Extending XP Practices to Support Security Requirements Engineering

Fuente: Zenodo
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Boström, Gustav, Wäyrynen, Jaana, Bodén,, Marine, Beznosov, Konstantin, Kruchten, Philippe
Format: Recurso digital
Veröffentlicht: Zenodo 2006
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866901824668172288
author Boström, Gustav
Wäyrynen, Jaana
Bodén,, Marine
Beznosov, Konstantin
Kruchten, Philippe
author_facet Boström, Gustav
Wäyrynen, Jaana
Bodén,, Marine
Beznosov, Konstantin
Kruchten, Philippe
contents This paper proposes a way of extending eXtreme Programming (XP) practices, in particular the original planning game and the coding guidelines, to aid the developers and the customer to engineer security requirements while maintaining the iterative and rapid feedback-driven nature of XP. More specifically, these steps result in two new security-specific flavours of XP User stories: Abuser stories (threat scenarios) and Security-related User stories (security functionalities). The introduced extensions also aid in formulating security-specific coding and design standards to be used in the project, as well as in understanding the need for supporting specific Security-related User stories by the system. The proposed extensions have been tested in a student project.
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_3264235
institution Zenodo
language
publishDate 2006
publisher Zenodo
record_format zenodo
spellingShingle Extending XP Practices to Support Security Requirements Engineering
Boström, Gustav
Wäyrynen, Jaana
Bodén,, Marine
Beznosov, Konstantin
Kruchten, Philippe
Security Engineering
Requirements
Agile Software Development
eXtreme Programming
Development methodology
This paper proposes a way of extending eXtreme Programming (XP) practices, in particular the original planning game and the coding guidelines, to aid the developers and the customer to engineer security requirements while maintaining the iterative and rapid feedback-driven nature of XP. More specifically, these steps result in two new security-specific flavours of XP User stories: Abuser stories (threat scenarios) and Security-related User stories (security functionalities). The introduced extensions also aid in formulating security-specific coding and design standards to be used in the project, as well as in understanding the need for supporting specific Security-related User stories by the system. The proposed extensions have been tested in a student project.
title Extending XP Practices to Support Security Requirements Engineering
topic Security Engineering
Requirements
Agile Software Development
eXtreme Programming
Development methodology
url https://doi.org/10.5281/zenodo.3264235