Towards Automated Continuous Security Compliance

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Angermeir, Florian, Fischbach, Jannik, Moyón, Fabiola, Mendez, Daniel
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910550235021312
author Angermeir, Florian
Fischbach, Jannik
Moyón, Fabiola
Mendez, Daniel
author_facet Angermeir, Florian
Fischbach, Jannik
Moyón, Fabiola
Mendez, Daniel
contents Context: Continuous Software Engineering is increasingly adopted in highly regulated domains, raising the need for continuous compliance. Adherence to especially security regulations -- a major concern in highly regulated domains -- renders Continuous Security Compliance of high relevance to industry and research. Problem: One key barrier to adopting continuous software engineering in the industry is the resource-intensive and error-prone nature of traditional manual security compliance activities. Automation promises to be advantageous. However, continuous security compliance is under-researched, precluding an effective adoption. Contribution: We have initiated a long-term research project with our industry partner to address these issues. In this manuscript, we make three contributions: (1) We provide a precise definition of the term continuous security compliance aligning with the state-of-art, (2) elaborate a preliminary overview of challenges in the field of automated continuous security compliance through a tertiary literature study, and (3) present a research roadmap to address those challenges via automated continuous security compliance.
format Preprint
id arxiv_https___arxiv_org_abs_2407_21494
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Towards Automated Continuous Security Compliance
Angermeir, Florian
Fischbach, Jannik
Moyón, Fabiola
Mendez, Daniel
Software Engineering
Context: Continuous Software Engineering is increasingly adopted in highly regulated domains, raising the need for continuous compliance. Adherence to especially security regulations -- a major concern in highly regulated domains -- renders Continuous Security Compliance of high relevance to industry and research. Problem: One key barrier to adopting continuous software engineering in the industry is the resource-intensive and error-prone nature of traditional manual security compliance activities. Automation promises to be advantageous. However, continuous security compliance is under-researched, precluding an effective adoption. Contribution: We have initiated a long-term research project with our industry partner to address these issues. In this manuscript, we make three contributions: (1) We provide a precise definition of the term continuous security compliance aligning with the state-of-art, (2) elaborate a preliminary overview of challenges in the field of automated continuous security compliance through a tertiary literature study, and (3) present a research roadmap to address those challenges via automated continuous security compliance.
title Towards Automated Continuous Security Compliance
topic Software Engineering
url https://arxiv.org/abs/2407.21494