{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T04:14:22Z","timestamp":1759032862705,"version":"3.41.2"},"reference-count":50,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2019,6,17]],"date-time":"2019-06-17T00:00:00Z","timestamp":1560729600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ICS"],"published-print":{"date-parts":[[2019,9,23]]},"abstract":"<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title>\n<jats:p>Today, agile software development teams in general do not adopt security risk-assessment practices in an ongoing manner to prioritize security work. Protection Poker is a collaborative and lightweight software security risk-estimation technique that is particularly suited for agile teams. Motivated by a desire to understand why security risk assessments have not yet gained widespread adoption in agile development, this study aims to assess to what extent the Protection Poker game would be accepted by agile teams and how it can be successfully integrated into the agile practices.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title>\n<jats:p>Protection Poker was studied in capstone projects, in teams doing a graduate software security course and in sessions with industry representatives. Data were collected via questionnaires, observations and group interviews.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Findings<\/jats:title>\n<jats:p>Results show that Protection Poker has the potential to be adopted by agile teams. Key benefits include good discussions on security and the development project, along with increased knowledge and awareness. Challenges include ensuring efficient use of time and gaining impact on the end product.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Research limitations\/implications<\/jats:title>\n<jats:p>Using students allowed easy access to subjects and an ability to collect rich data over time, but at the cost of generalizability to professional settings. Results from interactions with professionals supplement the data from students, showing similarities and differences in their opinions on Protection Poker.<\/jats:p>\n<\/jats:sec>\n<jats:sec>\n<jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title>\n<jats:p>The paper proposes ways to tackle the main obstacles to the adoption of the Protection Poker technique, as identified in this study.<\/jats:p>\n<\/jats:sec>","DOI":"10.1108\/ics-12-2018-0138","type":"journal-article","created":{"date-parts":[[2019,6,17]],"date-time":"2019-06-17T09:35:42Z","timestamp":1560764142000},"page":"508-535","source":"Crossref","is-referenced-by-count":14,"title":["Collaborative security risk estimation in agile software development"],"prefix":"10.1108","volume":"27","author":[{"given":"Inger Anne","family":"T\u00f8ndel","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin Gilje","family":"Jaatun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniela Soares","family":"Cruzes","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","published-online":{"date-parts":[[2019,6,17]]},"reference":[{"volume-title":"Understanding Attitudes and Predicting Social Behaviour","year":"1980","key":"key2021102014190899100_ref001"},{"article-title":"Quality requirements in large-scale distributed agile projects \u2013 a systematic literature review","volume-title":"International Working Conference on Requirements Engineering: Foundation for Software Quality","year":"2017","key":"key2021102014190899100_ref002"},{"article-title":"A novel security-enhanced agile software development process applied in an industrial setting","volume-title":"2015 10th International Conference on Availability, Reliability and Security (ARES)","year":"2015","key":"key2021102014190899100_ref003"},{"key":"key2021102014190899100_ref004","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1109\/ARES.2015.45","article-title":"A novel Security-Enhanced agile software development process applied in an industrial setting","volume-title":"2015 10th International Conference on Availability, Reliability and Security","year":"2015"},{"year":"2001","key":"key2021102014190899100_ref005","article-title":"Manifesto for agile software development"},{"year":"2007","key":"key2021102014190899100_ref006","article-title":"OCTAVE allegro: improving the information security risk assessment process (CMU\/SEI-2007-TR-012 ESC-TR-2007-012)"},{"year":"2015","key":"key2021102014190899100_ref047","article-title":"Fun Retrospectives \u2013 Activities and ideas for making agile retrospectives more engaging"},{"year":"2008","key":"key2021102014190899100_ref007","article-title":"Software assurance maturity model"},{"article-title":"Challenges and experiences with applying Microsoft threat modeling in agile development projects","volume-title":"Australasian Software Engineering Conference (ASWEC)","year":"2018","key":"key2021102014190899100_ref008"},{"first-page":"5","article-title":"Why Johnny can't evaluate security risk","year":"2006","key":"key2021102014190899100_ref009"},{"volume-title":"A Technology