An Empirical Perspective on Security Challenges in Large-Scale Agile Software Development

被引:7
|
作者
van der Heijden, Amber [1 ]
Broasca, Cosmin [2 ]
Serebrenik, Alexander [1 ]
机构
[1] Eindhoven Univ Technol, Eindhoven, Netherlands
[2] Rabobank, Utrecht, Netherlands
关键词
agile software development; security management; large-scale agile;
D O I
10.1145/3239235.3267426
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Background Agile methods have been shown to have a negative impact on security. Several studies have investigated challenges in aligning security practices with agile methods, however, none of these have examined security challenges in the context of large-scale agile. Large-scale agile can present unique challenges, as large organizations often involve highly interdependent teams that need to align with other (non-agile) departments. Goal Our objective is to identify security challenges encountered in large-scale agile software development from the perspective of agile practitioners. Method Cooperative Method Development is applied to guide a qualitative case study at Rabobank, a Dutch multinational banking organization. A total of ten interviews is conducted with members in different agile roles from five different agile development teams. Data saturation has been obtained. By open card sorting we identify challenges pertaining to security in agile. Results The following challenges appear to be unique to large-scale agile: alignment of security objectives in a distributed setting, developing a common understanding of the roles and responsibilities in security activities, and integration of low-overhead security testing tools. Additional challenges reported appear to be common to security in software development in general or concur with challenges reported for small-scale agile. Conclusions The reported findings suggest the presence of multiple security challenges unique to large-scale agile. Future work should focus on confirming these challenges and investigating possible mitigations.
引用
收藏
页数:4
相关论文
共 50 条
  • [1] Challenges in Large-Scale Agile Software Development Projects
    Saeeda, Hina
    Ahmad, Muhammad Ovais
    Gustavsson, Tomas
    [J]. 38TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2023, 2023, : 1030 - 1037
  • [2] Coordination in Large-Scale Agile Software Development: A Multiteam Systems Perspective
    Scheerer, Alexander
    Hildenbrand, Tobias
    Kude, Thomas
    [J]. 2014 47TH HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2014, : 4780 - 4788
  • [3] Large-scale agile security practices in software engineering
    Ascencao, Claudia
    Teixeira, Henrique
    Goncalves, Joao
    Almeida, Fernando
    [J]. INFORMATION AND COMPUTER SECURITY, 2024,
  • [4] Coordination in Large-Scale Agile Software Development
    Berntzen, Marthe
    [J]. AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING - WORKSHOPS, 2019, 364 : 123 - 133
  • [5] What Is Large in Large-Scale? A Taxonomy of Scale for Agile Software Development
    Dingsoyr, Torgeir
    Faegri, Tor Erlend
    Itkonen, Juha
    [J]. PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROFES 2014, 2014, 8892 : 273 - 276
  • [6] Large-Scale Agile Software Development at SAP AG
    Schnitter, Joachim
    Mackert, Olaf
    [J]. EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING, 2011, 230 : 209 - 220
  • [7] Business Development in Large-Scale Agile Software Development: Barriers and Enablers
    Olsen, John Olav
    Stray, Viktoria
    Moe, Nils Brede
    [J]. AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING - WORKSHOPS, XP 2022 WORKSHOPS, XP 2023 WORKSHOPS, 2024, 489 : 161 - 170
  • [8] Investigating the Current State of Security in Large-Scale Agile Development
    Naegele, Sascha
    Watzelt, Jan-Philipp
    Matthes, Florian
    [J]. AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING, XP 2022, 2022, 445 : 203 - 219
  • [9] Institutional Logics in Large-Scale Agile Software Development Transformations
    Gustavsson, Tomas
    [J]. AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING - WORKSHOPS (XP 2021), 2021, 426 : 12 - 19
  • [10] Requirements Engineering Challenges in Large-Scale Agile System Development
    Kasauli, Rashidah
    Liebel, Grischa
    Knauss, Eric
    Gopakumar, Swathi
    Kanagwa, Benjamin
    [J]. 2017 IEEE 25TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE), 2017, : 352 - 361