2010•Unpublished venueRequires access

Exploring security certification and accreditation using the agile software development lifecycle process

Steven A. Brown, Robert A. Tillman

Open publisher page 0 citations

Abstract

Government requirements for security certification and accreditation (C&A) of systems follow a sequential approach compatible with projects using the waterfall software development lifecycle (SDLC). The purpose of this study is to explore ideas that will allow incorporation of C&A into the agile SDLC process. With the emergence of agile SDLC, incorporating the government C&A process becomes a challenge in areas such as minimizing risk, requirements volatility, documentation, stakeholder involvement, and meeting aggressive schedules. Focus groups were used in this qualitative study to answer the research question: What factors assist in successful incorporation of C&A into the agile SDLC process? Twenty-eight success factors emerged in the areas of: customer support, management support, team training, requirements mapping, security engineering, customer-contractor communication, documentation, testing, and transitioning to agile SDLC from waterfall SDLC.

About this research paper

What this paper is about

Government requirements for security certification and accreditation (C&A) of systems follow a sequential approach compatible with projects using the waterfall software development lifecycle (SDLC). The purpose of this study is to explore ideas that will allow incorporation of C&A into the agile SDLC process. With the emergence of agile SDLC, incorporating the government C&A process becomes a challenge in areas such as minimizing risk, requirements volatility, documentation, stakeholder involvement, and meeting aggressive schedules. Focus groups were used in this qualitative study to answer the research question: What factors assist in successful incorporation of C&A into the agile SDLC process? Twenty-eight success factors emerged in the areas of: customer support, management support, team training, requirements mapping, security engineering, customer-contractor communication, documentation, testing, and transitioning to agile SDLC from waterfall SDLC.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Government requirements for security certification and accreditation (C&A) of systems follow a sequential approach compatible with projects using the waterfall software development lifecycle (SDLC). The purpose of this study is to explore ideas that will allow incorporation of C&A into the agile SDLC process. With the emergence of agile SDLC, incorporating the government C&A process becomes a challenge in areas such as minimizing risk, requirements volatility, documentation, stakeholder involvement, and meeting aggressive schedules. Focus groups were used in this qualitative study to answer the research question: What factors assist in successful incorporation of C&A into the agile SDLC process? Twenty-eight success factors emerged in the areas of: customer support, management support, team training, requirements mapping, security engineering, customer-contractor communication, documentation, testing, and transitioning to agile SDLC from waterfall SDLC.

Key concepts: Systems development life cycle, Waterfall model, Process management, Agile software development, Documentation, Lean software development, Agile Unified Process, Software development process

Related papers

Back to paper searchBrowse research topicsOriginal source
Exploring security certification and accreditation using the agile software development lifecycle process — Research Paper | ScholarLens