Utilize este identificador para referenciar este registo: http://hdl.handle.net/10071/23411
Registo completo
Campo DCValorIdioma
dc.contributor.authorMóyon, F.-
dc.contributor.authorSoares, R.-
dc.contributor.authorPinto-Albuquerque, M.-
dc.contributor.authorMendez, D.-
dc.contributor.authorBeckers, K.-
dc.contributor.editorMorisio, M., Torchiano, M., and Jedlitschka, A.-
dc.date.accessioned2021-10-27T12:12:39Z-
dc.date.available2021-10-27T12:12:39Z-
dc.date.issued2020-
dc.identifier.isbn978-3-030-64148-1-
dc.identifier.issn0302-9743-
dc.identifier.urihttp://hdl.handle.net/10071/23411-
dc.description.abstractIn the last decade, companies adopted DevOps as a fast path to deliver software products according to customer expectations, with well aligned teams and in continuous cycles. As a basic practice, DevOps relies on pipelines that simulate factory swim-lanes. The more automation in the pipeline, the shorter a lead time is supposed to be. However, applying DevOps is challenging, particularly for industrial control systems (ICS) that support critical infrastructures and that must obey to rigorous requirements from security regulations and standards. Current research on security compliant DevOps presents open gaps for this particular domain and in general for systematic application of security standards. In this paper, we present a systematic approach to integrate standard-based security activities into DevOps pipelines and highlight their automation potential. Our intention is to share our experiences and help practitioners to overcome the trade-off between adding security activities into the development process and keeping a short lead time. We conducted an evaluation of our approach at a large industrial company considering the IEC 62443-4-1 security standard that regulates ICS. The results strengthen our confidence in the usefulness of our approach and artefacts, and in that they can support practitioners to achieve security compliance while preserving agility including short lead times.eng
dc.language.isoeng-
dc.publisherSpringer, Cham-
dc.relationUIDB/04466/2020-
dc.rightsopenAccess-
dc.subjectSecure software engineeringeng
dc.subjectSecurity standardseng
dc.subjectAgile software engineeringeng
dc.subjectDevOps pipelineeng
dc.subjectDevSecOpseng
dc.subjectIndustrial control systemseng
dc.titleIntegration of security standards in DevOps pipelines: An industry case studyeng
dc.typeconferenceObject-
dc.event.title21st International Conference, PROFES 2020-
dc.event.typeConferênciapt
dc.event.locationTurineng
dc.event.date2020-
dc.pagination69 - 87-
dc.peerreviewedyes-
dc.journalProduct-Focused Software Process Improvement. Lecture Notes in Computer Science-
dc.volume12562-
degois.publication.firstPage69-
degois.publication.lastPage87-
degois.publication.locationTurineng
degois.publication.titleIntegration of security standards in DevOps pipelines: An industry case studyeng
dc.date.updated2021-10-27T13:10:32Z-
dc.description.versioninfo:eu-repo/semantics/acceptedVersion-
dc.identifier.doi10.1007/978-3-030-64148-1_27-
iscte.identifier.cienciahttps://ciencia.iscte-iul.pt/id/ci-pub-77760-
iscte.alternateIdentifiers.scopus2-s2.0-85097641509-
Aparece nas coleções:ISTAR-CRI - Comunicações a conferências internacionais

Ficheiros deste registo:
Ficheiro Descrição TamanhoFormato 
conferenceobject_77760.pdfVersão Aceite570,56 kBAdobe PDFVer/Abrir


FacebookTwitterDeliciousLinkedInDiggGoogle BookmarksMySpaceOrkut
Formato BibTex mendeley Endnote Logotipo do DeGóis Logotipo do Orcid 

Todos os registos no repositório estão protegidos por leis de copyright, com todos os direitos reservados.