Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Towards Automated Continuous Security Compliance
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.ORCID iD: 0000-0001-7903-8236
Fortiss, Germany.
Siemens Technology, Germany.
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.ORCID iD: 0000-0003-0619-6027
2024 (English)In: Proceedings of the 18th ACM/IEEE international symposium on empirical software engineering and measurement, ESEM 2024, IEEE Computer Society, 2024, p. 440-446Conference paper, Published paper (Refereed)
Abstract [en]

Context: Continuous Software Engineering is increasingly adopted in highly regulated domains, raising the need for continuous compliance. Adherence to especially security regulations - a major concern in highly regulated domains - renders Continuous Security Compliance of high relevance to industry and research.

Problem: One key barrier to adopting continuous software engineering in the industry is the resource-intensive and error-prone nature of traditional manual security compliance activities. Automation promises to be advantageous. However, continuous security compliance is under-researched, precluding an effective adoption.

Contribution: We have initiated a long-term research project with our industry partner to address these issues. In this manuscript, we make three contributions: (1) We provide a precise definition of the term continuous security compliance aligning with the state-of-art, (2) elaborate a preliminary overview of challenges in the field of automated continuous security compliance through a tertiary literature study, and (3) present a research roadmap to address those challenges via automated continuous security compliance. 

Place, publisher, year, edition, pages
IEEE Computer Society, 2024. p. 440-446
Series
International Symposium on Empirical Software Engineering and Measurement, ISSN 1949-3770, E-ISSN 1949-3789
Keywords [en]
Continuous Compliance, Continuous Security Compliance, Continuous Software Engineering, Security Challenges, Security Compliance, Continuous software engineerings, Error prones, Literature studies, Precise definition, Security regulations, Industrial research
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:bth-27254DOI: 10.1145/3674805.3690748ISI: 001537915200042Scopus ID: 2-s2.0-85210589352ISBN: 9798400710476 (print)OAI: oai:DiVA.org:bth-27254DiVA, id: diva2:1922042
Conference
18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement, ESEM 2024, Barcelona, Oct 24-25, 2024
Available from: 2024-12-17 Created: 2024-12-17 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

fulltext(656 kB)10 downloads
File information
File name FULLTEXT01.pdfFile size 656 kBChecksum SHA-512
ca3253e5147b724dc87c7204b2f841d05bc7210041d9e9cce47ac4520a715a0afaca5785313cfe4dc9948261abd3ff7901125740397f2e796dcd14dd1bca4b98
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Authority records

Angermeir, FlorianMendez, Daniel

Search in DiVA

By author/editor
Angermeir, FlorianMendez, Daniel
By organisation
Department of Software Engineering
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 10 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 110 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf