Logo Logo
Hilfe
Hilfe
Switch Language to English

Voggenreiter, Markus ORCID logoORCID: https://orcid.org/0000-0003-3964-1983 und Schöpp, Ulrich (2023): Prioritizing Industrial Security Findings in Agile Software Development Projects. International Conference on Software Engineering - Companion, ICSE, Companion, Melbourne, Australia, 14-20 May 2023. Institute of Electrical and Electronics Engineers (Hrsg.), In: 2023 IEEE/ACM 45th International Conference on SoftwareEngineering: Companion Proceedings (ICSE-Companion), Piscataway, NJ: IEEE. S. 375-379

Volltext auf 'Open Access LMU' nicht verfügbar.

Abstract

Automating repetitive activities is a key principle in most software development approaches employed in the industry. This implies that security activities and all related processes should be investigated for automation capabilities, particularly the management of security findings and vulnerabilities. Consid-ering the limited time available for each release and the vast flood of findings by automated security testing, prioritizing security finding responses is essential. In this paper, we present a partially automated process to prioritize security findings in industrial software development projects. We utilize a two-staged calculation process to produce a prioritization score, representing the finding's severity and factors like stakeholder input alike. This process was evaluated by conducting structured interviews with security professionals while also integrating the approach in ongoing industrial software development projects. The results indicate the potential of the process in terms of usefulness and correctness for agile software development projects.

Dokument bearbeiten Dokument bearbeiten