{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:23:06Z","timestamp":1781104986834,"version":"3.54.1"},"reference-count":51,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,1,1]]},"abstract":"<p>Security requirement work plays a key role in achieving cost-effective and adequate security in a software development project. Knowledge about software companies' experiences of security requirement work is important in order to bridge the observed gap between software security practices and security risks in many projects today. Particularly, such knowledge can help researchers improve on available practices and recommendations. This article uses the results of published empirical studies on security requirement work to create a conceptual framework that shows key concepts related to work context, this work itself and the effects of this work. The resulting framework points to the following research challenges: 1) Identifying and understanding factors important for the effect of security requirements work; 2) Understanding what is the importance of the chosen requirements approach itself, and; 3) Properly taking into account contextual factors, especially factors related to individuals and interactions, in planning and analysis of empirical studies on security requirements work.<\/p>","DOI":"10.4018\/ijsssp.2020010103","type":"journal-article","created":{"date-parts":[[2020,2,21]],"date-time":"2020-02-21T10:47:02Z","timestamp":1582282022000},"page":"33-62","source":"Crossref","is-referenced-by-count":4,"title":["Towards a Conceptual Framework for Security Requirements Work in Agile Software Development"],"prefix":"10.4018","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7599-0342","authenticated-orcid":true,"given":"Inger Anne","family":"T\u00f8ndel","sequence":"first","affiliation":[{"name":"Department of Computer Science, Norwegian University of Science and Technology (NTNU), Trondheim, Norway & SINTEF Digital, Trondheim, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7127-6694","authenticated-orcid":true,"given":"Martin Gilje","family":"Jaatun","sequence":"additional","affiliation":[{"name":"SINTEF Digital, Oslo, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJSSSP.2020010103-0","doi-asserted-by":"publisher","DOI":"10.1109\/QUATIC.2016.028"},{"key":"IJSSSP.2020010103-1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-54045-0_17"},{"key":"IJSSSP.2020010103-2","doi-asserted-by":"publisher","DOI":"10.1007\/11774129_16"},{"key":"IJSSSP.2020010103-3","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2015.45"},{"key":"IJSSSP.2020010103-4","doi-asserted-by":"crossref","unstructured":"Baca, D., & Carlsson, B. (2011). Agile development with security engineering activities. In Proceedings of the 2011 international conference on software and systems process (pp. 149\u2013158). Academic Press.","DOI":"10.1145\/1987875.1987900"},{"key":"IJSSSP.2020010103-5","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.82"},{"key":"IJSSSP.2020010103-6","unstructured":"Beck, K., Beedle, M., Van Bennekum, A., Cockburn, A., Cunningham, W., Fowler, M., . . .. others (2001). Manifesto for agile software development. Retrieved from http:\/\/www.agilemanifesto.org"},{"key":"IJSSSP.2020010103-7","doi-asserted-by":"crossref","unstructured":"Bellomo, S., & Woody, C. (2012). DoD Information Assurance and Agile: Challenges and Recommendations Gathered Through Interviews with Agile Program Managers and DoD Accreditation Reviewers. Carnegie-Melon University.","DOI":"10.21236\/ADA585502"},{"key":"IJSSSP.2020010103-8","unstructured":"Beznosov, K. (2003, October). Extreme security engineering: On employing XP practices to achieve\u2019good enough security\u2019without defining it. In Proceedings of theFirst ACM Workshop on Business Driven Security Engineering (BizSec). Academic Press."