Abstract
Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Consid-ering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.
Dokumententyp: | Konferenzbeitrag (Paper) |
---|---|
Fakultät: | Mathematik, Informatik und Statistik > Informatik |
Themengebiete: | 000 Informatik, Informationswissenschaft, allgemeine Werke > 004 Informatik |
ISBN: | 979-8-3503-2263-7 ; 979-8-3503-2264-4 |
Ort: | Piscataway, NJ |
Sprache: | Englisch |
Dokumenten ID: | 121961 |
Datum der Veröffentlichung auf Open Access LMU: | 04. Nov. 2024 14:13 |
Letzte Änderungen: | 04. Nov. 2024 14:13 |