Vis enkel innførsel

dc.contributor.authorOyetoyan, Tosin Daniel
dc.contributor.authorMilosheska, Bisera
dc.contributor.authorGrini, Mari
dc.contributor.authorCruzes, Daniela Soares
dc.date.accessioned2018-06-11T12:12:36Z
dc.date.available2018-06-11T12:12:36Z
dc.date.created2018-06-07T10:58:46Z
dc.date.issued2018
dc.identifier.citationAgile Processes in Software Engineering and Extreme Programming, 19th International Conference, XP 2018, Proceedings, 86-103nb_NO
dc.identifier.isbn978-3-319-91601-9
dc.identifier.urihttp://hdl.handle.net/11250/2501153
dc.description.abstractIt is claimed that integrating agile and security in practice is challenging. There is the notion that security is a heavy process, requires expertise, and consumes developers’ time. These contrast with the agile vision. Regardless of these challenges, it is important for organizations to address security within their agile processes since critical assets must be protected against attacks. One way is to integrate tools that could help to identify security weaknesses during implementation and suggest methods to refactor them. We used quantitative and qualitative approaches to investigate the efficiency of the tools and what they mean to the actual users (i.e. developers) at Telenor Digital. Our findings, although not surprising, show that several barriers exist both in terms of tool’s performance and developers’ perceptions. We suggest practical ways for improvement.nb_NO
dc.language.isoengnb_NO
dc.relation.ispartofAgile Processes in Software Engineering and Extreme Programming, 19th International Conference, XP 2018, Proceedings
dc.rightsNavngivelse 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/deed.no*
dc.titleMyths and Facts About Static Application Security Testing Tools: An Action Research at Telenor Digitalnb_NO
dc.typeChapternb_NO
dc.description.versionpublishedVersionnb_NO
dc.source.pagenumber86-103nb_NO
dc.identifier.cristin1589634
dc.relation.projectNorges forskningsråd: 247678nb_NO
cristin.unitcode7401,90,13,0
cristin.unitnameSystemutvikling og sikkerhet
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Navngivelse 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Navngivelse 4.0 Internasjonal