},{"issue":"1","key":"IJSSSP.2020010103-9","article-title":"Agile and secure software development: An unfinished story.","volume":"20","author":"D.Bishop","year":"2019","journal-title":"Issues in Information Systems"},{"key":"IJSSSP.2020010103-10","author":"H.Collins","year":"2019","journal-title":"Forms of Life: The Method and Meaning of Sociology"},{"key":"IJSSSP.2020010103-11","doi-asserted-by":"crossref","unstructured":"Daneva, M., & Wang, C. (2018, August). Security requirements engineering in the agile era: How does it work in practice? In Proceedings of the 2018 IEEE 1st International Workshop on Quality Requirements in Agile Projects (QuaRAP) (pp. 10-13). IEEE.","DOI":"10.1109\/QuaRAP.2018.00008"},{"key":"IJSSSP.2020010103-12","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2016.06.013"},{"key":"IJSSSP.2020010103-13","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606635"},{"key":"IJSSSP.2020010103-14","doi-asserted-by":"publisher","DOI":"10.3837\/tiis.2014.02.019"},{"key":"IJSSSP.2020010103-15","doi-asserted-by":"crossref","unstructured":"Hanssen, G. K., St\u00e5lhane, T., & Myklebust, T. (2018). SafescrumOR -agile development of safety-critical software. Springer.","DOI":"10.1007\/978-3-319-99334-8"},{"key":"IJSSSP.2020010103-16","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2018.06.004"},{"key":"IJSSSP.2020010103-17","author":"M.Howard","year":"2006","journal-title":"The security development lifecycle"},{"key":"IJSSSP.2020010103-18","doi-asserted-by":"publisher","DOI":"10.1177\/160940690900800406"},{"issue":"8","key":"IJSSSP.2020010103-19","first-page":"3032","article-title":"A review on factors influencing implementation of secure software development practices.","volume":"10","author":"S. L.Kanniah","year":"2016","journal-title":"International Journal of Computer and Systems Engineering"},{"key":"IJSSSP.2020010103-20","unstructured":"Kanniah, S. L., & Mahrin, M. N. (2018). Secure software development practice adoption model: A delphi study. Journal of Telecommunication, Electronic and Computer Engineering (JTEC), 10(2-8), 71\u201375."},{"issue":"3","key":"IJSSSP.2020010103-21","article-title":"A review of security integration technique in agile software development.","volume":"7","author":"R.Khaim","year":"2016","journal-title":"International Journal of Software Engineering and Its Applications"},{"key":"IJSSSP.2020010103-22","doi-asserted-by":"crossref","first-page":"805","DOI":"10.1145\/1176617.1176727","article-title":"Towards agile security in web applications.","author":"V.Kongsli","year":"2006","journal-title":"Companion to the 21st ACM SIGPLAN symposium on object-oriented programming systems, languages, and applications"},{"key":"IJSSSP.2020010103-23","author":"D.Leffingwell","year":"2010","journal-title":"Agile software requirements: lean requirements practices for teams, programs, and the enterprise"},{"key":"IJSSSP.2020010103-24","volume":"Vol. 41","author":"J. A.Maxwell","year":"2013","journal-title":"Qualitative research design: An interactive approach"},{"key":"IJSSSP.2020010103-25","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2004.1281254"},{"key":"IJSSSP.2020010103-26","author":"G.McGraw","year":"2006","journal-title":"Software Security: Building Security In"},{"key":"IJSSSP.2020010103-27","author":"G.McGraw","year":"2018","journal-title":"BSIMM 9"},{"key":"IJSSSP.2020010103-28","unstructured":"Microsoft. (2009, June 30). Security development lifecycle for agile development, version 1.0."