Agile security using an incremental security architecture

被引:0
|
作者
Chivers, H [1 ]
Paige, RF [1 ]
Ge, XC [1 ]
机构
[1] Univ York, Dept Comp Sci, York YO10 5DD, N Yorkshire, England
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The effective provision of security in an agile development requires a new approach: traditional security practices are bound to equally traditional development methods. However, there are concerns that security is difficult to build incrementally, and can prove prohibitively expensive to refactor. This paper describes how to grow security, organically, within an agile project, by using an incremental security architecture which evolves with the code. The architecture provides an essential bridge between system-wide security properties and implementation mechanisms, a focus for understanding security in the project, and a trigger for security refactoring. The paper also describes criteria that allow implementers to recognize when refactoring is needed, and a concrete example that contrasts incremental and 'top-down' architectures.
引用
收藏
页码:57 / 65
页数:9
相关论文
共 50 条
  • [41] A Smart Security Drones for Farms Using Software Architecture
    Karl, Yoki
    Kim, Haeng-Kon
    Lee, Jong-Halk
    INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2020, 8 (04) : 40 - 49
  • [42] Security architecture for health grid using ambient intelligence
    Naqvi, S
    Riguidel, M
    Demeure, I
    METHODS OF INFORMATION IN MEDICINE, 2005, 44 (02) : 202 - 206
  • [43] Web service security model using CBD architecture
    Park, Eun-Ju
    Kim, Haeng-Kon
    Lee, Roger Y.
    SERA 2007: 5TH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH, MANAGEMENT, AND APPLICATIONS, PROCEEDINGS, 2007, : 346 - +
  • [44] Cyber Security Threats Detection Using Ensemble Architecture
    Chou, Te-Shun
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2011, 5 (02): : 17 - 31
  • [45] Practical Multicast Security Architecture Using Sleep State
    Lee, Hoyoung
    Liu, Jing
    Han, Sunyoung
    2008 22ND INTERNATIONAL WORKSHOPS ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOLS 1-3, 2008, : 508 - 513
  • [46] Security in agile software development: A practitioner survey
    Rindell, Kalle
    Ruohonen, Jukka
    Holvitie, Johannes
    Hyrynsalmi, Sami
    Leppanen, Ville
    INFORMATION AND SOFTWARE TECHNOLOGY, 2021, 131
  • [47] Security in agile software development: A practitioner survey
    Rindell, Kalle
    Ruohonen, Jukka
    Holvitie, Johannes
    Hyrynsalmi, Sami
    Leppänen, Ville
    Information and Software Technology, 2021, 131
  • [48] Enabling Design of Agile Security in the IOT with MBSE
    Papke, Barry L.
    2017 12TH SYSTEM OF SYSTEMS ENGINEERING CONFERENCE (SOSE), 2017,
  • [49] Identification and Evaluation of Security Activities in Agile Projects
    Ayalew, Tigist
    Kidane, Tigist
    Carlsson, Bengt
    SECURE IT SYSTEMS, NORDSEC 2013, 2013, 8208 : 139 - 153
  • [50] Aligning Security Objectives With Agile Software Development
    Rindell, Kalle
    Hyrynsalmi, Sami
    Leppanen, Ville
    19TH INTERNATIONAL CONFERENCE ON AGILE SOFTWARE DEVELOPMENT (XP '18), 2018,