Prioritizing Industrial Security Findings in Agile Software Development Projects

被引:1
|
作者
Voggenreiter, Markus [1 ]
Schoepp, Ulrich [2 ]
机构
[1] Ludwig Maximilians Univ Munchen, Siemens Technol, Munich, Germany
[2] Fortiss GmbH, Munich, Germany
来源
2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS, ICSE-COMPANION | 2023年
关键词
agile; security findings; software engineering; prioritization;
D O I
10.1109/ICSE-Companion58688.2023.00106
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Considering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
引用
收藏
页码:375 / 379
页数:5
相关论文
共 50 条
  • [31] Project governance in public sector agile software projects
    Lappi, Teemu
    Aaltonen, Kirsi
    INTERNATIONAL JOURNAL OF MANAGING PROJECTS IN BUSINESS, 2017, 10 (02) : 263 - 294
  • [32] Learning Agile with Tech Startup Software Engineering Projects
    Buffardi, Kevin
    Robb, Colleen
    Rahn, David
    ITICSE'17: PROCEEDINGS OF THE 2017 ACM CONFERENCE ON INNOVATION AND TECHNOLOGY IN COMPUTER SCIENCE EDUCATION, 2017, : 28 - 33
  • [33] Investigating Daily Team Meetings in Agile Software Projects
    Stray, Viktoria Gulliksen
    Moe, Nils Brede
    Aurum, Aybueke
    2012 38TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA), 2012, : 274 - 281
  • [34] What Agile Processes Should We Use in Software Engineering Course Projects?
    Ju, An
    Hemani, Adnan
    Dimitriadis, Yannis
    Fox, Armando
    SIGCSE 2020: PROCEEDINGS OF THE 51ST ACM TECHNICAL SYMPOSIUM ON COMPUTER SCIENCE EDUCATION, 2020, : 643 - 649
  • [35] Automatically Prioritizing Tasks in Software Development
    Bugayenko, Yegor
    Farina, Mirko
    Kruglov, Artem
    Pedrycz, Witold
    Plaksin, Yaroslav
    Succi, Giancarlo
    IEEE ACCESS, 2023, 11 : 90322 - 90334
  • [36] Security in Agile Development: Pedagogic Lessons from an Undergraduate Software Engineering Case Study
    McDonald, J. Todd
    Trigg, Tyler H.
    Roberts, Clifton E.
    Darden, Blake J.
    CYBER SECURITY, CSS 2015, 2016, 589 : 127 - 141
  • [37] Compiling Requirements from Models for Early Phase Scope Estimation in Agile Software Development Projects
    Bisikirskiene, Lina
    Ceponiene, Lina
    Jurgelaitis, Mantas
    Ablonskis, Linas
    Grigonyte, Egle
    APPLIED SCIENCES-BASEL, 2023, 13 (22):
  • [38] Identifying some critical changes required in adopting agile practices in traditional software development projects
    Misra, Subhas
    Kumar, Vinod
    Kumar, Uma
    INTERNATIONAL JOURNAL OF QUALITY & RELIABILITY MANAGEMENT, 2010, 27 (04) : 451 - +
  • [39] Agile software development practices: evolution, principles, and criticisms
    Misra, Subhas
    Kumar, Vinod
    Kumar, Uma
    Fantazy, Kamel
    Akhter, Mahmud
    INTERNATIONAL JOURNAL OF QUALITY & RELIABILITY MANAGEMENT, 2012, 29 (09) : 972 - +
  • [40] Attitudes, Beliefs, and Development Data Concerning Agile Software Development Practices
    Matthies, Christoph
    Huegle, Johannes
    Duerschmid, Tobias
    Teusner, Ralf
    2019 IEEE/ACM 41ST INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: SOFTWARE ENGINEERING EDUCATION AND TRAINING (ICSE-SEET), 2019, : 158 - 169