How to Integrate Security Compliance Requirements with Agile Software Engineering at Scale?
2020 (English)In: Lecture Notes in Computer Science / [ed] Morisio M.,Torchiano M.,Jedlitschka A., Springer Science+Business Media B.V., 2020, Vol. 12562, p. 69-87Conference paper, Published paper (Refereed)
Abstract [en]
Integrating security into agile software development is an open issue for research and practice. Especially in strongly regulated industries, complexity increases not only when scaling agile practices but also when aiming for compliance with security standards. To achieve security compliance in a large-scale agile context, we developed S2C-SAFe: An extension of the Scaled Agile Framework that is compliant to the security standard IEC 62443-4-1 for secure product development. In this paper, we present the framework and its evaluation by agile and security experts within Siemens’ large-scale project ecosystem. We discuss benefits and limitations as well as challenges from a practitioners’ perspective. Our results indicate that S2C-SAFe contributes to successfully integrating security compliance with lean and agile development in regulated environments. We also hope to raise awareness for the importance and challenges of integrating security in the scope of Continuous Software Engineering. © 2020, Springer Nature Switzerland AG.
Place, publisher, year, edition, pages
Springer Science+Business Media B.V., 2020. Vol. 12562, p. 69-87
Series
Lecture Notes in Computer Science , ISSN 03029743, E-ISSN 16113349
Keywords [en]
Scaled Agile Framework, Secure software engineering, Security standards, Process engineering, Public utilities, Regulatory compliance, Agile development, Agile software development, Agile software engineering, Continuous software engineerings, Integrating security, Large-scale projects, Security compliance, Software design
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:bth-20884DOI: 10.1007/978-3-030-64148-1_5ISI: 000766320200005Scopus ID: 2-s2.0-85097649050ISBN: 9783030641474 (print)OAI: oai:DiVA.org:bth-20884DiVA, id: diva2:1514357
Conference
21st International Conference on Product-Focused Software Process Improvement, PROFES 2020, Turin, Italy, 25 November 2020 through 27 November 2020
Part of project
SERT- Software Engineering ReThought, Knowledge Foundation2021-01-052021-01-052023-01-02Bibliographically approved