{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T15:02:29Z","timestamp":1764687749250,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":26,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,8,29]],"date-time":"2017-08-29T00:00:00Z","timestamp":1503964800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,8,29]]},"DOI":"10.1145\/3098954.3103172","type":"proceedings-article","created":{"date-parts":[[2017,8,10]],"date-time":"2017-08-10T12:12:36Z","timestamp":1502367156000},"page":"1-6","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["DevOps for Better Software Security in the Cloud Invited Paper"],"prefix":"10.1145","author":[{"given":"Martin Gilje","family":"Jaatun","sequence":"first","affiliation":[{"name":"SINTEF Digital, Sluppen, Trondheim, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniela S.","family":"Cruzes","sequence":"additional","affiliation":[{"name":"SINTEF Digital, Sluppen, Trondheim, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jesus","family":"Luna","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t Darmstadt, Darmstadt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1852786.1852860"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.82"},{"key":"e_1_3_2_1_3_1","unstructured":"Len Bass Ingo Weber and Liming Zhu. 2015. DevOps: A Software Architect's Perspective. Addison-Wesley Professional.   Len Bass Ingo Weber and Liming Zhu. 2015. DevOps: A Software Architect's Perspective. Addison-Wesley Professional."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"L. ben Othmane P. Angin H. Weffers and B. Bhargava. 2014. Extending the Agile Development Approach to Develop Acceptably Secure Software. IEEE Transactions on Dependable and Secure Computing (2014).  L. ben Othmane P. Angin H. Weffers and B. Bhargava. 2014. Extending the Agile Development Approach to Develop Acceptably Secure Software. IEEE Transactions on Dependable and Secure Computing (2014).","DOI":"10.1109\/TDSC.2014.2298011"},{"volume-title":"Foundations of empirical software engineering: the legacy of Victor R. Basili.","author":"Boehm Barry","key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","DOI":"10.1007\/3-540-27662-9"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1111\/0735-2751.00040"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2012.09.004"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.50"},{"key":"e_1_3_2_1_10_1","unstructured":"Brian Fitzgerald and Klaas-Jan Stol. 2015. Continuous software engineering: A roadmap and agenda. Journal of Systems and Software (2015) --.  Brian Fitzgerald and Klaas-Jan Stol. 2015. Continuous software engineering: A roadmap and agenda. Journal of Systems and Software (2015) --."},{"key":"e_1_3_2_1_11_1","unstructured":"George V. Hulme. 2015. The Myth of DevOps as a Catalyst to improve Security? (2015). http:\/\/devops.com\/2015\/07\/16\/the-myth-of-devops-as-a-catalyst-to-improve-security\/  George V. Hulme. 2015. The Myth of DevOps as a Catalyst to improve Security? (2015). http:\/\/devops.com\/2015\/07\/16\/the-myth-of-devops-as-a-catalyst-to-improve-security\/"},{"key":"e_1_3_2_1_12_1","unstructured":"J. Luna A. Taha R. Trapero and N. Suri. 2015. Quantitative Reasoning about Cloud Security Using Service Level Agreements. In Trans. on Cloud Computing 99 (2015).  J. Luna A. Taha R. Trapero and N. Suri. 2015. Quantitative Reasoning about Cloud Security Using Service Level Agreements. In Trans. on Cloud Computing 99 (2015)."},{"key":"e_1_3_2_1_13_1","volume-title":"Lecture Notes in Computer Science","volume":"7465","author":"Jaatun Martin Gilje","year":"2012"},{"key":"e_1_3_2_1_14_1","first-page":"i","article-title":"Special Issue from the 5th International Workshop on Secure Software Engineering","volume":"2","author":"Jaatun Martin Gilje","year":"2011","journal-title":"International Journal of Secure Software Engineering"},{"key":"e_1_3_2_1_15_1","unstructured":"Gene Kim. 2012. Top 11 Things You Need to Know About DevOps. (2012). https:\/\/www.thinkhdi.com\/~\/media\/HDICorp\/Files\/White-Papers\/whtppr-1112-devops-kim.pdf  Gene Kim. 2012. Top 11 Things You Need to Know About DevOps. (2012). https:\/\/www.thinkhdi.com\/~\/media\/HDICorp\/Files\/White-Papers\/whtppr-1112-devops-kim.pdf"},{"volume-title":"Software Security: Building Security In","year":"2006","author":"McGraw Gary","key":"e_1_3_2_1_16_1"},{"key":"e_1_3_2_1_17_1","unstructured":"Gary McGraw Sammy Migues and Jacob West. 2015. Building Security In Maturity Model (BSIMM 6). (2015). http:\/\/bsimm.com.  Gary McGraw Sammy Migues and Jacob West. 2015. Building Security In Maturity Model (BSIMM 6). (2015). http:\/\/bsimm.com."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Peter Mell and Tim Grance. 2011. The NIST definition of cloud computing. Computer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg. (2011).  Peter Mell and Tim Grance. 2011. The NIST definition of cloud computing. Computer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg. (2011).","DOI":"10.6028\/NIST.SP.800-145"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/AGILE.2011.35"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"Jolanda Modic Rub\u00e9n Trapero Ahmed Taha Jesus Luna Miha Stopar and Neeraj Suri. 2016. Novel Efficient Techniques for Real-Time Cloud Security Assessment. Elsevier Journal on Computer & Security (Sep. 2016) 1--18.  Jolanda Modic Rub\u00e9n Trapero Ahmed Taha Jesus Luna Miha Stopar and Neeraj Suri. 2016. Novel Efficient Techniques for Real-Time Cloud Security Assessment. Elsevier Journal on Computer & Security (Sep. 2016) 1--18.","DOI":"10.1016\/j.cose.2016.06.003"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1142055.1142065"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2372251.2372255"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-011-9190-8"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.65"},{"key":"e_1_3_2_1_25_1","unstructured":"Trimintzios P. 2011. Measurement Frameworks and Metrics for Resilient Networks and Services. Discussion Draft. European Network and Information Security Agency. (2011).  Trimintzios P. 2011. Measurement Frameworks and Metrics for Resilient Networks and Services. Discussion Draft. European Network and Information Security Agency. (2011)."},{"key":"e_1_3_2_1_27_1","unstructured":"Carol Woody. 2013. Agile Security - Review of Current Research and Pilot Usage. SEI White Paper. (2013).  Carol Woody. 2013. Agile Security - Review of Current Research and Pilot Usage. SEI White Paper. (2013)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2015.23"}],"event":{"name":"ARES '17: International Conference on Availability, Reliability and Security","acronym":"ARES '17","location":"Reggio Calabria Italy"},"container-title":["Proceedings of the 12th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3098954.3103172","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3098954.3103172","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:37:25Z","timestamp":1750217845000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3098954.3103172"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,29]]},"references-count":26,"alternative-id":["10.1145\/3098954.3103172","10.1145\/3098954"],"URL":"https:\/\/doi.org\/10.1145\/3098954.3103172","relation":{},"subject":[],"published":{"date-parts":[[2017,8,29]]},"assertion":[{"value":"2017-08-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}