The Experts below are selected from a list of 1638 Experts worldwide ranked by ideXlab platform
Tim Scammell - One of the best experts on this subject based on the ideXlab platform.
-
Security Architecture one practitioner s view
2003Co-Authors: Tim ScammellAbstract:The “Security Architect” is a key function within many corporations, or at least it should be. This role could function as a “corporate clutch,” providing an interface between the Security policymakers and those tasked with providing information systems (IS) solutions to businesses. Such a role needs to balance the demands of the policy setters against the implementation barriers (available technology, integration and cost barriers) facing the IT department and derive a solution that is costeffective, yet meets business requirements. This balancing act falls short of being a science and demands the application of a wide range of tools and techniques, both technical and personal. This article takes one practitioner’s experiences and explains the techniques found to be effective.
Andreas Jacobsson - One of the best experts on this subject based on the ideXlab platform.
-
a novel Security enhanced agile software development process applied in an industrial setting
Availability Reliability and Security, 2015Co-Authors: Dejan Baca, Martin Boldt, Bengt Carlsson, Andreas JacobssonAbstract:A Security-enhanced agile software development process, SEAP, is introduced in the development of a mobile money transfer system at Ericsson Corp. A specific characteristic of SEAP is that it includes a Security group consisting of four different competences, i.e., Security manager, Security Architect, Security master and penetration tester. Another significant feature of SEAP is an integrated risk analysis process. In analyzing risks in the development of the mobile money transfer system, a general finding was that SEAP either solves risks that were previously postponed or solves a larger proportion of the risks in a timely manner. The previous software development process, i.e., The baseline process of the comparison outlined in this paper, required 2.7 employee hours spent for every risk identified in the analysis process compared to, on the average, 1.5 hours for the SEAP. The baseline development process left 50% of the risks unattended in the software version being developed, while SEAP reduced that figure to 22%. Furthermore, SEAP increased the proportion of risks that were corrected from 12.5% to 67.1%, i.e., More than a five times increment. This is important, since an early correction may avoid severe attacks in the future. The Security competence in SEAP accounts for 5% of the personnel cost in the mobile money transfer system project. As a comparison, the corresponding figure, i.e., For Security, was 1% in the previous development process.
Dejan Baca - One of the best experts on this subject based on the ideXlab platform.
-
a novel Security enhanced agile software development process applied in an industrial setting
Availability Reliability and Security, 2015Co-Authors: Dejan Baca, Martin Boldt, Bengt Carlsson, Andreas JacobssonAbstract:A Security-enhanced agile software development process, SEAP, is introduced in the development of a mobile money transfer system at Ericsson Corp. A specific characteristic of SEAP is that it includes a Security group consisting of four different competences, i.e., Security manager, Security Architect, Security master and penetration tester. Another significant feature of SEAP is an integrated risk analysis process. In analyzing risks in the development of the mobile money transfer system, a general finding was that SEAP either solves risks that were previously postponed or solves a larger proportion of the risks in a timely manner. The previous software development process, i.e., The baseline process of the comparison outlined in this paper, required 2.7 employee hours spent for every risk identified in the analysis process compared to, on the average, 1.5 hours for the SEAP. The baseline development process left 50% of the risks unattended in the software version being developed, while SEAP reduced that figure to 22%. Furthermore, SEAP increased the proportion of risks that were corrected from 12.5% to 67.1%, i.e., More than a five times increment. This is important, since an early correction may avoid severe attacks in the future. The Security competence in SEAP accounts for 5% of the personnel cost in the mobile money transfer system project. As a comparison, the corresponding figure, i.e., For Security, was 1% in the previous development process.
Martin Boldt - One of the best experts on this subject based on the ideXlab platform.
-
a novel Security enhanced agile software development process applied in an industrial setting
Availability Reliability and Security, 2015Co-Authors: Dejan Baca, Martin Boldt, Bengt Carlsson, Andreas JacobssonAbstract:A Security-enhanced agile software development process, SEAP, is introduced in the development of a mobile money transfer system at Ericsson Corp. A specific characteristic of SEAP is that it includes a Security group consisting of four different competences, i.e., Security manager, Security Architect, Security master and penetration tester. Another significant feature of SEAP is an integrated risk analysis process. In analyzing risks in the development of the mobile money transfer system, a general finding was that SEAP either solves risks that were previously postponed or solves a larger proportion of the risks in a timely manner. The previous software development process, i.e., The baseline process of the comparison outlined in this paper, required 2.7 employee hours spent for every risk identified in the analysis process compared to, on the average, 1.5 hours for the SEAP. The baseline development process left 50% of the risks unattended in the software version being developed, while SEAP reduced that figure to 22%. Furthermore, SEAP increased the proportion of risks that were corrected from 12.5% to 67.1%, i.e., More than a five times increment. This is important, since an early correction may avoid severe attacks in the future. The Security competence in SEAP accounts for 5% of the personnel cost in the mobile money transfer system project. As a comparison, the corresponding figure, i.e., For Security, was 1% in the previous development process.
Bengt Carlsson - One of the best experts on this subject based on the ideXlab platform.
-
a novel Security enhanced agile software development process applied in an industrial setting
Availability Reliability and Security, 2015Co-Authors: Dejan Baca, Martin Boldt, Bengt Carlsson, Andreas JacobssonAbstract:A Security-enhanced agile software development process, SEAP, is introduced in the development of a mobile money transfer system at Ericsson Corp. A specific characteristic of SEAP is that it includes a Security group consisting of four different competences, i.e., Security manager, Security Architect, Security master and penetration tester. Another significant feature of SEAP is an integrated risk analysis process. In analyzing risks in the development of the mobile money transfer system, a general finding was that SEAP either solves risks that were previously postponed or solves a larger proportion of the risks in a timely manner. The previous software development process, i.e., The baseline process of the comparison outlined in this paper, required 2.7 employee hours spent for every risk identified in the analysis process compared to, on the average, 1.5 hours for the SEAP. The baseline development process left 50% of the risks unattended in the software version being developed, while SEAP reduced that figure to 22%. Furthermore, SEAP increased the proportion of risks that were corrected from 12.5% to 67.1%, i.e., More than a five times increment. This is important, since an early correction may avoid severe attacks in the future. The Security competence in SEAP accounts for 5% of the personnel cost in the mobile money transfer system project. As a comparison, the corresponding figure, i.e., For Security, was 1% in the previous development process.