Sistematični pregled literature agilnih in vitkih pristopov k razvoju varne programske opreme
DOI:
https://doi.org/10.31449/upinf.102Keywords:
methodology, information security, agile methods, secure software developmentAbstract
We conducted a systematic literature survey in four bibliographic databases. We have focused on secure
software development with special attention to shortcomings of existing surveys. We have identified 23
approaches. Most identified approaches were theoretical and only 21.7 percent of them were empirically
tested in industrial settings. All identified approaches are based on the assumption that security is not
considered in the development process since security elements are not integral and permanent part of agile
methods. Most frequently proposed security elements are processes (48 percent), followed by combination
of processes and artifacts (26 percent) and combination of processes, artifacts and roles (13 percent).