{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:06:24Z","timestamp":1781103984556,"version":"3.54.1"},"reference-count":38,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,1]]},"abstract":"<jats:p>Although most organizations understand the need for application security at an abstract level, achieving adequate software security at the sharp end requires taking bold steps to address security practices within the organization. In the Agile software development world, a security engineering process is unacceptable if it is perceived to run counter to the agile values, and agile teams have thus approached software security activities in their own way. To improve security within agile settings requires that management understands the current practices of software security activities within their agile teams. In this study, the authors have used a survey instrument to investigate software security usage, competence, and training needs in two agile organizations. They find that (1) The two organizations perform differently in terms of core software security activities, but are similar when secondary activities that could be leveraged for security are considered (2) regardless of cost or benefit, skill drives the kind of activities that are performed (3) Secure design is expressed as the most important training need by all groups in both organizations (4) Effective software security adoption in agile setting is not automatic, it requires a driver.<\/jats:p>","DOI":"10.4018\/ijsse.2017010101","type":"journal-article","created":{"date-parts":[[2017,3,10]],"date-time":"2017-03-10T12:32:43Z","timestamp":1489149163000},"page":"1-27","source":"Crossref","is-referenced-by-count":14,"title":["A Lightweight Measurement of Software Security Skills, Usage and Training Needs in Agile Teams"],"prefix":"10.4018","volume":"8","author":[{"given":"Tosin Daniel","family":"Oyetoyan","sequence":"first","affiliation":[{"name":"Department of Software Engineering, Safety & Security, SINTEF Digital, Trondheim, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin Gilje","family":"Jaatun","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Safety & Security, SINTEF Digital, Trondheim, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniela Soares","family":"Cruzes","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Safety & Security, SINTEF Digital, Trondheim, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJSSE.2017010101-0","unstructured":"Adams, E. (2012). The Biggest Information Security Mistakes that Organizations Make and How to Avoid Making Them. Retrieved from https:\/\/web.securityinnovation.com\/the-biggest-information-security-mistakes-that-organizations-make"},{"key":"IJSSE.2017010101-1","unstructured":"Allen, J. (2005). Governing for enterprise security (CMU\/SEI-2005-TN-023). Retrieved from http:\/\/resources.sei.cmu.edu\/library\/asset-view.cfm?assetid=7453"},{"key":"IJSSE.2017010101-2","doi-asserted-by":"crossref","unstructured":"Aniche, M. F., & de Azevedo Silveira, G. (2011). Increasing learning in an agile environment: Lessons learned in an agile team. Paper presented at theAgile Conference (AGILE).","DOI":"10.1109\/AGILE.2011.13"},{"key":"IJSSE.2017010101-3","unstructured":"Arce, I., Clark-Fisher, K., Daswani, N., DelGrosso, J., Dhillon, D., Kern, C., . . . West, J. (2014). Avoiding The Top 10 Software Security Design Flaws. Retrieved from https:\/\/www.computer.org\/cms\/CYBSI\/docs\/Top-10-Flaws.pdf"},{"key":"IJSSE.2017010101-4","doi-asserted-by":"crossref","unstructured":"Ayalew, T., Kidane, T., & Carlsson, B. (2013). Identification and Evaluation of Security Activities in Agile Projects In Secure IT Systems (pp. 139\u2013153). Springer.","DOI":"10.1007\/978-3-642-41488-6_10"},{"key":"IJSSE.2017010101-5","doi-asserted-by":"publisher","DOI":"10.1109\/WICSA.2009.5290794"},{"key":"IJSSE.2017010101-6","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2015.45"},{"key":"IJSSE.2017010101-7","doi-asserted-by":"crossref","unstructured":"Baca, D., & Carlsson, B. (2011). Agile development with security engineering activities. Paper presented at the2011 International Conference on Software and Systems