To main content

Myths and Facts About Static Application Security Testing Tools: An Action Research at Telenor Digital

Abstract

It is claimed that integrating agile and security in practice is challenging. There is the notion that security is a heavy process, requires expertise, and consumes developers’ time. These contrast with the agile vision. Regardless of these challenges, it is important for organizations to address security within their agile processes since critical assets must be protected against attacks. One way is to integrate tools that could help to identify security weaknesses during implementation and suggest methods to refactor them. We used quantitative and qualitative approaches to investigate the efficiency of the tools and what they mean to the actual users (i.e. developers) at Telenor Digital. Our findings, although not surprising, show that several barriers exist both in terms of tool’s performance and developers’ perceptions. We suggest practical ways for improvement.
Read publication

Category

Academic chapter/article/Conference paper

Client

  • Research Council of Norway (RCN) / 247678

Language

English

Author(s)

  • Tosin Daniel Oyetoyan
  • Bisera Milosheska
  • Mari Grini
  • Daniela Soares Cruzes

Affiliation

  • SINTEF Digital / Software Engineering, Safety and Security
  • Telenor

Year

2018

Publisher

Springer

Book

Agile Processes in Software Engineering and Extreme Programming, 19th International Conference, XP 2018, Proceedings

Issue

314

ISBN

978-3-319-91601-9

Page(s)

86 - 103

View this publication at Cristin