Vis enkel innførsel

dc.contributor.authorTøndel, Inger Anne
dc.contributor.authorCruzes, Daniela Soares
dc.contributor.authorJAATUN, Martin Gilje
dc.contributor.authorSindre, Guttorm
dc.date.accessioned2023-03-02T16:27:34Z
dc.date.available2023-03-02T16:27:34Z
dc.date.created2022-05-11T12:33:55Z
dc.date.issued2022
dc.identifier.citationComputers & Security. 2022, 118, 102744.en_US
dc.identifier.issn0167-4048
dc.identifier.urihttps://hdl.handle.net/11250/3055550
dc.description.abstractSoftware security is a complex topic, and for development projects it can be challenging to assess what security is necessary and cost-effective. Agile Software Development (ASD) values self-management. Thus, teams and their Product Owners are expected to also manage software security prioritisation. In this paper we build on the notion that security experts who want to influence the priority given to security in ASD need to do this through interactions and support for teams rather than prescribing certain activities or priorities. But to do this effectively, there is a need to understand what hinders and supports teams in prioritising security. Based on a longitudinal case study, this article offers insight into the strategy used by one security professional in an SME to influence the priority of security in software development projects in the company. The main result is a model of influences on security prioritisation that can assist in understanding what supports or hinders the prioritisation of security in ASD, thus providing recommendations for security professionals. Two alternative strategies are outlined for software security in ASD – prescribed and emerging – where we hypothesise that an emerging approach can be more relevant for SMEs doing ASD, and that this can impact how such companies should consider software security maturity.en_US
dc.language.isoengen_US
dc.publisherElsevieren_US
dc.rightsNavngivelse 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/deed.no*
dc.titleInfluencing the security prioritisation of an agile software development projecten_US
dc.typePeer revieweden_US
dc.typeJournal articleen_US
dc.description.versionpublishedVersionen_US
dc.rights.holder© 2022 The Authors.en_US
dc.source.pagenumber19en_US
dc.source.volume118en_US
dc.source.journalComputers & Securityen_US
dc.identifier.doi10.1016/j.cose.2022.102744
dc.identifier.cristin2023480
dc.relation.projectNorges forskningsråd: 247678en_US
dc.source.articlenumber102744en_US
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Navngivelse 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Navngivelse 4.0 Internasjonal