Vis enkel innførsel

dc.contributor.authorNicolaysen, Torstein
dc.contributor.authorSassoon, Richard
dc.contributor.authorBartnes, Maria
dc.contributor.authorJaatun, Martin Gilje
dc.date.accessioned2018-04-26T07:14:35Z
dc.date.available2018-04-26T07:14:35Z
dc.date.created2017-02-16T10:00:11Z
dc.date.issued2010
dc.identifier.citationInternational Journal of Secure Software Engineering. 2010, 1 (3), 71-85.nb_NO
dc.identifier.issn1947-3036
dc.identifier.urihttp://hdl.handle.net/11250/2496035
dc.description.abstractIn this article, we contrast the results of a series of interviews with agile software development organizations with a case study of a distributed agile development effort, focusing on how information security is taken care of in an agile context. The interviews indicate that small and medium-sized agile software development organizations do not use any particular methodology to achieve security goals, even when their software is web-facing and potential targets of attack, and our case study confirms that even in cases where security is an articulated requirement, and where security design is fed as input to the implementation team, there is no guarantee that the end result meets the security objectives. We contend that security must be built as an intrinsic software property and emphasize the need for security awareness throughout the whole software development lifecycle. We suggest two extensions to agile methodologies that may contribute to ensuring focus on security during the complete lifecyclenb_NO
dc.language.isoengnb_NO
dc.publisherIGI Globalnb_NO
dc.titleAgile Software Development: The Straight and Narrow Path to Secure Software?nb_NO
dc.typeJournal articlenb_NO
dc.typePeer reviewednb_NO
dc.description.versionpublishedVersionnb_NO
dc.source.pagenumber71-85nb_NO
dc.source.volume1nb_NO
dc.source.journalInternational Journal of Secure Software Engineeringnb_NO
dc.source.issue3nb_NO
dc.identifier.doi10.4018/jsse.2010070105
dc.identifier.cristin1451123
dc.description.localcodeCopyright © 2010, IGI Global.nb_NO
cristin.unitcode194,0,0,0
cristin.unitnameNorges teknisk-naturvitenskapelige universitet
cristin.ispublishedtrue
cristin.fulltextpostprint
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel