{"id":"https://openalex.org/W2240706405","doi":"https://doi.org/10.1145/2812428.2812431","title":"A comparison of security assurance support of agile software development methods","display_name":"A comparison of security assurance support of agile software development methods","publication_year":2015,"publication_date":"2015-06-25","ids":{"openalex":"https://openalex.org/W2240706405","doi":"https://doi.org/10.1145/2812428.2812431","mag":"2240706405"},"language":"en","primary_location":{"id":"doi:10.1145/2812428.2812431","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2812428.2812431","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 16th International Conference on Computer Systems and Technologies","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5029221788","display_name":"Kalle Rindell","orcid":"https://orcid.org/0000-0003-3349-5823"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Kalle Rindell","raw_affiliation_strings":[""],"affiliations":[{"raw_affiliation_string":"","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006523717","display_name":"Sami Hyrynsalmi","orcid":"https://orcid.org/0000-0002-5073-3750"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sami Hyrynsalmi","raw_affiliation_strings":[""],"affiliations":[{"raw_affiliation_string":"","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5029023235","display_name":"Ville Lepp\u00e4nen","orcid":"https://orcid.org/0000-0001-5296-677X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ville Lepp\u00e4nen","raw_affiliation_strings":[""],"affiliations":[{"raw_affiliation_string":"","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5029221788"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":4.1481,"has_fulltext":false,"cited_by_count":14,"citation_normalized_percentile":{"value":0.94528401,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"61","last_page":"68"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10430","display_name":"Software Engineering Techniques and Practices","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10430","display_name":"Software Engineering Techniques and Practices","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/software-security-assurance","display_name":"Software security assurance","score":0.8139733672142029},{"id":"https://openalex.org/keywords/agile-software-development","display_name":"Agile software development","score":0.7736618518829346},{"id":"https://openalex.org/keywords/documentation","display_name":"Documentation","score":0.6150801777839661},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5838575959205627},{"id":"https://openalex.org/keywords/scrum","display_name":"Scrum","score":0.5303236842155457},{"id":"https://openalex.org/keywords/quality-assurance","display_name":"Quality assurance","score":0.5116679668426514},{"id":"https://openalex.org/keywords/lean-software-development","display_name":"Lean software development","score":0.49483221769332886},{"id":"https://openalex.org/keywords/process-management","display_name":"Process management","score":0.47706782817840576},{"id":"https://openalex.org/keywords/agile-unified-process","display_name":"Agile Unified Process","score":0.4566901624202728},{"id":"https://openalex.org/keywords/security-engineering","display_name":"Security engineering","score":0.45098504424095154},{"id":"https://openalex.org/keywords/software-development","display_name":"Software development","score":0.44720354676246643},{"id":"https://openalex.org/keywords/engineering-management","display_name":"Engineering management","score":0.4255380928516388},{"id":"https://openalex.org/keywords/information-security-management-system","display_name":"Information security management system","score":0.4167614281177521},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.41126489639282227},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.3770284652709961},{"id":"https://openalex.org/keywords/software-development-process","display_name":"Software development process","score":0.34114938974380493},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.31364864110946655},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2833731770515442},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.25535398721694946},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.22797951102256775},{"id":"https://openalex.org/keywords/security-service","display_name":"Security service","score":0.1991138756275177},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.16132834553718567},{"id":"https://openalex.org/keywords/operations-management","display_name":"Operations management","score":0.14634549617767334}],"concepts":[{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.8139733672142029},{"id":"https://openalex.org/C14185376","wikidata":"https://www.wikidata.org/wiki/Q30232","display_name":"Agile software development","level":2,"score":0.7736618518829346},{"id":"https://openalex.org/C56666940","wikidata":"https://www.wikidata.org/wiki/Q788790","display_name":"Documentation","level":2,"score":0.6150801777839661},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5838575959205627},{"id":"https://openalex.org/C147579259","wikidata":"https://www.wikidata.org/wiki/Q460387","display_name":"Scrum","level":4,"score":0.5303236842155457},{"id":"https://openalex.org/C106436119","wikidata":"https://www.wikidata.org/wiki/Q836575","display_name":"Quality