{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:48:58Z","timestamp":1781106538978,"version":"3.54.1"},"reference-count":24,"publisher":"IGI Global Scientific Publishing","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010,7]]},"abstract":"<jats:p>In this article, the authors contrast the results of a series of interviews with agile software development organizations with a case study of a distributed agile development effort, focusing on how information security is taken care of in an agile context. The interviews indicate that small and medium-sized agile software development organizations do not use any particular methodology to achieve security goals, even when their software is web-facing and potential targets of attack. This case study confirms that even in cases where security is an articulated requirement, and where security design is fed as input to the implementation team, there is no guarantee that the end result meets the security objectives. The authors contend that security must be built as an intrinsic software property and emphasize the need for security awareness throughout the whole software development lifecycle. This paper suggests two extensions to agile methodologies that may contribute to ensuring focus on security during the complete lifecycle.<\/jats:p>","DOI":"10.4018\/jsse.2010070105","type":"journal-article","created":{"date-parts":[[2010,9,7]],"date-time":"2010-09-07T22:47:20Z","timestamp":1283899640000},"page":"71-85","source":"Crossref","is-referenced-by-count":13,"title":["Agile Software Development"],"prefix":"10.4018","volume":"1","author":[{"given":"Torstein","family":"Nicolaysen","sequence":"first","affiliation":[{"name":"NTNU, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Richard","family":"Sassoon","sequence":"additional","affiliation":[{"name":"NTNU, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maria B.","family":"Line","sequence":"additional","affiliation":[{"name":"SINTEF ICT, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin Gilje","family":"Jaatun","sequence":"additional","affiliation":[{"name":"SINTEF ICT, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2010070105-0","unstructured":"Beznosov, K. (2003). eXtreme Security Engineering: On Employing XP Practices to Achieve \u201cGood Enough Security\u201d without Defining It. Paper presented at the First ACM Workshop on Business Driven Security Engineering (BizSec)."},{"key":"jsse.2010070105-1","unstructured":"Beznosov, K., & Kruchten, P. (2004). Towards Agile Security Assurance. Paper presented at the New Security Paradigms Workshop, Nova Scotia, Canada."},{"key":"jsse.2010070105-2","doi-asserted-by":"publisher","DOI":"10.1109\/2.962984"},{"key":"jsse.2010070105-3","doi-asserted-by":"crossref","unstructured":"Bostr\u00f6m, G., W\u00e4yrynen, J., Bod\u00e9n, M., Beznosov, K., & Kruchten, P. (2006). Extending XP practices to support security requirements engineering. Paper presented at the Proceedings of the 2006 international workshop on Software engineering for secure systems (SESS '06).","DOI":"10.1145\/1137627.1137631"},{"key":"jsse.2010070105-4","unstructured":"Cheswick, B. (1990). The Design of a Secure Internet Gateway. Paper presented at the USENIX Conference."},{"key":"jsse.2010070105-5","unstructured":"Directive 95\/94\/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data. (1995). Retrieved October 6, 2008, from http:\/\/eur-lex.europa.eu\/LexUriServ\/LexUriServ.do?uri=CELEX:31995L0046:EN:HTML"},{"key":"jsse.2010070105-6","unstructured":"EPTA. (2006). ICT and Privacy in Europe, Experiences from technology assessment of ICT and Privacy in seven different European countries. Retrieved September 23, 2008, from http:\/\/epub.oeaw.ac.at\/ita\/ita-projektberichte\/e2-2a44.pdf"},{"key":"jsse.2010070105-7","first-page":"3","article-title":"A framework for an institutional high level security policy for the processing of medical data and their transmission through the Internet.","author":"C.Ilioudis","year":"2001","journal-title":"Journal of Medical Internet Research"},{"key":"jsse.2010070105-8","unstructured":"ISO. (2005). Evaluation criteria for IT security Part 1: Introduction and general model (Tech. Rep. No. 15408-1). Geneva, Switzerland: ISO\/IEC."