Skip to main navigation Skip to search Skip to main content

Security Compliance in Agile Software Development: A Systematic Mapping Study

  • Fabiola Moyon
  • , Pamela Almeida
  • , Daniel Riofrio
  • , Daniel Mendez
  • , Marcos Kalinowski
  • Technical University of Munich
  • Universidad San Francisco de Quito
  • Blekinge Institute of Technology
  • Pontifícia Universidade Católica do Rio de Janeiro

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

23 Scopus citations

Abstract

Companies adopting agile development tend to face challenges in complying with security norms. Existing research either focuses on how to integrate security into agile methods or on discussing compliance issues of agile methods but independently of the regulation type, in particular of security standards. A comprehensive overview of this scattered field is still missing and we know little about how to achieve security compliance in agile software development. Existing secondary studies (mapping studies and literature reviews) analyze publications on secure agile development, but they do not analyze implications of security standard compliance, e.g., integration of specific standard requirements or compliance assessments. To close this gap, we report on a systematic mapping study. Starting with a set of 2,383 papers, our work distills 11 relevant publications addressing security compliance in agile software development. With this study, we contribute by describing the maturity of the field, as well as domains where security compliant agile software engineering was investigated. Moreover, we make explicit which phases of a secure development process are covered by the field and which agile principles are analyzed when aiming at compliance with international security standards, country-specific security regulations, industry-specific security standards, and other well-known security frameworks.

Original languageEnglish
Title of host publicationProceedings - 46th Euromicro Conference on Software Engineering and Advanced Applications, SEAA 2020
EditorsAntonio Martini, Manuel Wimmer, Amund Skavhaug
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages413-420
Number of pages8
ISBN (Electronic)9781728195322
DOIs
StatePublished - Aug 2020
Event46th Euromicro Conference on Software Engineering and Advanced Applications, SEAA 2020 - Kranj, Slovenia
Duration: 26 Aug 202028 Aug 2020

Publication series

NameProceedings - 46th Euromicro Conference on Software Engineering and Advanced Applications, SEAA 2020

Conference

Conference46th Euromicro Conference on Software Engineering and Advanced Applications, SEAA 2020
Country/TerritorySlovenia
CityKranj
Period26/08/2028/08/20

Keywords

  • Agile Software Engineering
  • Secure Software Engineering
  • Security Compliance
  • Systematic Mapping Study

Fingerprint

Dive into the research topics of 'Security Compliance in Agile Software Development: A Systematic Mapping Study'. Together they form a unique fingerprint.

Cite this