guidelines, management of security issues, and participation of the security team. The major recommended best practices for a transformation of current processes to SecDevOps are: good documentation and logging, strong collaboration and communication, automation of the processes, and enforcement of separation of roles. Based on the empirical results, we conclude that separation of roles is the main aspect to be considered when planning to automate deployment processes. The results of the study are being used by IBM BI Unit and may be used by other organizations when planning to migrate to SecDevOps, especially for BI projects.
引用
收藏
页码:21 / 28
页数:8
相关论文
共 50 条
  • [41] Capturing Software Security Practices using CBR: Three Case Studies
    Elrhaffari, Ikram
    Roudies, Ounsa
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (11) : 426 - 434
  • [42] Improving the Deployment of IT Service Management Processes: A Case Study
    Jantti, Marko
    Jarvinen, Julia
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, 2011, 172 : 37 - +
  • [43] Safeguarding Software-Defined Networks: Comprehensive Frameworks and Best Practices for Security Threat Mitigation
    Verma, Jyoti
    Snehi, Manish
    Kansa, Isha
    Kumar, Rajiv
    Goel, Kanu
    Singh, Ranvijay
    RECENT ADVANCES IN ELECTRICAL & ELECTRONIC ENGINEERING, 2025,
  • [44] Case study: Software product integration practices
    Larsson, S
    Crnkovic, I
    PRODUCT FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROCEEDINGS, 2005, 3547 : 272 - 285
  • [45] Comparison of SETAM with Security Use Case and Security Misuse Case:A Software Security Testing Study
    HUI Zhanwei1
    2.PLA Military Training Software Test and Evaluation Centre
    WuhanUniversityJournalofNaturalSciences, 2012, 17 (06) : 516 - 520
  • [46] A Case Study in Distributed Deployment of Embedded Software for Camera Networks
    Leonardi, Francesco
    Pinto, Alessandro
    Carloni, Luca P.
    DATE: 2009 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION, VOLS 1-3, 2009, : 1006 - +
  • [47] Multiple case study of processes used by hospitals to select performance indicators: do they align with best practices?
    Heenan, Michael A.
    Randall, Glen E.
    Evans, Jenna M.
    Reid, Erin M.
    INTERNATIONAL JOURNAL FOR QUALITY IN HEALTH CARE, 2024, 36 (01)
  • [48] Gradual Deployment in Practice: Experiences from an Industrial Case Study
    Pakarinen, Eveliina
    Harakkamaki, Tommi
    Mikkonen, Tommi
    2020 46TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2020), 2020, : 237 - 241
  • [49] Deployment of a Smart and Predictive Maintenance System in an Industrial Case Study
    Alves, Filipe
    Badikyan, Hasmik
    Moreira, Antonio H. J.
    Azevedo, Joao
    Moreira, Pedro Miguel
    Romero, Luis
    Leitao, Paulo
    2020 IEEE 29TH INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2020, : 493 - 498
  • [50] Enhancing Industrial Automation: A Practical Study on Communication Protocols and EdMES Software Integration
    Diaz, Heylin
    Poor, Peter
    IEEE REVISTA IBEROAMERICANA DE TECNOLOGIAS DEL APRENDIZAJE-IEEE RITA, 2024, 19 : 361 - 370