},{"key":"jsse.2010070105-9","doi-asserted-by":"crossref","unstructured":"Keramati, H., & Mirian-Hosseinabadi, S. H. (2008). Integrating software development security activities with agile methodologies.","DOI":"10.1109\/AICCSA.2008.4493611"},{"key":"jsse.2010070105-10","unstructured":"Lipner, S., & Howard, M. (2005). The Trustworthy Computing Security Development Lifecycle. Retrieved from http:\/\/msdn2.microsoft.com\/en-us\/library\/ms995349.aspx"},{"key":"jsse.2010070105-11","author":"R. C.Martin","year":"2008","journal-title":"Clean Code: A Handbook of Agile Software Craftsmanship"},{"key":"jsse.2010070105-12","doi-asserted-by":"publisher","DOI":"10.2196\/jmir.3.1.e9"},{"key":"jsse.2010070105-13","author":"G.McGraw","year":"2006","journal-title":"Software Security: Building Security"},{"key":"jsse.2010070105-14","unstructured":"Microsoft. (n.d.). Windows Azure Platform. Retrieved February 19, 2010, from http:\/\/www.microsoft.com\/windowsazure\/"},{"key":"jsse.2010070105-15","unstructured":"Narraine, R. (2006). Hacker Discovers Adobe PDF Back Doors. Retrieved from http:\/\/www.eweek.com\/c\/a\/Security\/Hacker-Discovers-Adobe-PDF-Back-Doors\/"},{"key":"jsse.2010070105-16","unstructured":"OWASP. (2007). Top 10 2007. Retrieved July 10, 2008, from http:\/\/www.owasp.org\/index.php\/Top_10_2007"},{"key":"jsse.2010070105-17","unstructured":"Peeters, J. (2005). Agile Security Requirements Engineering. Paper presented at the Symposium on Requirements Engineering for Information Security."},{"key":"jsse.2010070105-18","first-page":"12","article-title":"XP in a Safety-Critical Environment.","volume":"15","author":"M.Poppendieck","year":"2002","journal-title":"Cutter IT Journal"},{"key":"jsse.2010070105-19","unstructured":"Sassoon, R., Jaatun, M. G., & Jensen, J. (2010). The road to Hell is covered with good intentions: A story of (in)secure software engineering. Paper presented at the 4th International Workshop of Secure Software Engineering (SecSE 2010)."},{"key":"jsse.2010070105-20","unstructured":"Scrum Alliance, I. (2009). What is Scrum? Retrieved March 23, 2010, from http:\/\/www.scrumalliance.org\/learn_about_scrum"},{"key":"jsse.2010070105-21","doi-asserted-by":"crossref","unstructured":"Siponen, M., Baskerville, R., & Kuivalainen, T. (2005). Integrating Security into Agile Development Methods. Paper presented at the Hawaii International Conference on System Sciences, HI.","DOI":"10.1109\/HICSS.2005.329"},{"key":"jsse.2010070105-22","unstructured":"Sullivan, B. (2008). Agile SDL: Streamline Security Practices for Agile Development. msdn Magazine. Retrieved from http:\/\/msdn.microsoft.com\/en-us\/magazine\/dd153756.aspx van der Haak, M., Wolff, A. C., Brandner, R., Drings, P., Wannenmacher, M., & Wetter, T. (2003). Data security and protection in cross-institutional electronic patient records. International Journal of Medical Informatics, 70(2\/3), 117-130."},{"key":"jsse.2010070105-23","unstructured":"W\u00e4yrynen, J., Boden, M., & Bostr\u00f6m, G. (2004). Security engineering and eXtreme programming: An impossible marriage? In Proceedings of the Extreme Programming and Agile Methods - Xp\/ Agile Universe 2004 (Vol. 3134, pp. 117-128). Berlin: Springer Verlag."}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=46153","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,3]],"date-time":"2019-06-03T23:29:57Z","timestamp":1559604597000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2010070105"}},"subtitle":["The Straight and Narrow Path to Secure Software?"],"short-title":[],"issued":{"date-parts":[[2010,7]]},"references-count":24,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2010070105","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010,7]]}}}