{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,28]],"date-time":"2025-03-28T04:24:12Z","timestamp":1743135852612,"version":"3.40.3"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030959463"},{"type":"electronic","value":"9783030959470"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-95947-0_40","type":"book-chapter","created":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T13:11:21Z","timestamp":1644930681000},"page":"567-581","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["An Empirical Investigation of Agile Information Systems Development for Cybersecurity"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0829-570X","authenticated-orcid":false,"given":"Abdulhamid A.","family":"Ardo","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0570-7086","authenticated-orcid":false,"given":"Julian M.","family":"Bass","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4065-4191","authenticated-orcid":false,"given":"Tarek","family":"Gaber","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2022,2,16]]},"reference":[{"key":"40_CR1","doi-asserted-by":"publisher","first-page":"1213","DOI":"10.1016\/j.jss.2012.02.033","volume":"85","author":"T Dings\u00f8yr","year":"2012","unstructured":"Dings\u00f8yr, T., Nerur, S., Balijepally, V., Moe, N.B.: A decade of agile methodologies: towards explaining agile software development. J. Syst. Softw. 85, 1213\u20131221 (2012)","journal-title":"J. Syst. Softw."},{"key":"40_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.infsof.2016.03.001","volume":"75","author":"JM Bass","year":"2016","unstructured":"Bass, J.M.: Artefacts and agile method tailoring in large-scale offshore software development programmes. Inf. Softw. Technol. 75, 1\u201316 (2016)","journal-title":"Inf. Softw. Technol."},{"key":"40_CR3","doi-asserted-by":"crossref","unstructured":"Baca, D., Carlsson, B.: Agile development with security engineering activities. In: International Conference on Software and Systems Process, pp. 149\u2013158. Association for Computing Machinery (ACM), New York (2011)","DOI":"10.1145\/1987875.1987900"},{"key":"40_CR4","doi-asserted-by":"crossref","unstructured":"Terpstra, E., Daneva, M., Wang, C.: Agile practitioners\u2019 understanding of security requirements: insights from a grounded theory analysis. In: 25th International Requirements Engineering Conference Workshops (REW), pp. 439\u2013442. IEEE, Lisbon, Portugal (2017)","DOI":"10.1109\/REW.2017.54"},{"key":"40_CR5","doi-asserted-by":"crossref","unstructured":"Riisom, K.R., Hubel, M.S., Alradhi, H.M., Nielsen, N.B., Kuusinen, K., Jabangwe, R.: Software security in agile software development: a literature review of challenges and solutions. In Proceedings of the 19th International Conference on Agile Software Development, pp. 1\u20135. ACM, Porto, Portugal (2018)","DOI":"10.1145\/3234152.3234189"},{"key":"40_CR6","unstructured":"Backman, L.: Why is security still an issue? a study comparing developers\u2019 software security awareness to existing vulnerabilities in software applications. In: Research Thesis, Linkoping University, Linkoping, Sweden (2018)"},{"key":"40_CR7","doi-asserted-by":"publisher","unstructured":"Rindell, K., Hyrynsalmi, S., Lepp\u00e4nen, V.: Fitting security into agile software development. In: Research Anthology on Recent Trends, Tools, and Implications of Computer Programming, pp. 1026\u20131045. IGI Global (2021). https:\/\/doi.org\/10.4018\/978-1-7998-3016-0.ch047","DOI":"10.4018\/978-1-7998-3016-0.ch047"},{"key":"40_CR8","doi-asserted-by":"publisher","first-page":"106488","DOI":"10.1016\/j.infsof.2020.106488","volume":"131","author":"K Rindell","year":"2020","unstructured":"Rindell, K., Ruohonen, J., Holvitie, J., Hyrynsalmi, S., Lepp\u00e4nen, V.: Security in agile software development: a practitioner survey. Inf. Soft. Technol 131, 106488 (2020)","journal-title":"Inf. Soft. Technol"},{"key":"40_CR9","doi-asserted-by":"crossref","unstructured":"Baca, D., Boldt, M., Carlsson, B., Jacobsson, A.: A novel security-enhanced agile software development process applied in an industrial setting. In: 10th International Conference on Availability, Reliability and Security, pp. 11\u201319. IEEE, Toulouse, France (2015)","DOI":"10.1109\/ARES.2015.45"},{"key":"40_CR10","doi-asserted-by":"publisher","unstructured":"Villamizar, H., Kalinowski, M., Viana, M., Fern\u00b4andez, D.: A systematic mapping study on security in agile requirements engineering. In: 44th Euromicro Conference on Software Engineering and Advanced Applications (SEAA), pp. 454\u2013461. IEEE, Prague, Czech Republic (2018). https:\/\/doi.org\/10.1109\/SEAA.2018.00080","DOI":"10.1109\/SEAA.2018.00080"},{"key":"40_CR11","doi-asserted-by":"crossref","unstructured":"Bartsch, S.: Practitioners\u2019 perspectives on security in agile development. In: Sixth International Conference on Availability, Reliability and Security, pp. 479\u2013484. IEEE, Vienna, Austria (2011)","DOI":"10.1109\/ARES.2011.82"},{"key":"40_CR12","doi-asserted-by":"crossref","unstructured":"Oueslati, H., Rahman, M.M., ben Othmane, L., Ghani, I., Arbain, A.F.B.: Evaluation of the challenges of developing secure software using the agile approach. Int. J. Secure Softw. Eng. (IJSSE), 7(1), 17\u201337 (2016)","DOI":"10.4018\/IJSSE.2016010102"},{"key":"40_CR13","doi-asserted-by":"publisher","unstructured":"Amoroso, E.: Recent progress in software security. IEEE Softw. 35(2), 11\u201313 (2018). https:\/\/doi.org\/10.1109\/MS.2018.1661316","DOI":"10.1109\/MS.2018.1661316"},{"key":"40_CR14","volume-title":"Software Security: Building Security","author":"G McGraw","year":"2006","unstructured":"McGraw, G.: Software Security: Building Security, 1st edn. Addison-Wesley Professional, Upper Saddle River, NJ (2006)","edition":"1"},{"key":"40_CR15","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1016\/j.cose.2013.04.004","volume":"38","author":"R Von Solms","year":"2013","unstructured":"Von Solms, R., Van Niekerk, J.: From information security to cyber security. Comput. Secur. 38, 97\u2013102 (2013)","journal-title":"Comput. Secur."},{"key":"40_CR16","volume-title":"Computer security: principles and practice: pearson education upper saddle river","author":"W Stallings","year":"2012","unstructured":"Stallings, W., Brown, L., Bauer, M.D., Bhattacharjee, A.K.: Computer security: principles and practice: pearson education upper saddle river. NJ, USA (2012)"},{"issue":"9","key":"40_CR17","first-page":"1","volume":"15","author":"M Siavvas","year":"2020","unstructured":"Siavvas, M., Tsoukalas, D., Jankovic, M., Kehagias, D., Tzovaras, D.: Technical debt as an indicator of software security risk: a machine learning approach for software development enterprises. Enterp. Inf. Syst. J. 15(9), 1\u201343 (2020)","journal-title":"Enterp. Inf. Syst. J."},{"key":"40_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1007\/978-3-642-23088-2_15","volume-title":"Database and Expert Systems Applications","author":"S Zhang","year":"2011","unstructured":"Zhang, S., Caragea, D., Ou, X.: An empirical study on using the national vulnerability database to predict software vulnerabilities. In: Hameurlain, A., Liddle, S.W., Schewe, K.-D., Zhou, X. (eds.) DEXA 2011. LNCS, vol. 6860, pp. 217\u2013231. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23088-2_15"},{"key":"40_CR19","unstructured":"Howard, M., Lipner, S.: The Security Development Lifecycle, vol. 8. Microsoft Press, Redmond (2006)"},{"key":"40_CR20","unstructured":"Owasp Samm Project.: Software Assurance Maturity Model (SAMM): A guide to building security into software development - v1.5. Technical Report Version 1.5., p. 72 (2017). https:\/\/owaspsamm.org\/"},{"issue":"3","key":"40_CR21","first-page":"7","volume":"30","author":"G McGraw","year":"2015","unstructured":"McGraw, G.: Software security and the building security in maturity model (BSIMM). J. Comput. Sci. Coll. 30(3), 7\u20138 (2015)","journal-title":"J. Comput. Sci. Coll."},{"key":"40_CR22","doi-asserted-by":"crossref","unstructured":"Rindell, K., Ruohonen, J., Hyrynsalmi, S.: Surveying secure software development practices in finland. In: 13th International Conference on Availability, Reliability and Security, pp. 1-7. ACM, Hamburg, Germany (2018)","DOI":"10.1145\/3230833.3233274"},{"key":"40_CR23","doi-asserted-by":"crossref","unstructured":"Rindell, K., Hyrynsalmi, S., Lepp\u00e4nen, V.: A comparison of security assurance support of agile software development methods. In: Proceedings of the 16th International Conference on Computer Systems and Technologies, pp. 61\u201368. ACM, Dublin, Ireland (2015)","DOI":"10.1145\/2812428.2812431"},{"issue":"4","key":"40_CR24","doi-asserted-by":"publisher","first-page":"487","DOI":"10.1007\/s10664-010-9152-6","volume":"16","author":"S Adolph","year":"2011","unstructured":"Adolph, S., Hall, W., Kruchten, P.: Using grounded theory to study the experience of software development. Empirical Softw. Eng. 16(4), 487\u2013513 (2011)","journal-title":"Empirical Softw. Eng."