Case Study of Security Development in an Agile Environment: Building Identity Management for a Government Agency

被引:5
|
作者
Rindell, Kalle [1 ]
Hyrynsalmi, Sami [1 ]
Leppanen, Ville [1 ]
机构
[1] Univ Turku, Dept Informat Technol, Turku, Finland
关键词
security; Scrum; VAHTI; infrastructure;
D O I
10.1109/ARES.2016.45
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In contemporary software development projects and computing tasks, security concerns have an increasing effect, and sometimes even guide both the design and the project's processes. In certain environments, the demand for the security becomes the main driver of the development. In these cases, the development of the product requires special security arrangements for development and hosting, and specific security-oriented processes for governance. Compliance with these requirements using agile development methods may not only be a chance to improve the project efficiency, but can in some cases, such as in the case discussed in this paper, be an organizational requirement. This paper describes a case of building a secure identity management system and its management processes, in compliance with the Finnish government's VAHTI security instructions. The building project was to be implemented in accordance to the governmental security instructions, while following the service provider's own management framework. Project itself was managed with Scrum. The project's steering group required the use of Scrum, and this project may be viewed as a showcase of Scrum's suitability to multi-teamed, multi-site, security standard-compliant work. We also discuss the difficulties of fulfilling strict security regulations regarding both the development process and the end product in this project, and the difficulties utilizing Scrum to manage a multi-site project organization. Evaluation of the effects of the security work to project cost and efficiency is also presented. Finally, suggestions to enhance the Scrum method for security-related projects are made.
引用
收藏
页码:556 / 563
页数:8
相关论文
共 50 条
  • [41] Bringing computer automation to a large government agency: A case study
    Russakoff, S
    Kronstadt, B
    Scherer, KV
    FIFTEENTH ANNUAL OFFICE SYSTEMS RESEARCH CONFERENCE: SOLUTIONS FOR THE FUTURE, 1996, : 159 - 167
  • [42] Study on the E-government Security Risk Management
    Zhou, Zhitian
    Hu, Congyang
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2008, 8 (05): : 208 - 213
  • [43] Bringing computer automation to a large government agency: A case study
    Russakoff, S
    Kronstadt, B
    Scherer, KV
    FIFTEENTH ANNUAL OFFICE SYSTEMS RESEARCH CONFERENCE: SOLUTIONS FOR THE FUTURE, 1996, : 159 - 167
  • [44] Risk Management in Agile Software Development: a Comparative Study
    Albadarneh, Aalaa
    Albadarneh, Israa
    Qusef, Abdallah
    2015 IEEE JORDAN CONFERENCE ON APPLIED ELECTRICAL ENGINEERING AND COMPUTING TECHNOLOGIES (AEECT), 2015,
  • [45] A Case Study of the Agile Enterprise Regarding the External Business Environment
    Penchev, Petar
    Kenarova-Pencheva, Irena
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON BUSINESS EXCELLENCE, 2024, 18 (01): : 573 - 582
  • [46] A Mapping Study on Knowledge Management in Agile Software Development
    Indumini, Udeshika
    Vasanthapriyan, Shanmuganathan
    2018 18TH INTERNATIONAL CONFERENCE ON ADVANCES IN ICT FOR EMERGING REGIONS (ICTER) CONFERENCE PROCEEDINGS, 2018, : 441 - 441
  • [47] Case study: Building an enterprise security program
    Teitler, Katie
    ISACA Journal, 2020, 4 : 43 - 48
  • [48] Toward an Agile and Transformational Government, Through the Development of the Tangerang LIVE Application (Case Study of Tangerang City, Indonesia)
    Syukri, Ahmad
    Nurmandi, Achmad
    Muallidin, Isnaini
    Kurniawan, Danang
    Loilatu, Mohammad Jafar
    PROCEEDINGS OF SEVENTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, ICICT 2022, VOL. 3, 2023, 464 : 343 - 352
  • [49] Modelling and Development of Energy Management System in a Domestic Building: Case Study
    Jones, Owain
    Sprake, David
    Vagapov, Yuriy
    Borzistaya, Ekaterina
    PROCEEDINGS OF THE 2017 IEEE RUSSIA SECTION YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING CONFERENCE (2017 ELCONRUS), 2017, : 429 - 434
  • [50] Information Security Risk Management by a Holistic Approach: a Case Study for Vietnamese e-Government
    Ha Le Viet
    On Phung Van
    Hoa Nguyen Ngoc
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2020, 20 (06): : 72 - 82