{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:24:34Z","timestamp":1781105074041,"version":"3.54.1"},"reference-count":19,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,1]]},"abstract":"<jats:p>Security concerns are increasingly guiding both the design and processes of software-intensive product development. In certain environments, the development of the product requires special security arrangements for development processes, product release, maintenance and hosting, and specific security-oriented processes and governance. Integrating the security engineering processes into agile development methods can have the effect of mitigating the agile methods' intended benefits. This article describes a case of a large ICT service provider building a secure identity management system for a sizable government agency. The project was a subject to strict security regulations due to the end product's critical role. The project was a multi-team, multi-site, standard-regulated security engineering and development work executed following the Scrum framework. The study reports the difficulties in combining security engineering with agile development, provides propositions to enhance Scrum for security engineering activities. Also, an evaluation of the effects of the security work on project cost presented.<\/jats:p>","DOI":"10.4018\/ijsse.2017010103","type":"journal-article","created":{"date-parts":[[2017,3,10]],"date-time":"2017-03-10T12:32:43Z","timestamp":1489149163000},"page":"43-57","source":"Crossref","is-referenced-by-count":5,"title":["Case Study of Agile Security Engineering"],"prefix":"10.4018","volume":"8","author":[{"given":"Kalle","family":"Rindell","sequence":"first","affiliation":[{"name":"Informaatioteknologian laitos, University of Turku, Turku, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sami","family":"Hyrynsalmi","sequence":"additional","affiliation":[{"name":"Tampere University of Technology, Pori, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ville","family":"Lepp\u00e4nen","sequence":"additional","affiliation":[{"name":"Informaatioteknologian laitos, University of Turku, Turku, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJSSE.2017010103-0","unstructured":"Alnatheer, A., Gravell, A., & Argles, D. (2010). Agile security issues: A research study. Proceedings of the 5th International Doctoral Symposium on Empirical Software Engineering (IDoESE)."},{"key":"IJSSE.2017010103-1","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1145\/1987875.1987900","article-title":"Agile development with security engineering activities.","author":"D.Baca","year":"2011","journal-title":"Proceedings of the 2011 International Conference on Software and Systems Process, ICSSP '11"},{"key":"IJSSE.2017010103-2","unstructured":"Beznosov, K., & Kruchten, P. (2004). Towards agile security assurance. Proceedings of the 2004 workshop on New security paradigms NSPW '04 (pp. 47-54)."},{"key":"IJSSE.2017010103-3","author":"J. W.Creswell","year":"2003","journal-title":"Research Design: Qualitative and Quantitative and Mixed Methods Approaches"},{"key":"IJSSE.2017010103-4","doi-asserted-by":"crossref","unstructured":"Diaz, J., Garbajosa, J., & Calvo-Manzano, J. A. (2009). Mapping CMMI Level 2 to Scrum Practices: An Experience Report. In Software Process Improvement, CIS (Vol. 42, pp. 93-104).","DOI":"10.1007\/978-3-642-04133-4_8"},{"key":"IJSSE.2017010103-5","doi-asserted-by":"publisher","DOI":"10.1145\/2593812.2593813"},{"key":"IJSSE.2017010103-6","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606635"},{"key":"IJSSE.2017010103-7","unstructured":"FMoF. (2009) ICT-toiminnan varautuminen h\u00e4iri\u00f6- ja erityistilanteisiin. Retrieved from https:\/\/www.vahtiohje.fi\/web\/guest\/2\/2009-ict-toiminnan-varautuminen-hairio-ja-erityistilanteisiin"},{"key":"IJSSE.2017010103-8","unstructured":"FMoF. (2012) Requirements for ICT Contingency Planning. Retrieved from https:\/\/www.vahtiohje.fi\/web\/guest\/2b\/2012-requirements-for-ict-contingency-planning"},{"key":"IJSSE.2017010103-9","unstructured":"FMoF. (2012) Teknisen ymp\u00e4rist\u00f6n tietoturvataso-ohje. Retrieved from https:\/\/www.vahtiohje.fi\/web\/guest\/3\/2012-teknisen-ympariston-tietoturvataso-ohje"},{"key":"IJSSE.2017010103-10","unstructured":"FMoF. (2013) Sovelluskehityksen tietoturvaohje. Retrieved from https:\/\/www.vahtiohje.fi\/web\/guest\/vahti-1\/2013-sovelluskehityksen-tietoturvaohje"},{"key":"IJSSE.2017010103-11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-73101-6_42"},{"key":"IJSSE.2017010103-12","unstructured":"ISO\/IEC. (2008). Information Technology - Security Techniques - Systems Security Engineering - Capability Maturity Model (SSE-CMM) ISO\/IEC 21817:2008."},{"key":"IJSSE.2017010103-13","unstructured":"ISO\/IEC. (2013). Information Technology - Security Techniques - Code of Practice for Information Security Controls. ISO\/IEC 27002:2013."},{"key":"IJSSE.2017010103-14","author":"P.Pietik\u00e4inen","year":"2014","journal-title":"Handbook of the Secure Agile Software Development Life Cycle"},{"key":"IJSSE.2017010103-15","doi-asserted-by":"publisher","DOI":"10.1145\/2812428.2812431"},{"key":"IJSSE.2017010103-16","first-page":"236","article-title":"). Securing Scrum for VAHTI.","author":"K.Rindell","year":"2015","journal-title":"Proceedings"},{"key":"IJSSE.2017010103-17","unstructured":"VersionOne. (2016). 10th annual state of agile survey. Retrieved from https:\/\/versionone.com\/pdf\/VersionOne-10th-Annual-State-of-Agile-Report.pdf"},{"key":"IJSSE.2017010103-18","author":"R. K.Yin","year":"2003","journal-title":"Case Study Research: Design and Methods"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=179643","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,22]],"date-time":"2023-08-22T11:47:21Z","timestamp":1692704841000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJSSE.2017010103"}},"subtitle":["Building Identity Management for a Government Agency"],"short-title":[],"issued":{"date-parts":[[2017,1]]},"references-count":19,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/ijsse.2017010103","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,1]]}}}