{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,27]],"date-time":"2025-10-27T20:46:15Z","timestamp":1761597975619,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":25,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,8,27]],"date-time":"2018-08-27T00:00:00Z","timestamp":1535328000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,8,27]]},"DOI":"10.1145\/3230833.3233275","type":"proceedings-article","created":{"date-parts":[[2018,8,13]],"date-time":"2018-08-13T12:29:48Z","timestamp":1534163388000},"page":"1-6","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":15,"title":["Software Security Activities that Support Incident Management in Secure DevOps"],"prefix":"10.1145","author":[{"given":"Martin Gilje","family":"Jaatun","sequence":"first","affiliation":[{"name":"SINTEF Digital, Trondheim, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,8,27]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Extending the Agile Development Approach to Develop Acceptably Secure Software","author":"Othmane Lotfi","year":"2014","unstructured":"Lotfi ben Othmane , Pelin Angin , Harold Weffers , and Bharat Bhargava . 2014. Extending the Agile Development Approach to Develop Acceptably Secure Software . IEEE Transactions on Dependable and Secure Computing ( 2014 ). Lotfi ben Othmane, Pelin Angin, Harold Weffers, and Bharat Bhargava. 2014. Extending the Agile Development Approach to Develop Acceptably Secure Software. IEEE Transactions on Dependable and Secure Computing (2014)."},{"volume-title":"Foundations of empirical software engineering: the legacy of Victor R. Basili.","author":"Boehm Barry","key":"e_1_3_2_1_2_1","unstructured":"Barry Boehm and Victor R Basili . 2005. Software defect reduction top 10 list . In Foundations of empirical software engineering: the legacy of Victor R. Basili. Vol. 426 . Barry Boehm and Victor R Basili. 2005. Software defect reduction top 10 list. In Foundations of empirical software engineering: the legacy of Victor R. Basili. Vol. 426."},{"key":"e_1_3_2_1_3_1","unstructured":"Rico de Feijter. 2017. Towards the adoption of DevOps in software product organizations: A Maturity model approach. Master's thesis.  Rico de Feijter. 2017. Towards the adoption of DevOps in software product organizations: A Maturity model approach. Master's thesis."},{"key":"e_1_3_2_1_4_1","unstructured":"EU. 2016. Position of the Council at first reading with a view to the adoption of a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation). LEGISLATIVE ACTS AND OTHER INSTRUMENTS 16 5419 (2016). http:\/\/data.consilium.europa.eu\/doc\/document\/ST-5419-2016-INIT\/en\/pdf  EU. 2016. Position of the Council at first reading with a view to the adoption of a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC (General Data Protection Regulation). LEGISLATIVE ACTS AND OTHER INSTRUMENTS 16 5419 (2016). http:\/\/data.consilium.europa.eu\/doc\/document\/ST-5419-2016-INIT\/en\/pdf"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866835.1866850"},{"key":"e_1_3_2_1_6_1","volume-title":"The Myth of DevOps as a Catalyst to improve Security?","author":"Hulme George V","year":"2015","unstructured":"George V Hulme . 2015. The Myth of DevOps as a Catalyst to improve Security? ( 2015 ). http:\/\/devops.com\/2015\/07\/16\/the-myth-of-devops-as-a-catalyst-to-improve-security\/ George V Hulme. 2015. The Myth of DevOps as a Catalyst to improve Security? (2015). http:\/\/devops.com\/2015\/07\/16\/the-myth-of-devops-as-a-catalyst-to-improve-security\/"},{"key":"e_1_3_2_1_7_1","unstructured":"ISO 2011. ISO\/IEC 27035:2011 Information technology - Security techniques - Information security incident management. (2011).  ISO 2011. ISO\/IEC 27035:2011 Information technology - Security techniques - Information security incident management. (2011)."},{"key":"e_1_3_2_1_8_1","unstructured":"Ivan Reitman (dir.) Dan Aykroyd (Writ.) Harold Ramis (Writ.) Bill Murray (Perf.) Dan Aykroyd (Perf.) and Sigourney Weaver (Perf.). 1984. Ghostbusters. Motion picture. (1984). Columbia Pictures.  Ivan Reitman (dir.) Dan Aykroyd (Writ.) Harold Ramis (Writ.) Bill Murray (Perf.) Dan Aykroyd (Perf.) and Sigourney Weaver (Perf.). 1984. Ghostbusters. Motion picture. (1984). Columbia Pictures."},{"key":"e_1_3_2_1_9_1","series-title":"Lecture Notes in Computer Science","volume-title":"Gerald Quirchmayr, Josef Basl, Ilsun You, Lida Xu, and Edgar Weippl (Eds.)","author":"Jaatun Martin Gilje","unstructured":"Martin Gilje Jaatun . 2012. Hunting for Aardvarks: Can Software Security Be Measured? In Multidisciplinary Research and Practice for Information Systems , Gerald Quirchmayr, Josef Basl, Ilsun You, Lida Xu, and Edgar Weippl (Eds.) . Lecture Notes in Computer Science , Vol. 7465 . Springer Berlin Heidelberg , 85--92. Martin Gilje Jaatun. 