{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:14:17Z","timestamp":1781108057093,"version":"3.54.1"},"reference-count":48,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,1]]},"abstract":"<jats:p>Security objectives in software development are increasingly convergent with the business objectives, as requirements for privacy and the cost of security incidents call for more dependable software products. The development of secure software is accomplished by augmenting the software development process with specific security engineering activities. Security engineering, in contrast to the iterative and incremental software development processes, is characterized by sequential life cycle models: the security objectives are thus to be achieved by conflicting approaches. In this study, to identify the incompatibilities between the approaches, the security engineering activities from Microsoft SDL, the ISO Common Criteria and OWASP SAMM security engineering models are mapped into common agile software development processes, practices and artifacts.<\/jats:p>","DOI":"10.4018\/ijsssp.2018010103","type":"journal-article","created":{"date-parts":[[2019,1,7]],"date-time":"2019-01-07T16:28:07Z","timestamp":1546878487000},"page":"47-70","source":"Crossref","is-referenced-by-count":1,"title":["Fitting Security into Agile Software Development"],"prefix":"10.4018","volume":"9","author":[{"given":"Kalle","family":"Rindell","sequence":"first","affiliation":[{"name":"Informaatioteknologian laitos, University of Turku, Turku, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5073-3750","authenticated-orcid":true,"given":"Sami","family":"Hyrynsalmi","sequence":"additional","affiliation":[{"name":"Tampere University of Technology, Pori, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ville","family":"Lepp\u00e4nen","sequence":"additional","affiliation":[{"name":"Department of Information Technology, University of Turku, Turku, Finland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJSSSP.2018010103-0","unstructured":"Abrahamsson, P., Salo, O., Ronkainen, J., & Warsta, J. (2002). Agile software development methods - review and analysis. Technical Report 478, VTT Publications."},{"key":"IJSSSP.2018010103-1","author":"S. W.Ambler","year":"2012","journal-title":"Disciplined Agile Delivery: A Practitioner\u2019s Guide to Agile Software Delivery in the Enterprise"},{"key":"IJSSSP.2018010103-2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-41488-6_10"},{"key":"IJSSSP.2018010103-3","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1145\/1987875.1987900","article-title":"Agile development with security engineering activities.","author":"D.Baca","year":"2011","journal-title":"Proceedings of the 2011 International Conference on Software and Systems Process, ICSSP \u201911"},{"key":"IJSSSP.2018010103-4","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-25590-7_1"},{"key":"IJSSSP.2018010103-5","author":"K.Beck","year":"2000","journal-title":"Extreme Programming Explained: Embrace Change"},{"issue":"2","key":"IJSSSP.2018010103-6","first-page":"12","article-title":"How to agilely architect an agile architecture.","volume":"27","author":"S.Bellomo","year":"2014","journal-title":"Cutter IT Journal"},{"key":"IJSSSP.2018010103-7","first-page":"47","article-title":"Towards agile security assurance.","author":"K.Beznosov","year":"2004","journal-title":"NSPW \u201904 Proceedings of the 2004 workshop on new security paradigms"},{"key":"IJSSSP.2018010103-8","doi-asserted-by":"publisher","DOI":"10.1002\/sys.20044"},{"key":"IJSSSP.2018010103-9","author":"B.Boehm","year":"2003","journal-title":"Balancing Agility and Discipline: A Guide for the Perplexed"},{"key":"IJSSSP.2018010103-10","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2003.1204376"},{"key":"IJSSSP.2018010103-11","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2005.129"},{"key":"IJSSSP.2018010103-12","unstructured":"CMMI. (2017). The CMMI institute. Retrieved from http:\/\/cmmiinstitute.com\/"},{"key":"IJSSSP.2018010103-13","unstructured":"Cockburn, A. & Williams, L. (2000). The costs and benefits of pair programming. Extreme programming examined, 8, 223\u2013247."},{"key":"IJSSSP.2018010103-14","unstructured":"Common Criteria Recognition Arrangement (CCRA). (2018). The common criteria. Retrieved from https:\/\/www.commoncriteriaportal.org\/cc\/"},{"key":"IJSSSP.2018010103-15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04133-4_8"},{"key":"IJSSSP.2018010103-16","doi-asserted-by":"crossref","unstructured":"Dijkstra, E. W. (1982). Selected Writings on Computing: Perspective. Springer-Verlag.","DOI":"10.1007\/978-1-4612-5695-3"},{"key":"IJSSSP.2018010103-17","year":"1983","journal-title":"Trusted computer system evaluation criteria"},{"key":"IJSSSP.2018010103-18","year":"1985","journal-title":"Guidance for applying the department of defense trusted computer system evaluation criteria in specific environments"},{"key":"IJSSSP.2018010103-19","doi-asserted-by":"publisher","DOI":"10.1145\/2593812.2593813"},{"key":"IJSSSP.2018010103-20","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2001.922739"},{"key":"IJSSSP.2018010103-21","article-title":"Technical debt and agile software development practices and processes: An industry practitioner survey.","author":"J.Holvitie","year":"2017","journal-title":"Information and Software Technology"},{"key":"IJSSSP.2018010103-22","author":"M.Howard","year":"2006","journal-title":"The Security Development Lifecycle"},{"key":"IJSSSP.2018010103-23","unstructured":"ISO\/IEC standard 15408-1:2009. (2009). Information technology \u2013 Security techniques \u2013 Evaluation criteria for IT security. ISO\/IEC."