Towards Automated Continuous Security Compliance
2024 (English)In: Proceedings of the 18th ACM/IEEE international symposium on empirical software engineering and measurement, ESEM 2024, IEEE Computer Society, 2024, p. 440-446Conference paper, Published paper (Refereed)
Abstract [en]
Context: Continuous Software Engineering is increasingly adopted in highly regulated domains, raising the need for continuous compliance. Adherence to especially security regulations - a major concern in highly regulated domains - renders Continuous Security Compliance of high relevance to industry and research.
Problem: One key barrier to adopting continuous software engineering in the industry is the resource-intensive and error-prone nature of traditional manual security compliance activities. Automation promises to be advantageous. However, continuous security compliance is under-researched, precluding an effective adoption.
Contribution: We have initiated a long-term research project with our industry partner to address these issues. In this manuscript, we make three contributions: (1) We provide a precise definition of the term continuous security compliance aligning with the state-of-art, (2) elaborate a preliminary overview of challenges in the field of automated continuous security compliance through a tertiary literature study, and (3) present a research roadmap to address those challenges via automated continuous security compliance.
Place, publisher, year, edition, pages
IEEE Computer Society, 2024. p. 440-446
Series
International Symposium on Empirical Software Engineering and Measurement, ISSN 1949-3770, E-ISSN 1949-3789
Keywords [en]
Continuous Compliance, Continuous Security Compliance, Continuous Software Engineering, Security Challenges, Security Compliance, Continuous software engineerings, Error prones, Literature studies, Precise definition, Security regulations, Industrial research
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:bth-27254DOI: 10.1145/3674805.3690748ISI: 001537915200042Scopus ID: 2-s2.0-85210589352ISBN: 9798400710476 (print)OAI: oai:DiVA.org:bth-27254DiVA, id: diva2:1922042
Conference
18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement, ESEM 2024, Barcelona, Oct 24-25, 2024
2024-12-172024-12-172025-09-30Bibliographically approved