Applicability Issues in Security Requirements Engineering for Agile Development
Nikola Luburić, Goran Sladić, Branko Milosavljević · 2018
Cyberattackers present a real threat to software systems, which is why organizations are requiring software vendors to produce secure software. During the past decade, many software vendors have started expanding their development process to include activities that increase the security of the software. Furthermore, both the industrial and the scientific literature has presented dozens of different secure software development methods. Despite this effort and an explicit requirement, secure development practices are still not widely adopted. In this paper, we present insight into why this is the case. We examine issues that limit the adoption of security requirements engineering practices in agile development. Furthermore, we analyze the proposed security analysis techniques designed to identify security requirements and increase the security posture of software products developed following the Scrum framework and examine how they address the discovered issues. From this research, we derive a set of recommendations for improving security requirements engineering practices for the agile development context.