{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T04:08:34Z","timestamp":1781064514156,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T00:00:00Z","timestamp":1693267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Bundesministerium f\u00fcr Bildung und Forschung","award":["01IS17049"],"award-info":[{"award-number":["01IS17049"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,29]]},"DOI":"10.1145\/3600160.3600170","type":"proceedings-article","created":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T22:54:41Z","timestamp":1691621681000},"page":"1-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Adoption of Information Security Practices in Large-Scale Agile Software Development: A Case Study in the Finance Industry"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-6953-6347","authenticated-orcid":false,"given":"Sascha","family":"N\u00e4gele","sequence":"first","affiliation":[{"name":"Technical University Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1584-9667","authenticated-orcid":false,"given":"Lorena","family":"Korn","sequence":"additional","affiliation":[{"name":"Technical University Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6667-5452","authenticated-orcid":false,"given":"Florian","family":"Matthes","sequence":"additional","affiliation":[{"name":"Technical University Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Software Security Engineering: A Guide for Project Managers. Vol.\u00a01","author":"Allen H","unstructured":"Julia\u00a0H Allen, Sean Barnum, Robert\u00a0J Ellison, Gary McGraw, and Nancy\u00a0R Mead. 2008. Software Security Engineering: A Guide for Project Managers. Vol.\u00a01. Addison-Wesley Professional, Boston."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2019.01.009"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.7472\/jksii.2014.15.1.13"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2015.45"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/WBMA.2015.9"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.82"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2016.03.001"},{"key":"e_1_3_2_1_8_1","unstructured":"Kent Beck Mike Beedle Arie van Bennekum Alistair Cockburn Ward Cunningham Martin Fowler James Grenning Jim Highsmith Andrew Hunt Ron Jeffries Jon Kern Brian Marick Robert\u00a0C. Martin Steve Mellor Ken Schwaber Jeff Sutherland and Dave Thomas. 2001. Manifesto for Agile Software Development. http:\/\/agilemanifesto.org\/"},{"key":"e_1_3_2_1_9_1","volume-title":"Agile Application Security: Enabling Security in a Continuous Delivery Pipeline","author":"Bell Laura","unstructured":"Laura Bell, Michael Brunton-Spall, Rich Smith, and Jim Bird. 2017. Agile Application Security: Enabling Security in a Continuous Delivery Pipeline. O\u2019Reilly Media Inc."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58793-2_28"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065907.1066034"},{"key":"e_1_3_2_1_12_1","first-page":"144","article-title":"AGILE AND SECURE SOFTWARE DEVELOPMENT","volume":"20","author":"Bishop Dave","year":"2019","unstructured":"Dave Bishop, Rowland, and Pam. 2019. AGILE AND SECURE SOFTWARE DEVELOPMENT: AN UNFINISHED STORY. Issues in Information Systems 20, 1 (2019), 144\u2013156.","journal-title":"AN UNFINISHED STORY. Issues in Information Systems"},{"key":"e_1_3_2_1_13_1","volume-title":"Interviews mit Experten: eine praxisorientierte Einf\u00fchrung","author":"Bogner Alexander","unstructured":"Alexander Bogner, Beate Littig, and Wolfgang Menz. 2014. Interviews mit Experten: eine praxisorientierte Einf\u00fchrung. Springer Fachmedien, Wiesbaden."},{"key":"e_1_3_2_1_14_1","volume-title":"Forschungsmethoden und Evaluation","author":"Bortz J\u00fcrgen","unstructured":"J\u00fcrgen Bortz and Nicola D\u00f6ring. 1995. Forschungsmethoden und Evaluation. Springer, Berlin, Heidelberg."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1137627.1137631"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/QuaRAP.2018.00008"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2016.06.013"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-13835-0_20"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9524-2"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2012.02.033"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.2307\/258557"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606635"},{"key":"e_1_3_2_1_23_1","volume-title":"ENISA Threat Landscape","author":"European Union\u00a0Agency for Cyber\u00a0Security. 2023.","year":"2022","unstructured":"European Union\u00a0Agency for Cyber\u00a0Security. 2023. ENISA Threat Landscape 2022. https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-2022"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Floyd\u00a0J Fowler\u00a0Jr. 2009. Survey research methods (4 ed.). SAGE publications.","DOI":"10.4135\/9781452230184"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/MySEC.2011.6140708"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2018.06.004"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2018.290111318"},{"key":"e_1_3_2_1_28_1","unstructured":"International Organization for Standardization. 2018. ISO\/IEC 27000:2018(en): Information technology - Security techniques - Information security management systems - Overview and vocabulary."