scholarly journals Lean integration of IT security and data privacy governance aspects into product development in agile organizations

2021 ◽  
Vol 27 (8) ◽  
pp. 868-893 ◽  
Author(s):  
Alexander Poth ◽  
Mario Kottke ◽  
Kerstin Middelhauve ◽  
Torsten Mahr ◽  
Andreas Riel

This article deals with the design of a product development-specific framework to support lean and adequate governance. This framework is based on layers of product-specific standards and regulations. The layers can be merged into a specific set to address the demands of a product to fit the state-of-the-art requirements of its domain. For the product domain, specific layers are presented with examples from IT security and data privacy for the software development phase. The approach is generic and can be extended to other domains like finance services or embedded products and their life-cycle phases.

2018 ◽  
Vol 17 (3) ◽  
pp. 15-25
Author(s):  
Umasankar Saketharaman ◽  
Victor Anandkumar

This study characterises the results of published scientific research in the field of Global Software Product Development (GSD). Based on the analysis of about 22 scholarly articles published between 2001 and 2014, it is observed that in spite of issues and challenges faced in its implementation, GSD is a business necessity. To ensure more successful realisation of the benefits of GSD, co-locating some of the key-roles at global locations along with software development could be exercised. This could have a positive impact on the software product life cycle. This relationship needs to be validated by further research backed with empirical data.      


Author(s):  
Andriy Lishchytovych ◽  
Volodymyr Pavlenko

The present article describes setup, configuration and usage of the key performance indicators (KPIs) of members of project teams involved into the software development life cycle. Key performance indicators are described for the full software development life cycle and imply the deep integration with both task tracking systems and project code management systems, as well as a software product quality testing system. To illustrate, we used the extremely popular products - Atlassian Jira (tracking development tasks and bugs tracking system) and git (code management system). The calculation of key performance indicators is given for a team of three developers, two testing engineers responsible for product quality, one designer, one system administrator, one product manager (responsible for setting business requirements) and one project manager. For the key members of the team, it is suggested to use one integral key performance indicator per the role / team member, which reflects the quality of the fulfillment of the corresponding role of the tasks. The model of performance indicators is inverse positive - the initial value of each of the indicators is zero and increases in the case of certain deviations from the standard performance of official duties inherent in a particular role. The calculation of the proposed key performance indicators can be fully automated (in particular, using Atlassian Jira and Atlassian Bitbucket (git) or any other systems, like Redmine, GitLab or TestLink), which eliminates the human factor and, after the automation, does not require any additional effort to calculate. Using such a tool as the key performance indicators allows project managers to completely eliminate bias, reduce the emotional component and provide objective data for the project manager. The described key performance indicators can be used to reduce the time required to resolve conflicts in the team, increase productivity and improve the quality of the software product.


Author(s):  
Sampada G.C ◽  
Tende Ivo Sake ◽  
Amrita

Background: With the advancement in the field of software development, software poses threats and risks to customers’ data and privacy. Most of these threats are persistent because security is mostly considered as a feature or a non-functional requirement, not taken into account during the software development life cycle (SDLC). Introduction: In order to evaluate the security performance of a software system, it is necessary to integrate the security metrics during the SDLC. The appropriate security metrics adopted for each phase of SDLC aids in defining the security goals and objectives of the software as well as quantify the security in the software. Methods: This paper presents systematic review and catalog of security metrics that can be adopted during the distinguishable phases of SDLC, security metrics for vulnerability and risk assessment reported in the literature for secure development of software. The practices of these metrics enable software security experts to improve the security characteristics of the software being developed. The critical analysis of security metrics of each phase and their comparison are also discussed. Results: Security metrics obtained during the development processes help to improve the confidentiality, integrity, and availability of software. Hence, it is imperative to consider security during the development of the software, which can be done with the use of software security metrics. Conclusion: This paper reviews the various security metrics that are meditated in the copious phases during the progression of the SDLC in order to provide researchers and practitioners with substantial knowledge for adaptation and further security assessment.


Author(s):  
Magnus Sparrevik ◽  
Luitzen de Boer ◽  
Ottar Michelsen ◽  
Christofer Skaar ◽  
Haley Knudson ◽  
...  