2012. Hunting for Aardvarks: Can Software Security Be Measured? In Multidisciplinary Research and Practice for Information Systems, Gerald Quirchmayr, Josef Basl, Ilsun You, Lida Xu, and Edgar Weippl (Eds.). Lecture Notes in Computer Science, Vol. 7465. Springer Berlin Heidelberg, 85--92."},{"key":"e_1_3_2_1_10_1","first-page":"iv","article-title":"Secure Software Engineering is not About Security Features","volume":"8","author":"Jaatun Martin Gilje","year":"2017","unstructured":"Martin Gilje Jaatun . 2017 . Secure Software Engineering is not About Security Features . International Journal of Secure Software Engineering 8 , 2 (2017), iv . Martin Gilje Jaatun. 2017. Secure Software Engineering is not About Security Features. International Journal of Secure Software Engineering 8, 2 (2017), iv.","journal-title":"International Journal of Secure Software Engineering"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-23318-5_7"},{"key":"e_1_3_2_1_12_1","volume-title":"International Journal of Information Management","author":"Jaatun Martin Gilje","year":"2016","unstructured":"Martin Gilje Jaatun , Siani Pearson , Fr\u00e9d\u00e9ric Gittler , Ronald Leenes , and Maartje Niezen . 2016. Enhancing Accountability in the Cloud . International Journal of Information Management ( 2016 ). Martin Gilje Jaatun, Siani Pearson, Fr\u00e9d\u00e9ric Gittler, Ronald Leenes, and Maartje Niezen. 2016. Enhancing Accountability in the Cloud. International Journal of Information Management (2016)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2015.38"},{"key":"e_1_3_2_1_14_1","unstructured":"Gene Kim. 2012. Top 11 Things You Need to Know About DevOps. (2012). https:\/\/www.thinkhdi.eom\/~\/media\/HDICorp\/Files\/White-Papers\/whtppr-1112-devops-kim.pdf  Gene Kim. 2012. Top 11 Things You Need to Know About DevOps. (2012). https:\/\/www.thinkhdi.eom\/~\/media\/HDICorp\/Files\/White-Papers\/whtppr-1112-devops-kim.pdf"},{"key":"e_1_3_2_1_15_1","volume-title":"Software Security: Building Security In","author":"McGraw Gary","year":"2006","unstructured":"Gary McGraw . 2006 . Software Security: Building Security In . Addison-Wesley . Gary McGraw. 2006. Software Security: Building Security In. Addison-Wesley."},{"key":"e_1_3_2_1_16_1","unstructured":"Gary McGraw Sammy Migues and Jacob West. 2017. Building Security In Maturity Model (BSIMM 8). (2017). http:\/\/bsimm.com.  Gary McGraw Sammy Migues and Jacob West. 2017. Building Security In Maturity Model (BSIMM 8). (2017). http:\/\/bsimm.com."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2016.92"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/UCC.2014.128"},{"key":"e_1_3_2_1_19_1","unstructured":"OpenSAMM. {n. d.}. Software Assurance Maturity Model (SAMM): A guide to building security into software development. ({n. d.}). http:\/\/www.opensamm.org\/.  OpenSAMM. {n. d.}. Software Assurance Maturity Model (SAMM): A guide to building security into software development. ({n. d.}). http:\/\/www.opensamm.org\/."},{"key":"e_1_3_2_1_20_1","unstructured":"Puppet and DORA. 2017. 2017 State of DevOps Report. (2017). https:\/\/puppet.com\/resources\/whitepaper\/state-of-devops-report.  Puppet and DORA. 2017. 2017 State of DevOps Report. (2017). https:\/\/puppet.com\/resources\/whitepaper\/state-of-devops-report."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.12.001"},{"key":"e_1_3_2_1_22_1","unstructured":"Bruce Schneier. 2007. Information Security and Externalities. Schneier on Security Blog. (2007). https:\/\/www.schneier.com\/blog\/archives\/2007\/01\/information_sec_1.html  Bruce Schneier. 2007. Information Security and Externalities. Schneier on Security Blog. (2007). https:\/\/www.schneier.com\/blog\/archives\/2007\/01\/information_sec_1.html"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.05.003"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2896941.2896946"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.4018\/IJSSE.2016100103"}],"event":{"name":"ARES 2018: International Conference on Availability, Reliability and Security","sponsor":["Universit\u00e4t Hamburg Universit\u00e4t Hamburg"],"location":"Hamburg Germany","acronym":"ARES 2018"},"container-title":["Proceedings of the 13th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3230833.3233275","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3230833.3233275","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:07:51Z","timestamp":1750212471000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3230833.3233275"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,8,27]]},"references-count":25,"alternative-id":["10.1145\/3230833.3233275","10.1145\/3230833"],"URL":"https:\/\/doi.org\/10.1145\/3230833.3233275","relation":{},"subject":[],"published":{"date-parts":[[2018,8,27]]},"assertion":[{"value":"2018-08-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}