{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,21]],"date-time":"2026-06-21T14:31:33Z","timestamp":1782052293224,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,10,24]],"date-time":"2024-10-24T00:00:00Z","timestamp":1729728000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,10,24]]},"DOI":"10.1145\/3674805.3690748","type":"proceedings-article","created":{"date-parts":[[2024,10,15]],"date-time":"2024-10-15T18:39:24Z","timestamp":1729017564000},"page":"440-446","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Towards Automated Continuous Security Compliance"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7903-8236","authenticated-orcid":false,"given":"Florian","family":"Angermeir","sequence":"first","affiliation":[{"name":"fortiss, Germany and Blekinge Institute of Technology, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4361-6118","authenticated-orcid":false,"given":"Jannik","family":"Fischbach","sequence":"additional","affiliation":[{"name":"Netlight Consulting GmbH, Germany and fortiss, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0535-1371","authenticated-orcid":false,"given":"Fabiola","family":"Moy\u00f3n","sequence":"additional","affiliation":[{"name":"Siemens Technology, Germany and Technical University of Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0619-6027","authenticated-orcid":false,"given":"Daniel","family":"Mendez","sequence":"additional","affiliation":[{"name":"Blekinge Institute of Technology, Sweden and fortiss, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,10,24]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Javad Abed Gurpreet Dhillon and Sevgi Ozkan. 2016. Investigating Continuous Security Compliance Behavior: Insights from Information Systems Continuance Model. In AMCIS \u201916. 10\u00a0pages."},{"key":"e_1_3_2_1_2_1","volume-title":"Exploring Automated GDPR-Compliance in Requirements Engineering: A Systematic Mapping Study","author":"Aberkane Abdel-Jaouad","year":"2021","unstructured":"Abdel-Jaouad Aberkane, Geert Poels, and Seppe\u00a0Vanden Broucke. 2021. Exploring Automated GDPR-Compliance in Requirements Engineering: A Systematic Mapping Study. IEEE Access 9 (5 2021), 66542\u201366559."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Muhammad\u00a0Zaid Abrahams and Josef\u00a0J Langerman. 2018. Compliance at Velocity within a DevOps Environment. In ICDIM \u201918. 94\u2013101.","DOI":"10.1109\/ICDIM.2018.8847007"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Abdullah Aldahmash Andy\u00a0M. Gravell and Yvonne Howard. 2017. Systems Software and Services Process Improvement. Chapter A Review on the Critical Success Factors of Agile Software Development 504\u2013512.","DOI":"10.1007\/978-3-319-64218-5_41"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Arwa Alromaih Yasser Ismail and Wael Elmedany. 2022. Continuous compliance to ensure strong cybersecurity posture within digital transformation in smart cities. In SCS \u201922. 464\u2013479.","DOI":"10.1049\/icp.2023.0647"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","unstructured":"Florian Angermeir Jannik Fischbach Fabiola Moy\u00f3n and Daniel Mendez. 2024. Towards Automated Continuous Security Compliance. https:\/\/doi.org\/10.6084\/m9.figshare.25199225.v1","DOI":"10.6084\/m9.figshare.25199225.v1"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Vanessa Ayala-Rivera and Liliana Pasquale. 2018. The Grace Period Has Ended: An Approach to Operationalize GDPR Requirements. In RE\u201918. 136\u2013146.","DOI":"10.1109\/RE.2018.00023"},{"key":"e_1_3_2_1_8_1","volume-title":"DevOps critical success factors \u2014 A systematic literature review. Information and Software Technology 157 (5","author":"Azad Nasreen","year":"2023","unstructured":"Nasreen Azad and Sami Hyrynsalmi. 2023. DevOps critical success factors \u2014 A systematic literature review. Information and Software Technology 157 (5 2023), 14\u00a0pages."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Jan Bosch (Ed.). 2014. Continuous Software Engineering. Springer.","DOI":"10.1007\/978-3-319-11283-1"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1002\/smr.2440"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Suresh Chari Ian Molloy Youngja Park and Wilfried Teiken. 2013. Ensuring continuous compliance through reconciling policy with usage. In SACMAT \u201913. 49\u2013\u201360.","DOI":"10.1145\/2462410.2462417"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2007.08.020"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Fabiola\u00a0Moy\u00f3n Constante Rafael Soares Maria Pinto-Albuquerque Daniel Mendez and Kristian Beckers. 2020. Integration of Security Standards in DevOps Pipelines: An Industry Case Study. In PROFES \u201920. 