{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T22:39:37Z","timestamp":1785537577617,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":24,"publisher":"ACM","license":[{"start":{"date-parts":[[2016,5,14]],"date-time":"2016-05-14T00:00:00Z","timestamp":1463184000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100009226","name":"National Security Agency","doi-asserted-by":"publisher","award":["2014-1267"],"award-info":[{"award-number":["2014-1267"]}],"id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2016,5,14]]},"DOI":"10.1145\/2896941.2896946","type":"proceedings-article","created":{"date-parts":[[2016,7,21]],"date-time":"2016-07-21T15:20:09Z","timestamp":1469114409000},"page":"70-76","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":63,"title":["Software security in DevOps"],"prefix":"10.1145","author":[{"given":"Akond Ashfaque","family":"Ur Rahman","sequence":"first","affiliation":[{"name":"North Carolina State University, Raleigh, NC"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, NC"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2016,5,14]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.82"},{"key":"e_1_3_2_1_2_1","volume-title":"Proc. of the 3rd International Workshop on Release Engineering","author":"Dyck A.","year":"2015","unstructured":"Dyck , A. , Penners , R. , and Licthter , H . 2015. Towards Definitions for Release Engineering and DevOps , in Proc. of the 3rd International Workshop on Release Engineering , Florence, Italy, pages 3- -3, May , 2015 Dyck, A., Penners, R., and Licthter, H. 2015. Towards Definitions for Release Engineering and DevOps, in Proc. of the 3rd International Workshop on Release Engineering, Florence, Italy, pages 3--3, May, 2015"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.23"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2013.25"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2006.147"},{"key":"e_1_3_2_1_6_1","volume-title":"1st Ed. Addison-Wesley","author":"Humble J.","year":"2011","unstructured":"Humble , J. , and Farley , D . 2011. Continuous Delivery , 1st Ed. Addison-Wesley , Boston, MA , 2011 Humble, J., and Farley, D. 2011. Continuous Delivery, 1st Ed. Addison-Wesley, Boston, MA, 2011"},{"key":"e_1_3_2_1_7_1","volume-title":"IEEE SA -- 24765 -- 2010 -- Systems and Software Engineering -- Vocabulary","author":"IEEE Standards Association","year":"2010","unstructured":"IEEE Standards Association . IEEE SA -- 24765 -- 2010 -- Systems and Software Engineering -- Vocabulary : 2010 . https:\/\/standards.ieee.org\/findstds\/standard\/24765-2010.html. Accessed : 2016-01-24 IEEE Standards Association. IEEE SA -- 24765 -- 2010 -- Systems and Software Engineering -- Vocabulary: 2010. https:\/\/standards.ieee.org\/findstds\/standard\/24765-2010.html. Accessed: 2016-01-24"},{"key":"e_1_3_2_1_8_1","volume-title":"Regulatory Compliance Demystified: An Introduction to Compliance for Developers","author":"Innovation S.","year":"2006","unstructured":"Innovation . S. Regulatory Compliance Demystified: An Introduction to Compliance for Developers : 2006 . Available: https:\/\/msdn.microsoft.com\/en-us\/library\/aa480484.aspx. Accessed: 2016-01-24 Innovation. S. Regulatory Compliance Demystified: An Introduction to Compliance for Developers: 2006. Available: https:\/\/msdn.microsoft.com\/en-us\/library\/aa480484.aspx. Accessed: 2016-01-24"},{"key":"e_1_3_2_1_9_1","volume-title":"Concepts and Definitions","author":"Software","year":"2013","unstructured":"ISO\/IEC\/IEEE. ISO\/IEC\/IEEE 29119:2013 Software and Systems Engineering-Software Testing-Part 1 : Concepts and Definitions : 2013 . http:\/\/www.iso.org\/iso\/catalogue_detail.htm?csnumber=4514 2. Accessed : 2016-01-24 ISO\/IEC\/IEEE. ISO\/IEC\/IEEE 29119:2013 Software and Systems Engineering-Software Testing-Part 1: Concepts and Definitions: 2013. http:\/\/www.iso.org\/iso\/catalogue_detail.htm?csnumber=4514 2. Accessed: 2016-01-24"},{"key":"e_1_3_2_1_10_1","volume-title":"2015 State of DevOps Report | Puppet Labs","author":"Labs P.","year":"2015","unstructured":"Labs , P. , and Revolution , IT . 2015 State of DevOps Report | Puppet Labs : 2015 . Available: https:\/\/puppetlabs.com\/sites\/default\/files\/2015-state-of-devops-report.pdf. Accessed: 2016-01-24 Labs, P., and Revolution, IT. 2015 State of DevOps Report | Puppet Labs: 2015. Available: https:\/\/puppetlabs.com\/sites\/default\/files\/2015-state-of-devops-report.pdf. Accessed: 2016-01-24"},{"key":"e_1_3_2_1_11_1","volume-title":"Archives of Psychology","volume":"22","author":"Likert R.","year":"1932","unstructured":"Likert , R. 1932 . A Technique for the Measurement of Attitudes , in Archives of Psychology , vol. 22 , no. 140, pages 5--55, June, 1932 Likert, R. 1932. A Technique for the Measurement of Attitudes, in Archives of Psychology, vol. 22, no. 140, pages 5--55, June, 1932"},{"key":"e_1_3_2_1_12_1","volume-title":"Software Security: Building Security In","author":"McGraw G.","year":"2006","unstructured":"McGraw , G. 2006 . Software Security: Building Security In , Addison-Wesley Professional , Cambridge, MA , 2006 McGraw, G. 2006. Software Security: Building Security In, Addison-Wesley Professional, Cambridge, MA, 