},{"key":"40_CR25","doi-asserted-by":"crossref","unstructured":"Oueslati, H., Rahman, M.M., ben Othmane, L.: Literature review of the challenges of developing secure software using the agile approach. In: 10th International Conference on Availability, Reliability and Security, pp. 540\u2013547. IEEE, Toulouse, France (2015)","DOI":"10.1109\/ARES.2015.69"},{"key":"40_CR26","doi-asserted-by":"crossref","unstructured":"Bansal, S.K., Jolly, A.: An encyclopedic approach for realization of security activities with agile methodologies. In: 5th International Conference - Confluence The Next Generation Information Technology Summit (Confluence), pp. 767\u2013772. IEEE, Noida, India (2014)","DOI":"10.1109\/CONFLUENCE.2014.6949242"},{"key":"40_CR27","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1007\/978-3-319-57633-6_13","volume-title":"Agile Processes in Software Engineering and Extreme Programming","author":"DS Cruzes","year":"2017","unstructured":"Cruzes, D.S., Felderer, M., Oyetoyan, T.D., Gander, M., Pekaric, I.: How is security testing done in agile teams? a cross-case analysis of four software Teams. In: Baumeister, H., Lichter, H., Riebisch, M. (eds.) XP 2017. LNBIP, vol. 283, pp. 201\u2013216. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-57633-6_13"},{"key":"40_CR28","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/bs.adcom.2015.11.003","volume":"101","author":"M Felderer","year":"2016","unstructured":"Felderer, M., B\u00fcchler, M., Johns, M., Brucker, A.D., Breu, R., Pretschner, A.: Chapter one - security testing: a survey. Adv. Comput. 101, 1\u201351 (2016)","journal-title":"Adv. Comput."},{"key":"40_CR29","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1007\/978-3-030-58793-2_28","volume-title":"Quality of Information and Communications Technology","author":"CMM Bezerra","year":"2020","unstructured":"Bezerra, C.M.M., Sampaio, S.C.B., Marinho, M.L.M.: Secure agile software development: policies and practices for agile teams. In: Shepperd, M., Brito e Abreu, F., Rodrigues da Silva, A., P\u00e9rez-Castillo, R. (eds.) QUATIC 2020. CCIS, vol. 1266, pp. 343\u2013357. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58793-2_28"},{"issue":"6","key":"40_CR30","doi-asserted-by":"publisher","first-page":"1525","DOI":"10.1007\/s10664-014-9322-z","volume":"20","author":"JM Bass","year":"2015","unstructured":"Bass, J.M.: How product owner teams scale agile methods to large distributed enterprises. Empir. Softw. Eng. 20(6), 1525\u20131557 (2015)","journal-title":"Empir. Softw. Eng."},{"key":"40_CR31","unstructured":"Glaser, B.G.: Theoretical Sensitivity: Advances in the Methodology of Grounded Theory 1978. Sociology Pr., New York (1967)"},{"issue":"1","key":"40_CR32","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/BF00988593","volume":"13","author":"JM Corbin","year":"1990","unstructured":"Corbin, J.M., Strauss, A.: Grounded theory research: procedures, canons, and evaluative criteria. Qual. Sociol. 13(1), 3\u201321 (1990). https:\/\/doi.org\/10.1007\/BF00988593","journal-title":"Qual. Sociol."},{"issue":"4","key":"40_CR33","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1080\/13645570902996301","volume":"13","author":"AJ Hutchison","year":"2010","unstructured":"Hutchison, A.J., Johnston, L.H., Breckon, J.D.: Using QSR-NVivo to facilitate the development of a grounded theory project: an account of a worked example. Int. J. Soc. Res. Methodol. 13(4), 283\u2013302 (2010)","journal-title":"Int. J. Soc. Res. Methodol."},{"key":"40_CR34","unstructured":"Oates, B.J.: Researching information systems and computing. Sage (2005)"}],"container-title":["Lecture Notes in Business Information Processing","Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-95947-0_40","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T13:33:36Z","timestamp":1644932016000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-95947-0_40"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030959463","9783030959470"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-95947-0_40","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"type":"print","value":"1865-1348"},{"type":"electronic","value":"1865-1356"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"16 February 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EMCIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European, Mediterranean, and Middle Eastern Conference on Information Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 December 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 December 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"emcis2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/emcis.eu\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"155","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"54","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}