434\u2013452.","DOI":"10.1007\/978-3-030-64148-1_27"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Sebastian D\u00e4nnart Fabiola\u00a0Moy\u00f3n Constante and Kristian Beckers. 2019. An Assessment Model for Continuous Security Compliance in Large Scale Agile Environments. In Advanced Information Systems Engineering. 529\u2013544.","DOI":"10.1007\/978-3-030-21290-2_33"},{"key":"e_1_3_2_1_15_1","volume-title":"DevOps benefits: A systematic literature review. Software: Practice and Experience 52, 9 (9","author":"Faustino Jo\u00e3o","year":"2022","unstructured":"Jo\u00e3o Faustino, Daniel Adriano, Ricardo Amaro, Rub\u00e9n Pereira, and Miguel\u00a0Mira da Silva. 2022. DevOps benefits: A systematic literature review. Software: Practice and Experience 52, 9 (9 2022), 1905\u20131926."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Brian Fitzgerald and Klaas-Jan Stol. 2014. Continuous Software Engineering and beyond: Trends and Challenges. In RCoSE \u201914. 1\u20139.","DOI":"10.1145\/2593812.2593813"},{"key":"e_1_3_2_1_17_1","volume-title":"Continuous software engineering: A roadmap and agenda. Journal of Systems and Software 123 (1","author":"Fitzgerald Brian","year":"2017","unstructured":"Brian Fitzgerald and Klaas-Jan Stol. 2017. Continuous software engineering: A roadmap and agenda. Journal of Systems and Software 123 (1 2017), 176\u2013189."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Rajaa\u00a0El Hamdani Majd Mustapha David\u00a0Restrepo Amariles Aurore Troussel S\u00e9bastien Mee\u00f9s and Katsiaryna Krasnashchok. 2021. A combined rule-based and machine learning approach for automated GDPR compliance checking. In ICAIL \u201921. 40\u201349.","DOI":"10.1145\/3462757.3466081"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Allenoush Hayrapetian and Rajeev Raje. 2018. Empirically Analyzing and Evaluating Security Features in Software Requirements. In ISEC \u201918. 1\u201311.","DOI":"10.1145\/3172871.3172879"},{"key":"e_1_3_2_1_20_1","unstructured":"IBM. 2013. Maintaining continuous compliance\u2014a new best-practice approach. https:\/\/docs.media.bitpipe.com\/io_11x\/io_115656\/item_894327\/Maintaining%20continuous%20compliance.pdf"},{"key":"e_1_3_2_1_21_1","unstructured":"International Standards Organization. 2018. Information technology - Security techniques - Information security management systems. ISO Standard 27001."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Martin Kellogg Martin Sch\u00e4f Serdar Tasiran and Michael\u00a0D. Ernst. 2020. Continuous Compliance. In ASE \u201920. 511\u2013523.","DOI":"10.1145\/3324884.3416593"},{"key":"e_1_3_2_1_23_1","volume-title":"Procedures for Performing Systematic Reviews","author":"Kitchenham Barbara","unstructured":"Barbara Kitchenham. 2004. Procedures for Performing Systematic Reviews. Technical Report. Keele, UK and Eveleigh, Australia."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101967"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","unstructured":"Ze\u00a0Shi Li Colin Werner Neil Ernst and Daniela Damian. 2020. GDPR Compliance in the Context of Continuous Integration. (2020). https:\/\/doi.org\/10.48550\/arXiv.2002.06830 arXiv:arXiv:2002.06830v1","DOI":"10.48550\/arXiv.2002.06830"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Aaron\u00a0K. Massey Richard\u00a0L. Rutledge Annie\u00a0I. Anton and Peter\u00a0P. Swire. 2014. Identifying and classifying ambiguity for regulatory requirements. In RE\u201914. 83\u201392.","DOI":"10.1109\/RE.2014.6912250"},{"key":"e_1_3_2_1_27_1","unstructured":"Marco Moscher. 2017. Continuous Compliance Testing. Master\u2019s thesis."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Fabiola Moy\u00f3n Florian Angermeir and Daniel Mendez. 2024. Industrial Challenges in Secure Continuous Development. In ICSE \u201924. 3\u00a0pages.","DOI":"10.1145\/3639477.3639736"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Fabiola Moy\u00f3n Kristian Beckers Sebastian Klepper Philipp Lachberger and Bernd Bruegge. 2018. Towards continuous security compliance in agile software development at scale. In RCoSE \u201918. 31\u201334.","DOI":"10.1145\/3194760.3194767"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","unstructured":"Fabiola Moy\u00f3n Daniel M\u00e9ndez Kristian Beckers and Sebastian Klepper. 2020. How to Integrate Security Compliance Requirements with Agile Software Engineering at Scale?. In PROFES \u201920. 69\u201387.","DOI":"10.1007\/978-3-030-64148-1_5"},{"key":"e_1_3_2_1_31_1","volume-title":"Field study on requirements engineering: Investigation of artefacts, project parameters, and execution strategies. Information and Software Technology 54, 2 (2","author":"Fern\u00e1ndez Daniel M\u00e9ndez","year":"2012","unstructured":"Daniel M\u00e9ndez Fern\u00e1ndez, Stefan Wagner, Klaus Lochmann, Andrea Baumann, and Holger de Carne. 