Case Study of Security Development in an Agile Environment: Building Identity Management for a Government Agency

被引:5
|
作者
Rindell, Kalle [1 ]
Hyrynsalmi, Sami [1 ]
Leppanen, Ville [1 ]
机构
[1] Univ Turku, Dept Informat Technol, Turku, Finland
关键词
security; Scrum; VAHTI; infrastructure;
D O I
10.1109/ARES.2016.45
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In contemporary software development projects and computing tasks, security concerns have an increasing effect, and sometimes even guide both the design and the project's processes. In certain environments, the demand for the security becomes the main driver of the development. In these cases, the development of the product requires special security arrangements for development and hosting, and specific security-oriented processes for governance. Compliance with these requirements using agile development methods may not only be a chance to improve the project efficiency, but can in some cases, such as in the case discussed in this paper, be an organizational requirement. This paper describes a case of building a secure identity management system and its management processes, in compliance with the Finnish government's VAHTI security instructions. The building project was to be implemented in accordance to the governmental security instructions, while following the service provider's own management framework. Project itself was managed with Scrum. The project's steering group required the use of Scrum, and this project may be viewed as a showcase of Scrum's suitability to multi-teamed, multi-site, security standard-compliant work. We also discuss the difficulties of fulfilling strict security regulations regarding both the development process and the end product in this project, and the difficulties utilizing Scrum to manage a multi-site project organization. Evaluation of the effects of the security work to project cost and efficiency is also presented. Finally, suggestions to enhance the Scrum method for security-related projects are made.
引用
收藏
页码:556 / 563
页数:8
相关论文
共 50 条
  • [21] Agile Development as a Change Management Approach in Software Projects: Applied Case Study
    Alawairdhi, Mohammed
    PROCEEDINGS OF 2016 2ND INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT (ICIM2016), 2016,
  • [22] Agile Project Management Styles and Control Ambidexterity in Agile Information Systems Development Projects: An Exploratory Case Study
    Virag, Peter
    Bernroider, Edward W. N.
    Remus, Ulrich
    JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2024, 25 (05): : 1274 - 1302
  • [23] An Issues Management Perspective on Corporate Identity: The Case of a Regulatory Agency
    Illia L.
    Schmid E.
    Fischbach I.
    Hangartner R.
    Rivola R.
    Corporate Reputation Review, 2004, 7 (1) : 10 - 21
  • [24] Building up trusted identity management in mobile heterogeneous environment
    Zhang, Peng
    Sun, Hanlin
    Yan, Zheng
    TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 873 - 877
  • [25] Agile Data Management in NAV: A Case Study
    Vestues, Kathrine
    Hanssen, Geir Kjetil
    Mikalsen, Marius
    Buan, Thor Aleksander
    Conboy, Kieran
    AGILE PROCESSES IN SOFTWARE ENGINEERING AND EXTREME PROGRAMMING, XP 2022, 2022, 445 : 220 - 235
  • [26] Knowledge Management in Practice: The Case of Agile Software Development
    Levy, Meira
    Hazzan, Orit
    2009 ICSE WORKSHOP ON COOPERATIVE AND HUMAN ASPECTS OF SOFTWARE ENGINEERING, 2009, : 60 - +
  • [27] Development of Frame Work for Residential Building Construction Using Agile Management
    Paul, Anand Jose
    Eldhose, Sahimol
    PROCEEDINGS OF STRUCTURAL ENGINEERING AND CONSTRUCTION MANAGEMENT, SECON'19, 2020, 46 : 725 - 737
  • [28] Security Compliance in Agile Software Development: A Systematic Mapping Study
    Moyon, Fabiola
    Almeida, Pamela
    Riofrio, Daniel
    Mendez, Daniel
    Kalinowski, Marcos
    2020 46TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2020), 2020, : 413 - 420
  • [29] A case with stock management in government office building in Hokkaido
    Government Buildings Department, Hokkaido Development Bureau, MLIT, Japan
    不详
    AIJ J. Technol. Des., 2007, 25 (301-304):
  • [30] Making agile development work in a government contracting environment - Measuring velocity with earned value
    Alleman, GB
    Henderson, M
    Seggelke, R
    PROCEEDINGS OF THE AGILE DEVELOPMENT CONFERENCE, 2003, : 114 - 119