To main content

Collaborative security risk estimation in agile software development

Collaborative security risk estimation in agile software development

Category
Journal publication
Abstract
Today, agile software development teams in general do not adopt security risk-assessment practices in an ongoing manner to prioritize security work. Protection Poker is a collaborative and lightweight software security risk-estimation technique that is particularly suited for agile teams. Motivated by a desire to understand why security risk assessments have not yet gained widespread adoption in agile development, this study aims to assess to what extent the Protection Poker game would be accepted by agile teams and how it can be successfully integrated into the agile practices.
Language
English
Affiliation
  • Norwegian University of Science and Technology
  • SINTEF Digital / Software Engineering, Safety and Security
  • North Carolina State University
Year
2019
Published in
Information and Computer Security
ISSN
2056-4961
Publisher
Emerald
Volume
26
Issue
4