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ress.2020.106954"},{"key":"e_1_3_2_1_30_1","volume-title":"Integrating Software Development Security Activities with Agile Methodologies. IEEE\/ACS International Conference on Computer Systems and Applications","author":"Keramati Hossein","year":"2008","unstructured":"Hossein Keramati and Seyed-Hassan Mirian-Hosseinabadi. 2008. Integrating Software Development Security Activities with Agile Methodologies. IEEE\/ACS International Conference on Computer Systems and Applications (2008), 749\u2013754."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.5121\/ijsea.2016.7304"},{"key":"e_1_3_2_1_32_1","volume-title":"UCVOF, ucvox. files. wordpress. com\/2012\/11\/113617905-scaling-Agile-spotify-11. pdf","author":"Kniberg Henrik","year":"2012","unstructured":"Henrik Kniberg and Anders Ivarsson. 2012. Scaling agile@ spotify. online], UCVOF, ucvox. files. wordpress. com\/2012\/11\/113617905-scaling-Agile-spotify-11. pdf (2012)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Steinar Kvale. 2007. Doing interviews (1 ed.). SAGE publications.","DOI":"10.4135\/9781849208963"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3103171"},{"key":"e_1_3_2_1_35_1","volume-title":"Qualitative Inhaltsanalyse: Grundlagen und Techniken. Beltz.","author":"Mayring Philipp","year":"2015","unstructured":"Philipp Mayring. 2015. Qualitative Inhaltsanalyse: Grundlagen und Techniken. Beltz."},{"key":"e_1_3_2_1_36_1","volume-title":"Software Security: Building Security In","author":"McGraw Gary","year":"2006","unstructured":"Gary McGraw. 2006. Software Security: Building Security In. Addison-Wesley."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SEAA51224.2020.00073"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-08169-9_13"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the 27th European Conference on Information Systems (ECIS)","author":"Newton Nathan","year":"2019","unstructured":"Nathan Newton, Craig Anslow, and Andreas Drechsler. 2019. Information Security in Agile Software Development Project: A Critical Success Factor Perspective. Proceedings of the 27th European Conference on Information Systems (ECIS) (2019)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.4018\/jsse.2010070105"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2016.103"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-010-9136-6"},{"key":"e_1_3_2_1_43_1","volume-title":"Secure Scrum: Development of Secure Software with Scrum","author":"Pohl Christoph","year":"2015","unstructured":"Christoph Pohl and Hans-Joachim Hof. 2015. Secure Scrum: Development of Secure Software with Scrum. http:\/\/arxiv.org\/pdf\/1507.02992v1"},{"key":"e_1_3_2_1_44_1","unstructured":"Check\u00a0Point Research. 2023. Check Point Research Reports a 38% Increase in 2022 Global Cyberattacks. https:\/\/blog.checkpoint.com\/2023\/01\/05\/38-increase-in-2022-global-cyberattacks\/"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.13140\/RG.2.1.4660.2964"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3103170"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2020.106488"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3230833.3233274"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-008-9102-8"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2005.329"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-35333-9_26"},{"key":"e_1_3_2_1_52_1","unstructured":"TemboSocial. 2023. TemboSocial: Software for Employee Recognition and Employee Feedback. https:\/\/www.tembosocial.com\/"},{"key":"e_1_3_2_1_53_1","volume-title":"16th Annual State of Agile Report. https:\/\/stateofagile.com\/","unstructured":"VersionOne. 2022. 16th Annual State of Agile Report. https:\/\/stateofagile.com\/"},{"key":"e_1_3_2_1_54_1","volume-title":"Analyzing the Past to Prepare for the Future: Writing a literature Review. MIS Quarterly 26, 2","author":"Webster Jane","year":"2002","unstructured":"Jane Webster and Richard\u00a0T. Watson. 2002. Analyzing the Past to Prepare for the Future: Writing a literature Review. MIS Quarterly 26, 2 (2002), xiii \u2013 xxiii."},{"key":"e_1_3_2_1_55_1","volume-title":"Case Study Research: Design and Methods","author":"Yin K.","unstructured":"Robert\u00a0K. Yin. 2003. Case Study Research: Design and Methods (3th edition ed.). Sage, Thousand Oaks.","edition":"3"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2022.111473"}],"event":{"name":"ARES 2023: The 18th International Conference on Availability, Reliability and Security","location":"Benevento Italy","acronym":"ARES 2023"},"container-title":["Proceedings of the 18th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3600170","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3600160.3600170","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:13Z","timestamp":1750178173000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3600170"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,29]]},"references-count":56,"alternative-id":["10.1145\/3600160.3600170","10.1145\/3600160"],"URL":"https:\/\/doi.org\/10.1145\/3600160.3600170","relation":{},"subject":[],"published":{"date-parts":[[2023,8,29]]},"assertion":[{"value":"2023-08-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}