AbstractThe construction sector is progressively becoming more circular by reducing waste, re-using building materials and adopting regenerative solutions for energy production and biodiversity protection. The implications of circularity on construction activities are complex and require the careful evaluation of impacts to select the appropriate path forward. Evaluations of circular solutions and their environmental effectiveness are often performed based on various types of life cycle-based impact assessments. This paper uses systemic thinking to map and evaluate different impact assessment methodologies and their implications for a shift to more circular solutions. The following systemic levels are used to group the methodologies: product (material life cycle declarations and building assessments), organisation (certification and management schemes) and system (policies, standards and regulations). The results confirm that circular economy is integrated at all levels. However, development and structure are not coordinated or governed unidirectionally, but rather occur simultaneously at different levels. This recursive structure is positive if the methods are applied in the correct context, thus providing both autonomy and cohesion in decision making. Methods at lower systemic levels may then improve production processes and stimulate the market to create circular and innovative building solutions, whereas methods at higher systemic levels can be used, for example, by real estate builders, trade organisations and governments to create incentives for circular development and innovation in a broader perspective. Use of the performance methods correctly within an actor network is therefore crucial for successful and effective implementation of circular economy in the construction sector.


2021 ◽  
pp. 1-30
Author(s):  
F. D. Maia ◽  
J. M. Lourenço da Saúde

ABSTRACT A state-of-the-art review of all the developments, standards and regulations associated with the use of major unmanned aircraft systems under development is presented. Requirements and constraints are identified by evaluating technologies specific to urban air mobility, considering equivalent levels of safety required by current and future civil aviation standards. Strategies, technologies and lessons learnt from remotely piloted aviation and novel unmanned traffic management systems are taken as the starting point to assess operational scenarios for autonomous urban air mobility.


2021 ◽  
Vol 13 (5) ◽  
pp. 2472
Author(s):  
Teodora Stillitano ◽  
Emanuele Spada ◽  
Nathalie Iofrida ◽  
Giacomo Falcone ◽  
Anna Irene De Luca

This study aims at providing a systematic and critical review on the state of the art of life cycle applications from the circular economy point of view. In particular, the main objective is to understand how researchers adopt life cycle approaches for the measurement of the empirical circular pathways of agri-food systems along with the overall lifespan. To perform the literature review, the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) protocol was considered to conduct a review by qualitative synthesis. Specifically, an evaluation matrix has been set up to gather and synthesize research evidence, by classifying papers according to several integrated criteria. The literature search was carried out employing scientific databases. The findings highlight that 52 case studies out of 84 (62% of the total) use stand-alone life cycle assessment (LCA) to evaluate the benefits/impacts of circular economy (CE) strategies. In contrast, only eight studies (9.5%) deal with the life cycle costing (LCC) approach combined with other analyses while no paper deals with the social life cycle assessment (S-LCA) methodology. Global warming potential, eutrophication (for marine, freshwater, and terrestrial ecosystems), human toxicity, and ecotoxicity results are the most common LCA indicators applied. Only a few articles deal with the CE assessment through specific indicators. We argue that experts in life cycle methodologies must strive to adopt some key elements to ensure that the results obtained fit perfectly with the measurements of circularity and that these can even be largely based on a common basis.


2021 ◽  
Vol 26 (4) ◽  
Author(s):  
Mazen Mohamad ◽  
Jan-Philipp Steghöfer ◽  
Riccardo Scandariato

AbstractSecurity Assurance Cases (SAC) are a form of structured argumentation used to reason about the security properties of a system. After the successful adoption of assurance cases for safety, SAC are getting significant traction in recent years, especially in safety-critical industries (e.g., automotive), where there is an increasing pressure to be compliant with several security standards and regulations. Accordingly, research in the field of SAC has flourished in the past decade, with different approaches being investigated. In an effort to systematize this active field of research, we conducted a systematic literature review (SLR) of the existing academic studies on SAC. Our review resulted in an in-depth analysis and comparison of 51 papers. Our results indicate that, while there are numerous papers discussing the importance of SAC and their usage scenarios, the literature is still immature with respect to concrete support for practitioners on how to build and maintain a SAC. More importantly, even though some methodologies are available, their validation and tool support is still lacking.


2016 ◽  
Vol 685 ◽  
pp. 881-885
Author(s):  
Alexey Ponomarev ◽  
Hitesh S. Nalamwar

Software traceability is an important part in software development that is getting more and more attention nowadays from organizations and researchers. The paper outlines the importance, different methods and techniques of software traceability. It also explains the need of automating traceability, problems and drawbacks of existing traceability tools, the ongoing challenges facing implementation of traceability in software development life cycle, and finally the paper discusses whether software traceability should be mandated as a key to improve software evolution


Sign in / Sign up

Export Citation Format

Share Document