Skip to main content
Kent Academic Repository

Towards Agile Security Risk Management in RE and Beyond

Franqueira, Virginia N. L., Bakalova, Zornitza, Tun, Thein Than, Daneva, Maya (2011) Towards Agile Security Risk Management in RE and Beyond. In: Proceedings of the Workshop on Empirical Requirements Engineering (EmpiRE 2011). . pp. 33-36. IEEE (doi:10.1109/empire.2011.6046253) (Access to this publication is currently restricted. You may be able to access a copy if URLs are provided) (KAR id:77196)

PDF Publisher pdf
Language: English

Restricted to Repository staff only
[thumbnail of 6046253]
Official URL:
https://doi.org/10.1109/empire.2011.6046253

Abstract

Little attention has been given so far to the process of security risk management at the early stages of system development. Security has been addressed by isolated security assurance practices, some of which consider risks and mitigations but they do not provide an overview of the overall security state of the system being developed. This paper takes the position that (1) these isolated security assurance practices should be fully integrated and should be embedded in short iterations of risk assessment, treatment and acceptance, providing input for updating security requirements and for security risk management, and that (2) available empirical data from public catalogs and databases should be used as a source of expertise, to leverage past experiences, and therefore reduce, although not eliminate, subjectivity of human judgment. Borrowing from the agile software development and project management philosophy, we introduce the idea of a light weight, agile approach to security risk management integrated to the development life cycle.

Item Type: Conference or workshop item (Paper)
DOI/Identification number: 10.1109/empire.2011.6046253
Additional information: Made published version available to staff only. Again, I belong to KirCCS (and SoCyETAL).
Uncontrolled keywords: Information Security Risk Management; Agile Software Development; Secure Engineering; Security Assurance
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
Depositing User: Virginia Franqueira
Date Deposited: 08 Oct 2019 17:29 UTC
Last Modified: 16 Nov 2021 10:26 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/77196 (The current URI for this page, for reference purposes)

University of Kent Author Information

Franqueira, Virginia N. L..

Creator's ORCID: https://orcid.org/0000-0003-1332-9115
CReDIT Contributor Roles:
  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.