How to Integrate Security Compliance Requirements with Agile Software Engineering at Scale?

05/27/2021
by   Fabiola Moyón, et al.
0

Integrating security into agile software development is an open issue for research and practice. Especially in strongly regulated industries, complexity increases not only when scaling agile practices but also when aiming for compliance with security standards. To achieve security compliance in a large-scale agile context, we developed S2C-SAFe: An extension of the Scaled Agile Framework that is compliant to the security standard IEC 62443-4-1 for secure product development. In this paper, we present the framework and its evaluation by agile and security experts within Siemens' large-scale project ecosystem. We discuss benefits and limitations as well as challenges from a practitioners' perspective. Our results indicate that contributes to successfully integrating security compliance with lean and agile development in regulated environments. We also hope to raise awareness for the importance and challenges of integrating security in the scope of Continuous Software Engineering.

READ FULL TEXT

page 6

page 10

research
11/28/2019

Challenges of Scaled Agile for Safety-Critical Systems

Automotive companies increasingly adopt scaled agile methods to allow th...
research
03/02/2021

Compliance Requirements in Large-Scale Software Development: An Industrial Case Study

Regulatory compliance is a well-studied area, including research on how ...
research
06/27/2019

An Approach for Reviewing Security-Related Aspects in Agile Requirements Specifications of Web Applications

Defects in requirements specifications can have severe consequences duri...
research
11/23/2021

Using DevOps Toolchains in Agile Model-Driven Engineering

For Model-Driven Engineering (MDE) to become Agile, it is has to be usab...
research
09/06/2020

An Efficient Approach for Reviewing Security-Related Aspects in Agile Requirements Specifications of Web Applications

Defects in requirements specifications can have severe consequences duri...
research
12/11/2020

DevOps A Historical Review and Future Works

DevOps is an emerging practice to be followed in Software Development li...
research
09/14/2023

From Compliance to Impact: Tracing the Transformation of an Organizational Security Awareness Program

There is a growing recognition of the need for a transformation from org...

Please sign up or login with your details

Forgot password? Click here to reset