},{"key":"IJSSSP.2018010103-24","unstructured":"ISO\/IEC standard 21827. (2008). Information Technology \u2013 Security Techniques \u2013 Systems Security Engineering \u2013 Capability Maturity Model (SSE-CMM). ISO\/IEC."},{"key":"IJSSSP.2018010103-25","author":"P.J\u00e4rvinen","year":"2004","journal-title":"On a variety of research output types. Series of Publications D \u2013 Net Publications D\u20132004\u20136"},{"key":"IJSSSP.2018010103-26","author":"P.J\u00e4rvinen","year":"2004","journal-title":"Research questions guiding selection of an appropriate research method. Series of Publications D \u2013 Net Publications D\u20132004\u20135"},{"key":"IJSSSP.2018010103-27","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC.2016.062"},{"key":"IJSSSP.2018010103-28","doi-asserted-by":"publisher","DOI":"10.1145\/3230833.3233765"},{"key":"IJSSSP.2018010103-29","unstructured":"Microsoft. (2017). Security Development Lifecycle. Agile development using Microsoft security development. Retrieved from https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ee790621.asp"},{"key":"IJSSSP.2018010103-30","unstructured":"OWASP. (2017). Software assurance maturity model (SAMM). Retrieved from https:\/\/www.owasp.org\/images\/6\/6f\/SAMM_Core_V1-5_FINAL.pdf"},{"key":"IJSSSP.2018010103-31","unstructured":"OWASP. (2018). OWASP Top 10 Application Security Risks. Retrieved from https:\/\/www.owasp.org\/index.php\/Top_10-2017_Top_10"},{"key":"IJSSSP.2018010103-32","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2016.103"},{"key":"IJSSSP.2018010103-33","doi-asserted-by":"publisher","DOI":"10.1109\/52.965798"},{"key":"IJSSSP.2018010103-34","doi-asserted-by":"publisher","DOI":"10.1111\/j.1365-2575.2007.00259.x"},{"key":"IJSSSP.2018010103-35","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3103170"},{"key":"IJSSSP.2018010103-36","doi-asserted-by":"publisher","DOI":"10.1145\/2372251.2372275"},{"issue":"12","key":"IJSSSP.2018010103-37","first-page":"1679","article-title":"Risk-driven security metrics in agile software development - an industrial pilot study.","volume":"18","author":"R. M.Savola","year":"2012","journal-title":"J-JUCS"},{"key":"IJSSSP.2018010103-38","unstructured":"Schwaber, K. (1995). Scrum development process. OOPSLA\u201995 workshop on business object design and implementation."},{"key":"IJSSSP.2018010103-39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-30350-0_1"},{"key":"IJSSSP.2018010103-40","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2010.07.006"},{"key":"IJSSSP.2018010103-41","unstructured":"Synopsys Software Integrity Group. (2017). The building security in maturity model. Retrieved from https:\/\/www.bsimm.com\/"},{"key":"IJSSSP.2018010103-42","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2008.19"},{"key":"IJSSSP.2018010103-43","first-page":"34","article-title":"Managing security work in scrum: Tensions and challenges.","author":"S.T\u00fcrpe","year":"2017","journal-title":"Proceedings of the International Workshop on Secure Software Engineering in DevOps and Agile Development (SecSE 2017)"},{"key":"IJSSSP.2018010103-44","unstructured":"VersionOne. (2017). 11th annual state of agile survey. Retrieved from https:\/\/versionone.com\/pdf\/VersionOne-11th-Annual-State-of-Agile-Report.pdf"},{"key":"IJSSSP.2018010103-45","author":"J.Viega","year":"2002","journal-title":"Building Secure Software: How to Avoid Security Problems the Right Way"},{"key":"IJSSSP.2018010103-46","unstructured":"Wake, W. (2003). Invest in good stories, and smart tasks."},{"key":"IJSSSP.2018010103-47","doi-asserted-by":"publisher","DOI":"10.1109\/MAHC.2015.21"}],"container-title":["International Journal of Systems and Software Security and Protection"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=221158","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,12]],"date-time":"2023-09-12T14:45:59Z","timestamp":1694529959000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJSSSP.2018010103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2018,1]]},"references-count":48,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/ijsssp.2018010103","relation":{},"ISSN":["2640-4265","2640-4273"],"issn-type":[{"value":"2640-4265","type":"print"},{"value":"2640-4273","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,1]]}}}