Towards a secure SCRUM process for agile web application development

Patrik Maier, Zhendong Ma, Roderick Bloem

Publikation: Beitrag in Buch/Bericht/KonferenzbandBeitrag in einem KonferenzbandBegutachtung

Abstract

Agile development such as Scrum and Extreme Programming deliver so.ware in short iterations for quick response to rapid business requirement and market changes. However, established secure so.ware development methodologies are mostly based on linear models such as waterfall and V-model, making them unsuitable for direct application in an agile environment. .is paper presents a proposal for integrating security activities into Scrum process for developing secure Web applications. We identify gaps in existing approaches to secure agile development and analyze established security engineering activities. We then adapt these activities and orchestrate them into Scrum development process to achieve both security and agility. Our proposal is evaluated by a Scrum team developing commercial JAVA EE applications in an opinion survey.

Originalspracheenglisch
TitelARES 2017 - Proceedings of the 12th International Conference on Availability, Reliability and Security
Herausgeber (Verlag)Association of Computing Machinery
ISBN (elektronisch)9781450352574
DOIs
PublikationsstatusVeröffentlicht - 29 Aug. 2017
Veranstaltung12th International Conference on Availability, Reliability and Security: ARES 2017 - Reggio Calabria, Italien
Dauer: 29 Aug. 20171 Sept. 2017

Publikationsreihe

NameACM International Conference Proceeding Series
BandPart F130521

Konferenz

Konferenz12th International Conference on Availability, Reliability and Security
Land/GebietItalien
OrtReggio Calabria
Zeitraum29/08/171/09/17

ASJC Scopus subject areas

  • Software
  • Human-computer interaction
  • Maschinelles Sehen und Mustererkennung
  • Computernetzwerke und -kommunikation

Fingerprint

Untersuchen Sie die Forschungsthemen von „Towards a secure SCRUM process for agile web application development“. Zusammen bilden sie einen einzigartigen Fingerprint.

Dieses zitieren