首页> 外文会议>IEEE International Conference on Technology Management, Operations and Decisions >Reframing Security in Contemporary Software Development Life Cycle
【24h】

Reframing Security in Contemporary Software Development Life Cycle

机译:在当代软件开发生命周期中重新定义安全性

获取原文

摘要

The purpose of the current paper is to gain insight in the manner in which security is taken into account when building information systems. In particular by comparing the concepts of Agile Scrum and DevOps, along the phases of the Software Development Life Cycle (SDLC), using Open Software Assurance Maturity Model as a measure, and the Lucky Clover Model to address the soft- and hard factors, in terms of Content, Process, Relation and Culture, which lead to a new framework. The initial results based on desk research confirm the general notion of there is limited coverage of security in such frameworks. There is only partial coverage of security in the DevOps approach and does so primarily in the later stages of the SDLC, and it also embraces cultural aspects more. Cultural aspects relating to shared value and behavioral aspects are not operationalized. Given the impact of security in the ever digitalizing society nowadays, the recommendation is that security is not just a feature but should be an inherent part of the iterative software development approach starting with the Minimal Viable Product version. Hence security by design is embraced by the team. Secondly, security is not only a technical nor procedural issue. Hence it is not only the hard controls (Content and Process) that should be taken into account. Also, soft controls (Relations and Culture) should be in managerially addressed in a balanced manner.
机译:本文的目的是了解在构建信息系统时考虑安全性的方式。特别是,通过在软件开发生命周期(SDLC)的各个阶段比较敏捷Scrum和DevOps的概念,使用开放软件保证成熟度模型作为度量,并使用Lucky Clover模型来解决软硬因素,内容,流程,关系和文化方面的条款,从而形成了一个新的框架。基于案头研究的初步结果证实了这样一种框架的普遍概念:安全性覆盖范围有限。 DevOps方法仅部分覆盖安全性,并且主要在SDLC的后期阶段进行,而且还包含更多文化方面的内容。与共享价值和行为方面有关的文化方面尚未实施。考虑到安全性在当今不断数字化的社会中的影响,建议安全性不仅是功能,而且应该是从最小可行产品版本开始的迭代软件开发方法的固有部分。因此,团队接受设计的安全性。其次,安全不仅是技术问题,也不是程序问题。因此,不仅应该考虑硬控制(内容和过程)。另外,应该以一种平衡的方式在管理上处理软控制(关系和文化)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号