Acceptance Model for Empirically Testing New End-User Information Systems: Theory and Results","year":"1985","key":"key2021102014190899100_ref010"},{"issue":"3","key":"key2021102014190899100_ref011","doi-asserted-by":"publisher","first-page":"319","DOI":"10.2307\/249008","article-title":"Perceived usefulness, perceived ease of use, and user acceptance of information technology","volume":"13","year":"1989","journal-title":"MIS Quarterly"},{"year":"2017","key":"key2021102014190899100_ref012","article-title":"Software assurance maturity model \u2013 how to guide \u2013 a guide to building security into software development"},{"issue":"1","key":"key2021102014190899100_ref013","doi-asserted-by":"crossref","first-page":"490","DOI":"10.1007\/s10664-017-9524-2","article-title":"Exploring software development at the very large-scale: a revelatory case study and research agenda for agile method adaptation","volume":"23","year":"2018","journal-title":"Empirical Software Engineering"},{"first-page":"58","article-title":"Verification, validation, and evaluation in information security risk management","year":"2010","key":"key2021102014190899100_ref014"},{"issue":"6","key":"key2021102014190899100_ref015","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1109\/MC.2010.159","article-title":"Are companies actually using secure development life cycles?","volume":"43","year":"2010","journal-title":"Computer"},{"key":"key2021102014190899100_ref016","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.cose.2004.11.002","article-title":"Management of risk in the information age","volume":"24","year":"2005","journal-title":"Computers and Security"},{"key":"key2021102014190899100_ref017","first-page":"22","article-title":"Planning poker or how to avoid analysis paralysis while release planning","volume":"3","year":"2002","journal-title":"Hawthorn Woods: Renaissance Software Consulting"},{"issue":"3","key":"key2021102014190899100_ref018a","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1023\/A:1026586415054","article-title":"Using students as subjects \u2013 a comparative study of students and professionals in lead-time impact assessment","volume":"5","year":"2000","journal-title":"Empirical Software Engineering"},{"volume-title":"The Security Development Lifecycle: Process for Developing Demonstrably More Secure Software","year":"2006","key":"key2021102014190899100_ref018"},{"article-title":"ISO\/IEC 27005: 2011 Information technology\u2013security techniques\u2013information security risk management","year":"2011","author":"ISO\/IEC","key":"key2021102014190899100_ref019"},{"article-title":"Covering your assets in software engineering","volume-title":"The Third International Conference on Availability, Reliability and Security","year":"2008","key":"key2021102014190899100_ref021"},{"article-title":"Playing protection poker for practical software security","volume-title":"International Conference on Product-Focused Software Process Improvement","year":"2016","key":"key2021102014190899100_ref020"},{"first-page":"120","article-title":"Software security maturity in public organisations","year":"2015","key":"key2021102014190899100_ref022a"},{"key":"key2021102014190899100_ref022","first-page":"10","article-title":"An investigation of organizational information security risk analysis","volume":"3","year":"2010","journal-title":"Journal of Service Science"},{"journal-title":"International Journal of Computer and Systems Engineering","article-title":"A review on factors influencing implementation of secure software development practices. 10","year":"2016","key":"key2021102014190899100_ref023"},{"issue":"3","key":"key2021102014190899100_ref024","doi-asserted-by":"crossref","first-page":"49","DOI":"10.5121\/ijsea.2016.7304","article-title":"A review of security integration technique in agile software development","volume":"7","year":"2016","journal-title":"International Journal of Software Engineering Applications"},{"article-title":"A critical review of technology acceptance literature","volume-title":"Southwest Decision Sciences Institute Conference","year":"2010","key":"key2021102014190899100_ref025"},{"key":"key2021102014190899100_ref026","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1109\/MSECP.2004.1281254","article-title":"Software security","volume":"2","year":"2004","journal-title":"IEEE Security and Privacy Magazine"},{"volume-title":"Software Security: Building Security In","year":"2006","key":"key2021102014190899100_ref027"},{"year":"2016","key":"key2021102014190899100_ref028","article-title":"Building security in maturity model (BSIMM7)"},{"key":"key2021102014190899100_ref029","unstructured":"MICROSOFT (2012), \u201cSecurity development lifecycle for agile development\u201d, available at: https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ee790621.aspx"},{"article-title":"Guide for applying the risk management framework to federal information systems \u2013 a security life cycle approach","year":"2010","author":"NIST","key":"key2021102014190899100_ref030"},{"article-title":"Integrating