Prioritizing Industrial Security Findings in Agile Software Development Projects

被引:1
|
作者
Voggenreiter, Markus [1 ]
Schoepp, Ulrich [2 ]
机构
[1] Ludwig Maximilians Univ Munchen, Siemens Technol, Munich, Germany
[2] Fortiss GmbH, Munich, Germany
关键词
agile; security findings; software engineering; prioritization;
D O I
10.1109/ICSE-Companion58688.2023.00106
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Considering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
引用
收藏
页码:375 / 379
页数:5
相关论文
共 50 条
  • [1] Prioritizing User Requirements for Agile Software Development
    Sachdeva, Samridhi
    Arya, Akshay
    Paygude, Priyanka
    Chaudhary, Snehal
    Idate, Sonali
    2018 INTERNATIONAL CONFERENCE ON ADVANCES IN COMMUNICATION AND COMPUTING TECHNOLOGY (ICACCT), 2018, : 495 - 498
  • [2] Prioritizing and Optimizing Risk Factors in Agile Software development
    Agrawal, Ruchi
    Singh, Deepali
    Sharma, Ashish
    2016 NINTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2016, : 241 - 247
  • [3] Security Practices in Agile Software Development
    Selva-Mora, Alejandra
    Quesada-Lopez, Christian
    PROCEEDINGS 2024 IEEE/ACM INTERNATIONAL WORKSHOP ON SOFTWARE-INTENSIVE BUSINESS, IWSIB 2024, 2024, : 56 - 63
  • [4] The Security Intention Meeting Series as a way to increase visibility of software security decisions in agile development projects
    Tondel, Inger Anne
    Cruzes, Daniela Soares
    Jaatun, Martin Gilje
    Rindell, Kalle
    14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
  • [5] A dependency taxonomy for agile software development projects
    Diane E. Strode
    Information Systems Frontiers, 2016, 18 : 23 - 46
  • [6] Barriers to Learning in Agile Software Development Projects
    Babb, Jeffry S.
    Hoda, Rashina
    Norbjerg, Jacob
    AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING, XP 2013, 2013, 149 : 1 - 15
  • [7] A Software Development Process for Super Agile Projects
    Cerqueira, Marilia M. B.
    Magalhaes, Ana Patricia
    Saba, Hugo
    Jorge, Eduardo M. F.
    PROCEEDINGS OF THE 14TH BRAZILIAN SYMPOSIUM ON INFORMATION SYSTEMS (SBSI2018), 2018, : 400 - 407
  • [8] Agile Software Development Projects Compliance to ASPICE
    Ibrahim, Ahmed
    Badr, Khaled
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2024, PT II, 2024, 2180 : 294 - 308
  • [9] A dependency taxonomy for agile software development projects
    Strode, Diane E.
    INFORMATION SYSTEMS FRONTIERS, 2016, 18 (01) : 23 - 46
  • [10] Distributing Expertise in Agile Software Development Projects
    Rejab, Mawarny Md.
    Noble, James
    Allan, George
    2014 AGILE CONFERENCE (AGILE), 2014, : 33 - 36