Aligning security objectives with agile software development

Aligning security objectives with agile software development
复制标题

将安全目标与敏捷软件开发保持一致

DOI:
--
复制
发表时间:
2018
期刊:
XP Companion
影响因子:
--
通讯作者:
Ville Leppänen
Ville Leppänen
中科院分区:
--
文献类型:
--
作者:
Kalle Rindell;Sami Hyrynsalmi;Ville Leppänen

文献摘要

被引文献

相似文献

软件开发过程的成功取决于其将业务目标转换为需求,并进一步转换为特性和功能的能力。除了业务目标之外,软件开发还有需要安全工程活动的安全目标。与迭代和增量软件开发过程不同,软件安全工程是由顺序生命周期模型定义的:因此,安全和业务目标是使用相互冲突的方法来实现的。为了识别方法之间的不兼容性,在本研究中,安全工程活动被映射到常见的敏捷软件开发实践、过程和构件中。Microsoft SDL、ISO Common Criteria和OWASP SAMM安全开发生命周期模型中的安全工程活动被映射到常见的敏捷流程、实践和构件中。映射的组织和技术方面主要是从实现为软件工程过程设定的安全目标的角度考虑的:为设计、实现和验证设定安全要求,并通过高效的软件安全开发过程发布安全软件。
Success of software development process is defined by its ability to transform the business objectives into requirements, and further into features and functionality. In addition to business objectives, software development also has security objectives requiring security engineering activities. In contrast to the iterative and incremental software development process, software security engineering is defined by sequential life cycle models: security and business objectives are thus implemented using conflicting approaches. To identify the incompatibilities between the methodologies, in this study the security engineering activities are mapped into common agile software development practises, processes and artifacts. Security engineering activities from Microsoft SDL, the ISO Common Criteria and OWASP SAMM security development lifecycle models are mapped into common agile processes, practises and artifacts. The organizational and technical aspects of the mapping are considered primarily from the point of view of achieving the security objectives set for the software engineering process: setting security requirements for design, their implementation and verification, and releasing secure software through efficient software security development process.