Secure Software Development in Agile Development Processes of E-Government Applications
Öz
Agile software development process is found to be the most useful for software industry, since it provides flexibility over requirements and specifications that can change over time. For this reason, government departments and municipalities as well as private organizations can develop products in a faster way but with some disadvantages as well as advantages. One of the concerns is the security problem due to increasing sophisticated attacks and their incrementing costs for cyber defense. Considering the increasing attacks over e-government platforms, development of software requires more emphasis on the security aspect. Particularly for government institutions that mostly have to lean on third party providers for software development that will provide automation of public services via internet, secure software problem became one of the most crucial concerns. Because of some vulnerability that is caused by incremental model developers are enforced to make more secure products. In this paper, large amount of literature has been researched to specify the security issues in agile processes which is the most common and chosen methodology for its elasticity. There are some challenges to provide secure software in agile processes. We have tried to answer why we could not develop secure software because of challenges and what methods can be used to overcome challenges. Comparative security engineering processes have explained to have secure software.
Anahtar Kelimeler
Kaynakça
- Alberts, J., & Allen, R. (2011). Risk based measurement and analysis: Application to software security. Carneige Mellon University Pittsburg: Software Enginnering Instıtute.
- Ambler, S. (2013). Retrieved from The Agile System Develpoment Lifecycle: http://www.ambysoft.com/agileLifecycle.html
- Anderson, R. (2003). What is Security Engineering? In Security Engineering. New York: Wiley.
- Baca, D., & Carlsson, B. (n.d.). Agile Development with Security Engineering Activities.
- Beznosov, K., & Kruchten, P. (n.d.). Towards Agile Security Assurance.
- Bostrom, G., & Jaana Wayrynen, M. B. (2006). Extending XP Practices to support Security Requirements Engineering (pp. 11-17). ACM SESS 06.
- Creel, R. (2007). Assuring Software Systems Security: Life Cycle Considerations for Government Acquisitions. Carnegie Mellon University , https://www.us-cert.gov/bsi/articles/best-practices/acquisition/assuring-software-systems-security---life-cycle-considerations-government-acquisitions.
- Davis, N. (2005). Secure Software Development Life Cycle Processes: A Technology Scouting Report. http://www.dtic.mil/docs/citations/ADA447047: Carnegie-Mellon Univ Pittsburgh Pa Software Engineering Inst.
Ayrıntılar
Birincil Dil
İngilizce
Konular
-
Bölüm
Araştırma Makalesi
Yazarlar
Ahmet Efe
*
Ankara Kalkınma Ajansı
0000-0002-2691-7517
Türkiye
Nisanur Mühürdaroğlu
Bu kişi benim
Yildirim Beyazit Üniversity
Türkiye
Yayımlanma Tarihi
5 Nisan 2018
Gönderilme Tarihi
19 Şubat 2018
Kabul Tarihi
30 Mart 2018
Yayımlandığı Sayı
Yıl 2018 Cilt: 3 Sayı: 1
Cited By
TEKNOLOJİ TAKIMLARI PERFORMANSLARININ AHP-PROMETHEE YÖNTEMLERİ KULLANARAK ÖLÇÜMÜ VE OECD ÜLKELERİNDEKİ İHRACATA ETKİSİNE YÖNELİK BİR ÇALIŞMA
Mehmet Akif Ersoy Üniversitesi İktisadi ve İdari Bilimler Fakültesi Dergisi
https://doi.org/10.30798/makuiibf.858642