},{"key":"IJSSSP.2020010103-29","unstructured":"Microsoft. (n.d.). Microsoft security development lifecycle (No. Accessed 2019.08.07). Retrieved from https:\/\/www.microsoft.com\/en-us\/SDL"},{"key":"IJSSSP.2020010103-30","author":"M. B.Miles","year":"1994","journal-title":"Qualitative data analysis: An expanded sourcebook"},{"issue":"3","key":"IJSSSP.2020010103-31","first-page":"1","article-title":"Comparison of modern techniques for analyzing NFRs in Agile: A systematic literature review.","volume":"3","author":"S. U.Muneer","year":"2019","journal-title":"Journal of Software Engineering Practice"},{"key":"IJSSSP.2020010103-32","doi-asserted-by":"publisher","DOI":"10.4018\/jsse.2010070105"},{"key":"IJSSSP.2020010103-33","doi-asserted-by":"crossref","unstructured":"Oueslati, H., Rahman, M. M., & ben Othmane, L. (2015). Literature review of the challenges of developing secure software using the agile approach. In Proceedings of the 10th international conference on availability, reliability and security (ARES) (pp. 540\u2013547).","DOI":"10.1109\/ARES.2015.69"},{"key":"IJSSSP.2020010103-34","article-title":"Software assurance maturity model - a guide to building security into software development. version 1.5 (Tech. Rep.).","journal-title":"Open Web Application Security Project."},{"key":"IJSSSP.2020010103-35","unstructured":"Peeters, J. (2005). Agile security requirements engineering. In Proceedings of theSymposium on requirements engineering for information security. Academic Press."},{"key":"IJSSSP.2020010103-36","unstructured":"Pohl, C., & Hof, H.-J. (2015). Secure scrum: Development of secure software with scrum."},{"key":"IJSSSP.2020010103-37","doi-asserted-by":"publisher","DOI":"10.1145\/2998181.2998191"},{"key":"IJSSSP.2020010103-38","doi-asserted-by":"publisher","DOI":"10.1145\/3230833.3233276"},{"key":"IJSSSP.2020010103-39","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2015.96"},{"key":"IJSSSP.2020010103-40","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2016.45"},{"key":"IJSSSP.2020010103-41","author":"C.Robson","year":"2011","journal-title":"Real World Research"},{"key":"IJSSSP.2020010103-42","doi-asserted-by":"publisher","DOI":"10.1109\/CONFLUENCE.2017.7943152"},{"key":"IJSSSP.2020010103-43","unstructured":"Saldanha, L. R., & Zorzo, A. (2019). Security requirements in agile software development: a systematic mapping study. Pontifical Catholic University of Rio Grande Do Sul, 2019, 32p."},{"issue":"12","key":"IJSSSP.2020010103-44","first-page":"1679","article-title":"Risk-driven security metrics in agile software development-an industrial pilot study.","volume":"18","author":"R. M.Savola","year":"2012","journal-title":"J. UCS"},{"key":"IJSSSP.2020010103-45","doi-asserted-by":"crossref","unstructured":"Terpstra, E., Daneva, M., & Wang, C. (2017). Agile practitioners\u2019 understanding of security requirements: Insights from a grounded theory analysis. In Proceedings of the 2017 IEEE 25th international requirements engineering conference workshops (REW) (pp. 439\u2013442). IEEE Press.","DOI":"10.1109\/REW.2017.54"},{"key":"IJSSSP.2020010103-46","doi-asserted-by":"publisher","DOI":"10.4018\/IJSSE.2017100101"},{"key":"IJSSSP.2020010103-47","doi-asserted-by":"publisher","DOI":"10.1145\/3239235.3267426"},{"key":"IJSSSP.2020010103-48","doi-asserted-by":"publisher","DOI":"10.1109\/SEAA.2018.00080"},{"key":"IJSSSP.2020010103-49","doi-asserted-by":"crossref","unstructured":"Williams, L., Gegick, M., & Meneely, A. (2009). Protection poker: Structuring software security risk assessment and knowledge transfer. In Proceedings of the International symposium on engineering secure software and systems (pp. 122\u2013134). Academic Press.","DOI":"10.1007\/978-3-642-00199-4_11"},{"key":"IJSSSP.2020010103-50","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.58"}],"container-title":["International Journal of Systems and Software Security and Protection"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=249764","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,6]],"date-time":"2022-05-06T17:17:33Z","timestamp":1651857453000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJSSSP.2020010103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2020,1,1]]},"references-count":51,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2020,1]]}},"URL":"https:\/\/doi.org\/10.4018\/ijsssp.2020010103","relation":{},"ISSN":["2640-4265","2640-4273"],"issn-type":[{"value":"2640-4265","type":"print"},{"value":"2640-4273","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,1,1]]}}}