To read this content please select one of the options below:

Large-scale agile security practices in software engineering

Cláudia Ascenção (School of Science and Technology, ISPGAYA, Vila Nova de Gaia, Portugal)
Henrique Teixeira (School of Science and Technology, ISPGAYA, Vila Nova de Gaia, Portugal)
João Gonçalves (School of Science and Technology, ISPGAYA, Vila Nova de Gaia, Portugal)
Fernando Almeida (INESC TEC Laboratory, University of Porto, Porto, Portugal)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 11 September 2024

65

Abstract

Purpose

Security in large-scale agile is a crucial aspect that should be carefully addressed to ensure the protection of sensitive data, systems and user privacy. This study aims to identify and characterize the security practices that can be applied in managing large-scale agile projects.

Design/methodology/approach

A qualitative study is carried out through 18 interviews with 6 software development companies based in Portugal. Professionals who play the roles of Product Owner, Scrum Master and Scrum Member were interviewed. A thematic analysis was applied to identify deductive and inductive security practices.

Findings

The findings identified a total of 15 security practices, of which 8 are deductive themes and 7 are inductive. Most common security practices in large-scale agile include penetration testing, sensitive data management, automated testing, threat modeling and the implementation of a DevSecOps approach.

Originality/value

The results of this study extend the knowledge about large-scale security practices and offer relevant practical contributions for organizations that are migrating to large-scale agile environments. By incorporating security practices at every stage of the agile development lifecycle and fostering a security-conscious culture, organizations can effectively address security challenges in large-scale agile environments.

Keywords

Citation

Ascenção, C., Teixeira, H., Gonçalves, J. and Almeida, F. (2024), "Large-scale agile security practices in software engineering", Information and Computer Security, Vol. ahead-of-print No. ahead-of-print. https://doi.org/10.1108/ICS-07-2023-0136

Publisher

:

Emerald Publishing Limited

Copyright © 2024, Emerald Publishing Limited

Related articles