risk management with software development: state of practice","volume-title":"International MultiConference of Engineers and Computer Scientists","year":"2008","key":"key2021102014190899100_ref031"},{"issue":"3","key":"key2021102014190899100_ref032","first-page":"823","article-title":"Agile risk management using software agents","year":"2018","journal-title":"Journal of Ambient Intelligence and Humanized Computing"},{"article-title":"Literature review of the challenges of developing secure software using the agile approach","volume-title":"2015 10th International Conference on Availability, Reliability and Security (ARES)","year":"2015","key":"key2021102014190899100_ref033"},{"key":"key2021102014190899100_ref034","doi-asserted-by":"crossref","first-page":"221","DOI":"10.1016\/j.cose.2011.12.001","article-title":"Unrealistic optimism on information security management","volume":"31","year":"2012","journal-title":"Computers and Security"},{"key":"key2021102014190899100_ref035","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1145\/2460999.2461013","article-title":"A review of research on risk analysis methods for IT systems","volume-title":"Proceedings of the 17th International Conference on Evaluation and Assessment in Software Engineering","year":"2013"},{"first-page":"288","article-title":"Using students as subjects-an empirical evaluation","year":"2008","key":"key2021102014190899100_ref036a"},{"issue":"5","key":"key2021102014190899100_ref036","article-title":"Risk management analysis in scrum software projects","volume":"26","year":"2017","journal-title":"International Transactions in Operational Research"},{"article-title":"Agile practitioners\u2019 understanding of security requirements: insights from a grounded theory analysis","volume-title":"2017 IEEE 25th International Requirements Engineering Conference Workshops (REW)","year":"2017","key":"key2021102014190899100_ref037"},{"year":"2018","key":"key2021102014190899100_ref038","article-title":"Results from questionnaires on protection poker"},{"issue":"4","key":"key2021102014190899100_ref040","doi-asserted-by":"crossref","first-page":"1","DOI":"10.4018\/IJSSE.2017100101","article-title":"Risk centric activities in secure software development in public organisations","volume":"8","year":"2017","journal-title":"International Journal of Secure Software Engineering"},{"article-title":"Understanding challenges to adoption of the protection poker software security game","volume-title":"2nd International Workshop on SECurity and Privacy Requirements Engineering (SECPRE 2018)","year":"2018","key":"key2021102014190899100_ref041"},{"article-title":"Assessing information security risks of AMI: What makes it so difficult?","volume-title":"1st International conference on Information Systems Security and Privacy 2015","year":"2015","key":"key2021102014190899100_ref039"},{"article-title":"Managing security work in scrum: tensions and challenges","volume-title":"International Workshop on Secure Software Engineering in DevOps and Agile Development","year":"2017","key":"key2021102014190899100_ref042"},{"issue":"3","key":"key2021102014190899100_ref043","doi-asserted-by":"crossref","first-page":"451","DOI":"10.1111\/j.1540-5915.1996.tb01822.x","article-title":"A model of the antecedents of perceived ease of use: Development and test","volume":"27","year":"1996","journal-title":"Decision Sciences"},{"article-title":"Protection poker: Structuring software security risk assessment and knowledge transfer","volume-title":"International Symposium on Engineering Secure Software and Systems","year":"2009","key":"key2021102014190899100_ref044"},{"issue":"5","key":"key2021102014190899100_ref045","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1109\/MS.2018.290110854","article-title":"Engineering security vulnerability prevention, detection and response","volume":"35","year":"2018","journal-title":"IEEE Software"},{"issue":"3","key":"key2021102014190899100_ref046","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/MSP.2010.58","article-title":"Protection poker: the new software security game","volume":"8","year":"2010","journal-title":"IEEE Security and Privacy Magazine"}],"container-title":["Information &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-12-2018-0138\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ICS-12-2018-0138\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T01:23:26Z","timestamp":1753406606000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/27\/4\/508-535\/190414"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6,17]]},"references-count":50,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2019,6,17]]},"published-print":{"date-parts":[[2019,9,23]]}},"alternative-id":["10.1108\/ICS-12-2018-0138"],"URL":"https:\/\/doi.org\/10.1108\/ics-12-2018-0138","relation":{},"ISSN":["2056-4961","2056-4961"],"issn-type":[{"type":"print","value":"2056-4961"},{"type":"print","value":"2056-4961"}],"subject":[],"published":{"date-parts":[[2019,6,17]]}}}