assurance","level":3,"score":0.5116679668426514},{"id":"https://openalex.org/C199561411","wikidata":"https://www.wikidata.org/wiki/Q2665555","display_name":"Lean software development","level":5,"score":0.49483221769332886},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.47706782817840576},{"id":"https://openalex.org/C87813535","wikidata":"https://www.wikidata.org/wiki/Q956418","display_name":"Agile Unified Process","level":5,"score":0.4566901624202728},{"id":"https://openalex.org/C13159133","wikidata":"https://www.wikidata.org/wiki/Q365674","display_name":"Security engineering","level":5,"score":0.45098504424095154},{"id":"https://openalex.org/C529173508","wikidata":"https://www.wikidata.org/wiki/Q638608","display_name":"Software development","level":3,"score":0.44720354676246643},{"id":"https://openalex.org/C110354214","wikidata":"https://www.wikidata.org/wiki/Q6314146","display_name":"Engineering management","level":1,"score":0.4255380928516388},{"id":"https://openalex.org/C111153917","wikidata":"https://www.wikidata.org/wiki/Q1662500","display_name":"Information security management system","level":5,"score":0.4167614281177521},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.41126489639282227},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.3770284652709961},{"id":"https://openalex.org/C180152950","wikidata":"https://www.wikidata.org/wiki/Q2904257","display_name":"Software development process","level":4,"score":0.34114938974380493},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.31364864110946655},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2833731770515442},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.25535398721694946},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.22797951102256775},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.1991138756275177},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.16132834553718567},{"id":"https://openalex.org/C21547014","wikidata":"https://www.wikidata.org/wiki/Q1423657","display_name":"Operations management","level":1,"score":0.14634549617767334},{"id":"https://openalex.org/C2778618615","wikidata":"https://www.wikidata.org/wiki/Q4008393","display_name":"External quality assessment","level":2,"score":0.0},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/2812428.2812431","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2812428.2812431","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 16th International Conference on Computer Systems and Technologies","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Partnerships for the goals","id":"https://metadata.un.org/sdg/17","score":0.46000000834465027}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":18,"referenced_works":["https://openalex.org/W416981147","https://openalex.org/W643519619","https://openalex.org/W1506343449","https://openalex.org/W1529465401","https://openalex.org/W1968165445","https://openalex.org/W2100894766","https://openalex.org/W2104698296","https://openalex.org/W2112657059","https://openalex.org/W2113848838","https://openalex.org/W2121016257","https://openalex.org/W2128412750","https://openalex.org/W2132462705","https://openalex.org/W2142796655","https://openalex.org/W2148357053","https://openalex.org/W2155629590","https://openalex.org/W2168633587","https://openalex.org/W2473041012","https://openalex.org/W3139751537"],"related_works":["https://openalex.org/W2007879862","https://openalex.org/W2779279197","https://openalex.org/W2742418299","https://openalex.org/W2751900431","https://openalex.org/W2618979805","https://openalex.org/W2253944789","https://openalex.org/W4200004132","https://openalex.org/W4320039727","https://openalex.org/W2292846935","https://openalex.org/W3107548336"],"abstract_inverted_index":{"Agile":[0],"methods":[1,88],"increase":[2],"the":[3,7,46,58,86],"speed":[4],"and":[5,37,68,94],"reduce":[6],"cost":[8],"of":[9,19,28,60],"software":[10,41],"projects;":[11],"however,":[12],"they":[13],"have":[14],"been":[15],"criticized":[16],"for":[17,48,98],"lack":[18,27],"documentation,":[20],"traditional":[21],"quality":[22],"control,":[23],"and,":[24],"most":[25],"importantly,":[26],"security":[29,49,63,74,80],"assurance":[30,50],"-":[31],"mostly":[32],"due":[33],"to":[34,40,56],"their":[35,91],"informal":[36],"self-organizing":[38],"approach":[39],"development.":[42],"This":[43],"paper":[44],"clarifies":[45],"requirements":[47],"by":[51],"using":[52],"an":[53],"evaluation":[54],"framework":[55],"analyze":[57,85],"compatibility":[59],"established":[61,78],"agile":[62],"development":[64],"methods:":[65],"XP,":[66],"Scrum":[67],"Kanban,":[69],"combined":[70],"with":[71],"Microsoft":[72],"SDL":[73],"framework,":[75],"against":[76],"Finland's":[77],"national":[79],"regulation":[81],"(Vahti).":[82],"We":[83],"also":[84],"selected":[87],"based":[89],"on":[90],"role":[92],"definitions,":[93],"provide":[95],"some":[96],"avenues":[97],"future":[99],"research.":[100]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":2},{"year":2019,"cited_by_count":3},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":2},{"year":2016,"cited_by_count":1},{"year":2015,"cited_by_count":1}],"updated_date":"2026-03-25T13:04:00.132906","created_date":"2025-10-10T00:00:00"}
