Software Security Activities that Support Incident Management in Secure DevOps

被引:4
作者
Jaatun, Martin Gilje [1 ]
机构
[1] SINTEF Digital, Trondheim, Norway
来源
13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018) | 2019年
关键词
DevOps; Software Security; Incident Management;
D O I
10.1145/3230833.3233275
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Many software services are currently created using DevOps, where developers and operations personnel are more tightly integrated. The DevOps paradigm enables shorter development cycles, but increased speed has raised concerns over whether security issues may be overlooked. However, perfect security is never achievable, and in addition to the proactive software security efforts, we also need a reactive effort to handle flaws and bugs that are not discovered before they are used in an attack. In this paper we explore how focus on incident management and collaboration with developers can contribute to improved software security.
引用
收藏
页数:6
相关论文
共 17 条
[1]  
ben Othmane L., 2014, IEEE T DEPENDABLE SE
[2]  
Boehm Barry, 2005, FDN EMPIRICAL SOFTWA, V426
[3]  
de Feijter Rico, 2017, THESIS
[4]   Towards Incident Handling in the Cloud: Challenges and Approaches [J].
Grobauer, Bernd ;
Schreck, Thomas .
PROCEEDINGS OF THE 2010 ACM WORKSHOP CLOUD COMPUTING SECURITY WORKSHOP (CCSW'10:), 2010, :77-85
[5]  
ISO/IEC, 2011, 270352011 ISOIEC
[6]  
Jaatun Martin Gilje, 2012, Multidisciplinary Research and Practice for Information Systems. International Cross-Domain Conference and Workshop on Availability, Reliability and Security (CD-ARES 2012). Proceedings, P85, DOI 10.1007/978-3-642-32498-7_7
[7]   Enhancing accountability in the cloud [J].
Jaatun, Martin Gilje ;
Pearson, Siani ;
Gittler, Frederic ;
Leenes, Ronald ;
Niezen, Maartje .
INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2020, 53
[8]   Software Security Maturity in Public Organisations [J].
Jaatun, Martin Gilje ;
Cruzes, Daniela S. ;
Bernsmed, Karin ;
Tondel, Inger Anne ;
Rostad, Lillian .
INFORMATION SECURITY, ISC 2015, 2015, 9290 :120-138
[9]   How Much Cloud Can You Handle? [J].
Jaatun, Martin Gilje ;
Tondel, Inger Anne .
PROCEEDINGS 10TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY ARES 2015, 2015, :467-473
[10]  
Jaatun Martin Gilje, 2017, INT J SECURE SOFTWAR, V8, piv