2006"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2008.478"},{"key":"e_1_3_2_1_14_1","volume-title":"BSIMM 6: Building Security in Maturity Model","author":"McGraw G.","year":"2015","unstructured":"McGraw , G. , Migues , S. , and West J . BSIMM 6: Building Security in Maturity Model : 2015 . https:\/\/www.bsimm.com\/download\/. Accessed : 2016-01-24 McGraw, G., Migues, S., and West J. BSIMM 6: Building Security in Maturity Model: 2015. https:\/\/www.bsimm.com\/download\/. Accessed: 2016-01-24"},{"key":"e_1_3_2_1_15_1","volume-title":"Microsoft Secure Development Lifecycle Guidance","author":"Microsoft","year":"2012","unstructured":"Microsoft . Microsoft Secure Development Lifecycle Guidance : 2012 . https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=29884. Accessed : 2016-01-24 Microsoft. Microsoft Secure Development Lifecycle Guidance: 2012. https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=29884. Accessed: 2016-01-24"},{"key":"e_1_3_2_1_16_1","volume-title":"Crossing the Chasm: Marketing and Selling Technology Products to Mainstream Customers","author":"Moore G.","year":"2002","unstructured":"Moore , G. 2002. Crossing the Chasm: Marketing and Selling Technology Products to Mainstream Customers , Revised Ed., Collins Business Essentials, New York City, NY , 2002 Moore, G. 2002. Crossing the Chasm: Marketing and Selling Technology Products to Mainstream Customers, Revised Ed., Collins Business Essentials, New York City, NY, 2002"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.84"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/Agile.2015.12"},{"key":"e_1_3_2_1_19_1","volume-title":"Threat Modeling: Designing for Security","author":"Shostack A.","year":"2014","unstructured":"Shostack , A. 2014 . Threat Modeling: Designing for Security , John Wiley & Sons Inc ., Indianapolis, IN, 2014 Shostack, A. 2014. Threat Modeling: Designing for Security, John Wiley & Sons Inc., Indianapolis, IN, 2014"},{"key":"e_1_3_2_1_20_1","first-page":"1","volume-title":"ISSE 2014 Securing Electronic Business Processes","volume":"1","author":"Simpson S.","year":"2014","unstructured":"Simpson , S. 2014 . SAFECode Whitepaper: Fundamental Practices for Secure Software Development , in ISSE 2014 Securing Electronic Business Processes , vol. 1 , no. 1, pages 1 -- 32 , October, 2014 Simpson, S. 2014. SAFECode Whitepaper: Fundamental Practices for Secure Software Development, in ISSE 2014 Securing Electronic Business Processes, vol. 1, no. 1, pages 1--32, October, 2014"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-18612-2_14"},{"key":"e_1_3_2_1_22_1","volume-title":"DevOps: The Worst Kept Secret to Winning in the Application Economy","author":"Technologies CA.","year":"2014","unstructured":"Technologies , CA. DevOps: The Worst Kept Secret to Winning in the Application Economy : 2014 . http:\/\/www.ca.com\/us\/~\/media\/Files\/whitepapers\/devops-the-worst-kept-secret-to-winning-in-the-application-economy.pdf. Accessed : 2016-01-24 Technologies, CA. DevOps: The Worst Kept Secret to Winning in the Application Economy: 2014. http:\/\/www.ca.com\/us\/~\/media\/Files\/whitepapers\/devops-the-worst-kept-secret-to-winning-in-the-application-economy.pdf. Accessed: 2016-01-24"},{"key":"e_1_3_2_1_23_1","volume-title":"2012","author":"Turnbull J.","unstructured":"Turnbull , J. DevOps & Security : 2012 . http:\/\/www.slideshare.net\/jamtur01\/security-loves-devops-devops-days-austin-2012. Accessed: 2016-01-24 Turnbull, J. DevOps & Security: 2012. http:\/\/www.slideshare.net\/jamtur01\/security-loves-devops-devops-days-austin-2012. Accessed: 2016-01-24"},{"key":"e_1_3_2_1_24_1","volume-title":"2014 State of DevOps Report","author":"Velasquez N.","year":"2014","unstructured":"Velasquez , N. , Kim , G. , Kersten , N. , and Humble , J . 2014 State of DevOps Report : 2014 . https:\/\/puppetlabs.com\/sites\/default\/files\/2014-state-of-devops-report.pdf. Accessed : 2016-01-24 Velasquez, N., Kim, G., Kersten, N., and Humble, J. 2014 State of DevOps Report: 2014. https:\/\/puppetlabs.com\/sites\/default\/files\/2014-state-of-devops-report.pdf. Accessed: 2016-01-24"}],"event":{"name":"ICSE '16: 38th International Conference on Software Engineering","location":"Austin Texas","acronym":"ICSE '16","sponsor":["ACM Association for Computing Machinery","SIGSOFT ACM Special Interest Group on Software Engineering","IEEE-CS\\DATC IEEE Computer Society","TCSE IEEE Computer Society's Tech. Council on Software Engin."]},"container-title":["Proceedings of the International Workshop on Continuous Software Evolution and Delivery"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2896941.2896946","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2896941.2896946","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:39:05Z","timestamp":1750221545000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2896941.2896946"}},"subtitle":["synthesizing practitioners' perceptions and practices"],"short-title":[],"issued":{"date-parts":[[2016,5,14]]},"references-count":24,"alternative-id":["10.1145\/2896941.2896946","10.1145\/2896941"],"URL":"https:\/\/doi.org\/10.1145\/2896941.2896946","relation":{},"subject":[],"published":{"date-parts":[[2016,5,14]]},"assertion":[{"value":"2016-05-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}