Prioritizing Industrial Security Findings in Agile Software Development Projects

被引:1
|
作者
Voggenreiter, Markus [1 ]
Schoepp, Ulrich [2 ]
机构
[1] Ludwig Maximilians Univ Munchen, Siemens Technol, Munich, Germany
[2] Fortiss GmbH, Munich, Germany
来源
2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS, ICSE-COMPANION | 2023年
关键词
agile; security findings; software engineering; prioritization;
D O I
10.1109/ICSE-Companion58688.2023.00106
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Considering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
引用
收藏
页码:375 / 379
页数:5
相关论文
共 50 条
  • [1] Prioritizing User Requirements for Agile Software Development
    Sachdeva, Samridhi
    Arya, Akshay
    Paygude, Priyanka
    Chaudhary, Snehal
    Idate, Sonali
    2018 INTERNATIONAL CONFERENCE ON ADVANCES IN COMMUNICATION AND COMPUTING TECHNOLOGY (ICACCT), 2018, : 495 - 498
  • [2] Aligning Security Objectives With Agile Software Development
    Rindell, Kalle
    Hyrynsalmi, Sami
    Leppanen, Ville
    19TH INTERNATIONAL CONFERENCE ON AGILE SOFTWARE DEVELOPMENT (XP '18), 2018,
  • [3] Is There an Optimal Sprint Length on Agile Software Development Projects?
    Nascimento, Nicolas
    Santos, Alan
    Sales, Afonso
    Chanin, Rafael
    ICEIS: PROCEEDINGS OF THE 24TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS - VOL 2, 2022, : 98 - 105
  • [4] Agile Software Development Projects Compliance to ASPICE
    Ibrahim, Ahmed
    Badr, Khaled
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2024, PT II, 2024, 2180 : 294 - 308
  • [5] An Approach to Software Architecting in Agile Software Development Projects in Education
    Angelov, Samuil
    de Beer, Patrick
    SOFTWARE ARCHITECTURE (ECSA 2015), 2015, 9278 : 157 - 168
  • [6] Knowledge Management in Distributed Agile Software Development Projects
    Razzak, Mohammad Abdur
    Bhuiyan, Touhid
    Ahmed, Rajib
    ARTIFICIAL INTELLIGENCE FOR KNOWLEDGE MANAGEMENT, AI4KM 2014, 2015, 469 : 107 - 131
  • [7] Adopting threat modelling in agile software development projects
    Bernsmed, Karin
    Cruzes, Daniela Soares
    Jaatun, Martin Gilje
    Iovan, Monica
    JOURNAL OF SYSTEMS AND SOFTWARE, 2022, 183
  • [8] The Missing Framework for Adaptation of Agile Software Development Projects
    Suryaatmaja, Kevin
    Wibisono, Dermawan
    Ghazali, Achmad
    EURASIAN BUSINESS PERSPECTIVES, 2019, 11 (02): : 113 - 127
  • [9] Development of software projects in thesis using an agile methodology
    Rivera S., Gustavo A.
    Forero S, Pedro A.
    Simanca H, Fredys A.
    Fabian Blanco, G.
    2022 8TH INTERNATIONAL ENGINEERING, SCIENCES AND TECHNOLOGY CONFERENCE, IESTEC, 2022, : 293 - 298
  • [10] Survey on Risk Classification in Agile Software Development Projects in Latvia
    Nikiforova, Oksana
    Babris, Kristaps
    Kristapsons, Janis
    APPLIED COMPUTER SYSTEMS, 2020, 25 (02) : 105 - 116