...
首页> 外文期刊>International journal of secure software engineering >A Lightweight Measurement of Software Security Skills, Usage and Training Needs in Agile Teams
【24h】

A Lightweight Measurement of Software Security Skills, Usage and Training Needs in Agile Teams

机译:轻量级衡量敏捷团队中软件安全技能,使用和培训需求的方法

获取原文
获取原文并翻译 | 示例
           

摘要

Although most organizations understand the need for application security at an abstract level, achieving adequate software security at the sharp end requires taking bold steps to address security practices within the organization. In the Agile software development world, a security engineering process is unacceptable if it is perceived to run counter to the agile values, and agile teams have thus approached software security activities in their own way. To improve security within agile settings requires that management understands the current practices of software security activities within their agile teams. In this study, the authors have used a survey instrument to investigate software security usage, competence, and training needs in two agile organizations. They find that (1) The two organizations perform differently in terms of core software security activities, but are similar when secondary activities that could be leveraged for security are considered (2) regardless of cost or benefit, skill drives the kind of activities that are performed (3) Secure design is expressed as the most important training need by all groups in both organizations (4) Effective software security adoption in agile setting is not automatic, it requires a driver.
机译:尽管大多数组织从抽象的角度理解了应用程序安全性的需求,但要在前端获得足够的软件安全性,则需要采取大胆的步骤来解决组织内部的安全性实践。在敏捷软件开发世界中,如果认为安全工程过程与敏捷价值背道而驰,那么安全工程过程是不可接受的,因此敏捷团队已经以自己的方式进行了软件安全活动。为了提高敏捷设置中的安全性,管理层需要了解其敏捷团队中软件安全活动的当前实践。在这项研究中,作者使用了一种调查工具来调查两个敏捷组织中的软件安全使用,能力和培训需求。他们发现(1)这两个组织在核心软件安全活动方面的执行方式不同,但是在考虑可以利用安全性进行的次要活动时,这两个组织是相似的(2)不论成本或收益如何,技能决定了活动的类型。已执行(3)安全设计被表示为两个组织中所有团队的最重要培训需求。(4)在敏捷环境中有效采用软件安全并不是自动的,它需要驱动程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号