{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T02:13:16Z","timestamp":1780107196327,"version":"3.54.0"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,8,26]],"date-time":"2019-08-26T00:00:00Z","timestamp":1566777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,8,26]]},"DOI":"10.1145\/3339252.3340338","type":"proceedings-article","created":{"date-parts":[[2019,8,9]],"date-time":"2019-08-09T12:21:03Z","timestamp":1565353263000},"page":"1-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":23,"title":["Managing Security in Software"],"prefix":"10.1145","author":[{"given":"Kalle","family":"Rindell","sequence":"first","affiliation":[{"name":"SINTEF Digital Trondheim, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Karin","family":"Bernsmed","sequence":"additional","affiliation":[{"name":"SINTEF Digital Trondheim, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin Gilje","family":"Jaatun","sequence":"additional","affiliation":[{"name":"SINTEF Digital Trondheim, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,8,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Extreme Programming Explained: Embrace Change","author":"Beck Kent"},{"key":"e_1_3_2_1_2_1","volume-title":"Bad smells in code. Refactoring: Improving the design of existing code 1","author":"Beck Kent","year":"1999"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASC.2018.8569579"},{"key":"e_1_3_2_1_4_1","volume-title":"2017 IEEE International Conference on Software Maintenance and Evolution (ICSME). 13--23","author":"Besker T."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2017.09.025"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/157709.157715"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","first-page":"53","DOI":"10.5381\/jot.2003.2.1.c6","article-title":"Engineering Security Requirements","volume":"2","author":"Firesmith Donald G.","year":"2003","journal-title":"Journal of Object Technology"},{"key":"e_1_3_2_1_11_1","volume-title":"Technical debt quadrant. Web Page","author":"Fowler Martin","year":"2009"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1985362.1985370"},{"key":"e_1_3_2_1_13_1","volume-title":"2013 4th International Workshop on Managing Technical Debt (MTD). 20--27","author":"Holvitie J."},{"key":"e_1_3_2_1_14_1","volume-title":"Leblanc","author":"Howard Michael","year":"2002"},{"key":"e_1_3_2_1_15_1","volume-title":"The Security Development Lifecycle","author":"Howard Michael"},{"key":"e_1_3_2_1_16_1","unstructured":"IEEE. 2018. Avoiding the Top 10 Software Security Design Flaws.  IEEE. 2018. Avoiding the Top 10 Software Security Design Flaws."},{"key":"e_1_3_2_1_17_1","volume-title":"Information Technology -- Security Techniques -- Systems Security Engineering -- Capability Maturity Model (SSE-CMM)","author":"IEC","edition":"2"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3103172"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2012.167"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2014.12.027"},{"key":"e_1_3_2_1_21_1","first-page":"77","article-title":"PORTFOLIO SELECTION*","volume":"7","author":"Markowitz Harry","year":"1952","journal-title":"The Journal of Finance"},{"key":"e_1_3_2_1_22_1","volume-title":"Software Security: Building Security In","author":"McGraw Gary","year":"2006"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1082983.1083214"},{"key":"e_1_3_2_1_24_1","unstructured":"Microsoft. 2017. Agile Development Using Microsoft Security Development Lifecycle. https:\/\/www.microsoft.com\/en-us\/SDL\/Discover\/sdlagile.aspx  Microsoft. 2017. Agile Development Using Microsoft Security Development Lifecycle. https:\/\/www.microsoft.com\/en-us\/SDL\/Discover\/sdlagile.aspx"},{"key":"e_1_3_2_1_25_1","unstructured":"MITRE CVE. 2018. National Vulnerability Database. https:\/\/cve.mitre.org\/  MITRE CVE. 2018. National Vulnerability Database. https:\/\/cve.mitre.org\/"},{"key":"e_1_3_2_1_26_1","volume-title":"Science of security hard problems: A lablet perspective","author":"Nicol David M","year":"2012"},{"key":"e_1_3_2_1_27_1","unstructured":"OWASP. 2018. OWASP Top 10 Application Security Risks.  OWASP. 2018. OWASP Top 10 Application Security Risks."},{"key":"e_1_3_2_1_28_1","unstructured":"OWASP SAMM. 2017. Software Assurance Maturity Model.  OWASP SAMM. 2017. Software Assurance Maturity Model."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.5555\/2663297.2663302"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecPODS.2019.8885100"},{"key":"e_1_3_2_1_31_1","unstructured":"SANS. 2011. CWE\/SANS TOP 25 Most Dangerous Software Errors.  SANS. 2011. CWE\/SANS TOP 25 Most Dangerous Software Errors."},{"key":"e_1_3_2_1_32_1","volume-title":"Agile Software Development with Scrum","author":"Schwaber Ken","edition":"1"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/2666036.2666044"},{"key":"e_1_3_2_1_34_1","volume-title":"Threat Modeling: Designing for Security","author":"Shostack Adam","year":"2014"},{"key":"e_1_3_2_1_35_1","volume-title":"Marco Tulio Valente, and Ricardo Terra","author":"Oliveira Silva Marcelino Campos","year":"2016"},{"key":"e_1_3_2_1_36_1","volume-title":"Software Engineering","author":"Sommerville Ian","edition":"10"},{"key":"e_1_3_2_1_37_1","unstructured":"Synopsys Software Integrity Group. 2018. The Building Security In Maturity Model 9. https:\/\/www.bsimm.com\/  Synopsys Software Integrity Group. 2018. The Building Security In Maturity Model 9. https:\/\/www.bsimm.com\/"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2016.05.018"}],"event":{"name":"ARES '19: 14th International Conference on Availability, Reliability and Security","location":"Canterbury CA United Kingdom","acronym":"ARES '19"},"container-title":["Proceedings of the 14th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3339252.3340338","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3339252.3340338","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:17Z","timestamp":1750203857000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3339252.3340338"}},"subtitle":["Or: How I Learned to Stop Worrying and Manage the Security Technical Debt"],"short-title":[],"issued":{"date-parts":[[2019,8,26]]},"references-count":35,"alternative-id":["10.1145\/3339252.3340338","10.1145\/3339252"],"URL":"https:\/\/doi.org\/10.1145\/3339252.3340338","relation":{},"subject":[],"published":{"date-parts":[[2019,8,26]]},"assertion":[{"value":"2019-08-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}