• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Managing security work in scrum: Tensions and challenges
 
  • Details
  • Full
Options
2017
Conference Paper
Title

Managing security work in scrum: Tensions and challenges

Abstract
We advocate a change of perspective in the question of agile secure software development and analyze what makes it difficult to address security needs in Scrum. The literature focuses on the integration of security activities into agile development processes. However, detailed prescriptions for security work would be misplaced in a generic management framework like Scrum. Therefore we take a closer look at the tensions between Scrums way of organizing work and the characteristics of security requirements. Our previous work suggests that Scrum works well as a management model and security development requires iterations as in agile development, yet Scrum teams can fail to address security needs due to their low visibility, competing objectives, and Scrums division of labor. Tensions ar ise as Scrum is optimized to fulfill explicit requirements and maximize business value, whereas security is often an implicit requirement with a different value proposition, which nevertheless requires substantial work and cannot be addressed by bug fixing or quality assurance alone. As a consequence, promising research directions are the reflective discovery of security needs, the valuation and prioritization of security work, collaboration between Scrum teams and security experts, and verification and feedback mechanisms for security.
Author(s)
Türpe, Sven
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Poller, Andreas
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Mainwork
SecSE 2017, International Workshop on Secure Software Engineering in DevOps and Agile Development. Proceedings. Online resource  
Conference
International Workshop on Secure Software Engineering in DevOps and Agile Development (SecSE) 2017  
European Symposium on Research in Computer Security (ESORICS) 2017  
File(s)
Download (205.36 KB)
Rights
Use according to copyright law
DOI
10.24406/publica-fhg-398272
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Keyword(s)
  • Scrum

  • security requirements

  • security work

  • management

  • agile development

  • software security

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024