Case Study of Security Development in an Agile Environment: Building Identity Management for a Government Agency

被引:5
|
作者
Rindell, Kalle [1 ]
Hyrynsalmi, Sami [1 ]
Leppanen, Ville [1 ]
机构
[1] Univ Turku, Dept Informat Technol, Turku, Finland
关键词
security; Scrum; VAHTI; infrastructure;
D O I
10.1109/ARES.2016.45
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In contemporary software development projects and computing tasks, security concerns have an increasing effect, and sometimes even guide both the design and the project's processes. In certain environments, the demand for the security becomes the main driver of the development. In these cases, the development of the product requires special security arrangements for development and hosting, and specific security-oriented processes for governance. Compliance with these requirements using agile development methods may not only be a chance to improve the project efficiency, but can in some cases, such as in the case discussed in this paper, be an organizational requirement. This paper describes a case of building a secure identity management system and its management processes, in compliance with the Finnish government's VAHTI security instructions. The building project was to be implemented in accordance to the governmental security instructions, while following the service provider's own management framework. Project itself was managed with Scrum. The project's steering group required the use of Scrum, and this project may be viewed as a showcase of Scrum's suitability to multi-teamed, multi-site, security standard-compliant work. We also discuss the difficulties of fulfilling strict security regulations regarding both the development process and the end product in this project, and the difficulties utilizing Scrum to manage a multi-site project organization. Evaluation of the effects of the security work to project cost and efficiency is also presented. Finally, suggestions to enhance the Scrum method for security-related projects are made.
引用
收藏
页码:556 / 563
页数:8
相关论文
共 50 条
  • [1] Tensions and ambidexterity: a case study of an agile project at a government agency
    Lindskog, Carin
    IJISPM-INTERNATIONAL JOURNAL OF INFORMATION SYSTEMS AND PROJECT MANAGEMENT, 2022, 10 (02): : 5 - 23
  • [2] Agile Project Management: A Case Study of a Virtual Research Environment Development Project
    Procter, Rob
    Rouncefield, Mark
    Poschen, Meik
    Lin, Yuwei
    Voss, Alex
    COMPUTER SUPPORTED COOPERATIVE WORK-THE JOURNAL OF COLLABORATIVE COMPUTING AND WORK PRACTICES, 2011, 20 (03): : 197 - 225
  • [3] Agile Project Management: A Case Study of a Virtual Research Environment Development Project
    Rob Procter
    Mark Rouncefield
    Meik Poschen
    Yuwei Lin
    Alex Voss
    Computer Supported Cooperative Work (CSCW), 2011, 20 : 197 - 225
  • [4] Analyzing of Employee Behavior on Information Security: A Case Study in a Government Agency
    Prabowo, Yulianto Budi
    Fathi, Muhammad
    Hidayanto, Achmad Nizar
    Hapsari, Ika Chandra
    PROCEEDINGS OF 2018 THE 10TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND ELECTRICAL ENGINEERING (ICITEE), 2018, : 112 - 117
  • [5] Information Security Awareness: Study on a Government Agency
    Kusumawati, Arie
    PROCEEDINGS OF 2018 3RD INTERNATIONAL CONFERENCE ON SUSTAINABLE INFORMATION ENGINEERING AND TECHNOLOGY (SIET 2018), 2018, : 224 - 229
  • [6] Energy Management Study: A Proposed Case of Government Building
    Tahir, Mohamad Zamhari
    Nawi, Mohd Nasrun Mohd
    Baharum, Mohd Faizal
    INTERNATIONAL CONFERENCE ON MATHEMATICS, ENGINEERING AND INDUSTRIAL APPLICATIONS 2014 (ICOMEIA 2014), 2015, 1660
  • [7] The adoption of agile management practices in a traditional project environment: An IT/IS Case Study
    Wells, Hany
    Dalcher, Darren
    Smyth, Hedley
    2015 48TH HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2015, : 4446 - 4453
  • [8] The effects of a stress management program in a high security government agency
    Sheppard, WD
    Staggers, FJ
    John, L
    ANXIETY STRESS AND COPING, 1997, 10 (04): : 341 - 350
  • [9] Adopting agile in government: a comparative case study
    Neumann, Oliver
    Kirklies, Pascale-Catherine
    Schott, Carina
    PUBLIC MANAGEMENT REVIEW, 2024, 26 (12) : 3692 - 3714
  • [10] Independent Security Testing on Agile Software Development: a Case Study in a Software Company
    Choliz, Jesus
    Vilas, Julian
    Moreira, Jose
    PROCEEDINGS 10TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY ARES 2015, 2015, : 522 - 531