<?xml version="1.0"?>
<metadata xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/"><dc:title>A delegation-based lightweight agile approach for secure software development in small and medium enterprises</dc:title><dc:creator>Mihelič,	Anže	(Avtor)
	</dc:creator><dc:creator>Hovelja,	Tomaž	(Mentor)
	</dc:creator><dc:creator>Vrhovec,	Simon	(Komentor)
	</dc:creator><dc:subject>secure software development</dc:subject><dc:subject>software engineering</dc:subject><dc:subject>agile</dc:subject><dc:subject>lean</dc:subject><dc:subject>small and medium sized enterprises</dc:subject><dc:subject>software development management</dc:subject><dc:subject>security</dc:subject><dc:description>The software development workflow is typically defined by a specific development methodology and then further organized by distinct phases for more effective software production. Secure software development aims to integrate security measures throughout this process to create a more secure end product. However, agile methodologies face challenges incorporating security features due to their characteristics like adaptability, rapid release cycles, and continuous feedback. Existing solutions within the literature propose embedding permanent security roles, processes, and artifacts into agile methods. These solutions, however, are constrained by their lack of adaptability to situational factors and their method-specific designs, such as for Scrum or Extreme Programming (XP), limiting their applicability in different development methods. In this dissertation, we introduce two novel approaches: the "ATTRACT Approach" for secure software development and an approach for evaluating existing software development methods from a security perspective. Unlike existing solutions, the ATTRACT Approach is not tied to any particular software development methodology. It is designed to incrementally build security knowledge and awareness in a temporary and iterative manner, taking into account the unique circumstances of the development enterprise. It is particularly suited for small and medium-sized enterprises. Meanwhile, our evaluation approach assesses various development methods and their elements based on three core dimensions: enhanced security, cost-efficiency, and retained agility. Both approaches were evaluated in a real-world, longitudinal, multiple-case study. The findings suggest that adopting these approaches elevates the security knowledge and awareness of project teams, fosters security-focused problem-solving, enhances code quality and review processes, and encourages the implementation of customized security measures in the end products. While developers reported a learning curve in adapting these approaches, the teams overall found that their initial expectations were met.</dc:description><dc:date>2024</dc:date><dc:date>2024-02-14 08:15:05</dc:date><dc:type>Doktorsko delo/naloga</dc:type><dc:identifier>154420</dc:identifier><dc:identifier>VisID: 28061</dc:identifier><dc:identifier>COBISS_ID: 185436163</dc:identifier><dc:language>sl</dc:language></metadata>
