Practices and challenges of threat modelling in agile environments


연구 분야: Software Development



학회: Informatik Spektrum


초록

Facing the increasing annual cybersecurity costs, threat modelling (TM) is a method to consider security as early as possible in the software development life cycle (SDLC). Thereby, TM helps to identify and address security-related design flaws in information systems. As the original TM approach is based on sequential development, it is not aligned with today’s predominantly agile environments. This results in several challenges. However, TM’s implementation in an agile development approach lacks the recommendations on how to tackle these challenges. Therefore, we assess the state-of-the-art of TM challenges and practices in agile environments by conducting a literature review covering 220 papers. Thereby, we identify nine categories of challenges and six categories of practices. We propose a valuable artefact for practitioners by mapping challenges and practices to the agile SDLC and by creating a matrix highlighting how the practices address the challenges of TM in an agile environment.


Author Profile
Paul Theurich

Mercedes-Benz Mobility AG Stuttgart Germany

Antigua and Barbuda
Author Profile
Josepha Witt

Department of Intelligent Information Systems University of Hohenheim Stuttgart Germany

Germany
Author Profile
Sebastian Richter

Information Systems Baden-Wuerttemberg Cooperative State University (DHBW) Stuttgart Stuttgart Germany

Germany

📄 논문 정보

발행 연도 2023년
인용수 3
출판 국가 Germany, Antigua and Barbuda
사이트 Springer
좋아요 수 0

연관 논문 목록 (275건)