AGILE AND SECURE SOFTWARE DEVELOPMENT: AN UNFINISHED STORY

7Citations
Citations of this article
25Readers
Mendeley users who have this article in their library.

Abstract

Given the widespread adoption of agile methods and the rising number of software vulnerabilities, we analyze the literature with an interest in the effect of security practices on software development agility. We propose a novel taxonomy to systematize the body of knowledge around secure agile development and then organize and summarize the selected research using the new taxonomy. At a high-level we create two categories, Phase Focused and Phase Independent. The Phase Focused category is then subdivided along the traditional SDLC phases. The Phase Independent category spans all phases of the SDLC or is phase independent. We conclude that, although there is a significant body of literature on the topic, the story is unfinished. There is further investigation needed to ensure agility as secure development practices are adopted and in regard to empirical evaluations of the proposed agile and secure software development integration approaches.

Cite

CITATION STYLE

APA

Bishop, D., & Rowland, P. (2019). AGILE AND SECURE SOFTWARE DEVELOPMENT: AN UNFINISHED STORY. Issues in Information Systems, 20(1), 144–156. https://doi.org/10.48009/1_iis_2019_144-156

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free