Process.","DOI":"10.1145\/1987875.1987900"},{"key":"IJSSE.2017010101-8","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.82"},{"key":"IJSSE.2017010101-9","doi-asserted-by":"publisher","DOI":"10.1109\/2.796139"},{"key":"IJSSE.2017010101-10","doi-asserted-by":"crossref","unstructured":"ben Othmane, L., Angin, P., Weffers, H., & Bhargava, B. (2014). Extending the agile development process to develop acceptably secure software. IEEE Transactions on Dependable and Secure Computing, 11(6), 497-509.","DOI":"10.1109\/TDSC.2014.2298011"},{"key":"IJSSE.2017010101-11","doi-asserted-by":"publisher","DOI":"10.1002\/0471750336"},{"key":"IJSSE.2017010101-12","unstructured":"Beznosov, K., & Kruchten, P. (2004). Towards agile security assurance. Paper presented at the2004 workshop on New security paradigms."},{"key":"IJSSE.2017010101-13","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-27662-9"},{"key":"IJSSE.2017010101-14","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2008.01.010"},{"key":"IJSSE.2017010101-15","doi-asserted-by":"publisher","DOI":"10.1023\/A:1009800404137"},{"key":"IJSSE.2017010101-16","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2008.01.006"},{"key":"IJSSE.2017010101-17","doi-asserted-by":"publisher","DOI":"10.1109\/METRIC.2004.1357905"},{"key":"IJSSE.2017010101-18","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2007.611"},{"key":"IJSSE.2017010101-19","author":"D. J.Greenwood","year":"2006","journal-title":"Introduction to action research: Social research for social change"},{"key":"IJSSE.2017010101-20","author":"M.Howard","year":"2006","journal-title":"The Security Development Lifecycle"},{"key":"IJSSE.2017010101-21","unstructured":"ISO\/IEC. (2009). Information technology -- Security techniques -- Evaluation criteria for IT security -- Part 1: Introduction and general model: ISO\/IEC 15408-1:2009."},{"key":"IJSSE.2017010101-22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32498-7_7"},{"key":"IJSSE.2017010101-23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-23318-5_7"},{"key":"IJSSE.2017010101-24","doi-asserted-by":"publisher","DOI":"10.1097\/00006199-199003000-00019"},{"key":"IJSSE.2017010101-25","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2004.1281254"},{"key":"IJSSE.2017010101-26","author":"G.McGraw","year":"2005","journal-title":"The 7 Touchpoints of Secure Software"},{"key":"IJSSE.2017010101-27","doi-asserted-by":"crossref","unstructured":"McGraw, G. (2006). Software Security: Building Security. Addison-Wesley Professional.","DOI":"10.1109\/ISSRE.2006.43"},{"key":"IJSSE.2017010101-28","unstructured":"McGraw, G., Migues, S., & West, J. (2016). Building Security In Maturity Model (BSIMM 7)."},{"key":"IJSSE.2017010101-29","unstructured":"Microsoft. (2012). Security Development Lifecycle for Agile Development. Retrieved from https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ee790621.aspx"},{"key":"IJSSE.2017010101-30","unstructured":"OWASP. (2006). CLASP concepts. Retrieved from https:\/\/www.owasp.org\/index.php\/CLASP_Concepts"},{"key":"IJSSE.2017010101-31","unstructured":"OWASP. (2016). Software Assurance Maturity Model. Retrieved from http:\/\/www.opensamm.org\/"},{"key":"IJSSE.2017010101-32","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2016.103"},{"key":"IJSSE.2017010101-33","unstructured":"Payment Card Industry. (2016). Payment Card Industry (PCI) Data Security Standard - Requirements and Security Assessment Procedures: PCI DSS v3.2."},{"key":"IJSSE.2017010101-34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24853-8_16"},{"key":"IJSSE.2017010101-35","author":"D.Rosenberg","year":"2003","journal-title":"Extreme programming refactored: the case against XP"},{"key":"IJSSE.2017010101-36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-27777-4_12"},{"key":"IJSSE.2017010101-37","doi-asserted-by":"publisher","DOI":"10.1145\/2445196.2445396"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=179641","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,19]],"date-time":"2019-09-19T11:57:20Z","timestamp":1568894240000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJSSE.2017010101"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2017,1]]},"references-count":38,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/ijsse.2017010101","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,1]]}}}