2012. Field study on requirements engineering: Investigation of artefacts, project parameters, and execution strategies. Information and Software Technology 54, 2 (2 2012), 162\u2013178."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Sebastian N\u00e4gele Natalie Schenk and Florian Matthes. 2023. The Current State of Security Governance and Compliance in Large-Scale Agile Development: A Systematic Literature Review and Interview Study. In CBI \u201923. 1\u201310.","DOI":"10.1109\/CBI58679.2023.10187439"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Hela Oueslati Mohammad\u00a0Masudur Rahman and Lotfi\u00a0ben Othmane. 2015. Literature Review of the Challenges of Developing Secure Software Using the Agile Approach. In ARES \u201915. 540\u2013547.","DOI":"10.1109\/ARES.2015.69"},{"key":"e_1_3_2_1_34_1","volume-title":"Continuous Open Source License Compliance. Computer 53, 12 (12","author":"Phipps Simon","year":"2020","unstructured":"Simon Phipps and Stefano Zacchiroli. 2020. Continuous Open Source License Compliance. Computer 53, 12 (12 2020), 115\u2013119."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Paul Ralph and Sebastian Baltes. 2022. Paving the way for mature secondary research: the seven types of literature review. In ESEC\/FSE\u201922. 5\u00a0pages.","DOI":"10.1145\/3540250.3560877"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Rajesh Rompicharla and Bhaskar\u00a0Reddy P.\u00a0V. 2020. Continuous Compliance model for Hybrid Multi-Cloud through Self-Service Orchestrator. In ICSTCEE \u201920. 589\u2013593.","DOI":"10.1109\/ICSTCEE49637.2020.9276897"},{"key":"e_1_3_2_1_37_1","volume-title":"Continuous Compliance: DevOps Approach to Compliance And Change Management. Master\u2019s thesis.","author":"Rysbekov Arstanaly","year":"2022","unstructured":"Arstanaly Rysbekov. 2022. Continuous Compliance: DevOps Approach to Compliance And Change Management. Master\u2019s thesis."},{"key":"e_1_3_2_1_38_1","volume-title":"What is Continuous Compliance?IEEE Software (12","author":"Santilli Tiziano","year":"2023","unstructured":"Tiziano Santilli, Patrizio Pelliccione, Rebekka Wohlrab, and Ali Shahrokni. 2023. What is Continuous Compliance?IEEE Software (12 2023), 1\u201310."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Ali Shahrokni and Patrizio Pelliccione. 2022. Significance of Continuous Compliance in Automotive. In EASE \u201922. 272\u2013\u2013273.","DOI":"10.1145\/3530019.3534984"},{"key":"e_1_3_2_1_40_1","unstructured":"Andreas Steffens Horst Lichter and Marco Moscher. 2018. Towards Data-Driven Continuous Compliance Testing. In SE \u201918. 78\u201384."},{"key":"e_1_3_2_1_41_1","unstructured":"Markus Voggenreiter Florian Angermeir Fabiola Moy\u00f3n Ulrich Sch\u00f6pp and Pierre Bonvin. 2022. Automated Security Findings Management: A Case Study in Industrial DevOps. In ICSE-SEIP \u201922. 11\u00a0pages."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"crossref","unstructured":"Markus Voggenreiter and Ulrich Sch\u00f6pp. 2022. Using a semantic knowledge base to improve the management of security reports in industrial DevOps projects. In ICSE-SEIP \u201922. 309\u2013310.","DOI":"10.1145\/3510457.3513065"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Roel\u00a0J. Wieringa. 2014. Design Science Methodology for Information Systems and Software Engineering.","DOI":"10.1007\/978-3-662-43839-8"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","unstructured":"Claes Wohlin. 2014. Guidelines for snowballing in systematic literature studies and a replication in software engineering. In EASE \u201914. Article 38 10\u00a0pages.","DOI":"10.1145\/2601248.2601268"}],"event":{"name":"ESEM '24: ACM \/ IEEE International Symposium on Empirical Software Engineering and Measurement","location":"Barcelona Spain","acronym":"ESEM '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 18th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3674805.3690748","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3674805.3690748","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T12:57:10Z","timestamp":1755867430000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3674805.3690748"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,24]]},"references-count":44,"alternative-id":["10.1145\/3674805.3690748","10.1145\/3674805"],"URL":"https:\/\/doi.org\/10.1145\/3674805.3690748","relation":{},"subject":[],"published":{"date-parts":[[2024,10,24]]},"assertion":[{"value":"2024-10-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}