Prioritizing Industrial Security Findings in Agile Software Development Projects

被引:1
|
作者
Voggenreiter, Markus [1 ]
Schoepp, Ulrich [2 ]
机构
[1] Ludwig Maximilians Univ Munchen, Siemens Technol, Munich, Germany
[2] Fortiss GmbH, Munich, Germany
来源
2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS, ICSE-COMPANION | 2023年
关键词
agile; security findings; software engineering; prioritization;
D O I
10.1109/ICSE-Companion58688.2023.00106
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Considering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
引用
收藏
页码:375 / 379
页数:5
相关论文
共 50 条
  • [21] Guidelines for Choosing an Agile Methodology for Software Projects
    Velandia, Lucy Nohemy Medina
    Gutierrez, Daniel Andres
    REVISTA EDUCACION EN INGENIERIA, 2023, 19 (37): : 1 - 8
  • [22] Prioritizing DevOps Implementation Guidelines for Sustainable Software Projects
    Zohaib, Muhammad
    Alsanad, Ahmed
    Alhogail, Areej Abdullah
    IEEE ACCESS, 2024, 12 : 71109 - 71130
  • [23] Identifying Risky Areas of Software Code in Agile/Lean Software Development: An Industrial Experience Report
    Antinyan, Vard
    Staron, Miroslaw
    Meding, Wilhelm
    Osterstrom, Per
    Wikstrom, Erik
    Wranker, Johan
    Henriksson, Anders
    Hansson, Jorgen
    2014 SOFTWARE EVOLUTION WEEK - IEEE CONFERENCE ON SOFTWARE MAINTENANCE, REENGINEERING, AND REVERSE ENGINEERING (CSMR-WCRE), 2014, : 154 - +
  • [24] Metrics to evaluate & monitor Agile based software development projects A Fuzzy Logic approach
    Sedehi, Habib
    Martano, Giovanni
    PROCEEDINGS OF THE 2012 JOINT CONFERENCE OF THE 22ND INTERNATIONAL WORKSHOP ON SOFTWARE MEASUREMENT AND THE 2012 SEVENTH INTERNATIONAL CONFERENCE ON SOFTWARE PROCESS AND PRODUCT MEASUREMENT (IWSM-MENSURA 2012), 2012, : 99 - 105
  • [25] The role of project management in ineffective decision making within Agile software development projects
    McAvoy, John
    Butler, Tom
    EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2009, 18 (04) : 372 - 383
  • [26] Requirement paradigms to implement the software projects in agile development using analytical hierarchy process
    Dhir S.
    Kumar D.
    Singh V.B.
    International Journal of Decision Support System Technology, 2017, 9 (03) : 28 - 41
  • [27] Common Spikes Success Factors: An Industrial Investigation within Agile Software Development
    Al Hashimi, Hussein
    Abduldaem, Asmaa
    Gravell, Andy
    2022 12TH INTERNATIONAL CONFERENCE ON SOFTWARE TECHNOLOGY AND ENGINEERING, ICSTE, 2022, : 1 - 7
  • [28] Adopting to Agile Software Development
    Linkevics, Gusts
    APPLIED COMPUTER SYSTEMS, 2014, 16 (01) : 64 - 70
  • [29] Knowledge Management in Agile Software Projects: A Systematic Review
    Cabral, Anderson R. Yanzer
    Ribeiro, Marcelo Blois
    Noll, Rodrigo Perozzo
    JOURNAL OF INFORMATION & KNOWLEDGE MANAGEMENT, 2014, 13 (01)
  • [30] Analysis of Software Engineering for Agile Machine Learning Projects
    Singla, Kushal
    Bose, Joy
    Naik, Chetan
    IEEE INDICON: 15TH IEEE INDIA COUNCIL INTERNATIONAL CONFERENCE, 2018,