Skip to main content

Showing 1–6 of 6 results for author: Moyón, F

  1. Automated Security Findings Management: A Case Study in Industrial DevOps

    Authors: Markus Voggenreiter, Florian Angermeir, Fabiola Moyón, Ulrich Schöpp, Pierre Bonvin

    Abstract: In recent years, DevOps, the unification of development and operation workflows, has become a trend for the industrial software development lifecycle. Security activities turned into an essential field of application for DevOps principles as they are a fundamental part of secure software development in the industry. A common practice arising from this trend is the automation of security tests that… ▽ More

    Submitted 12 January, 2024; originally announced January 2024.

  2. Industrial Challenges in Secure Continuous Development

    Authors: Fabiola Moyón, Florian Angermeir, Daniel Mendez

    Abstract: The intersection between security and continuous software engineering has been of great interest since the early years of the agile development movement, and it remains relevant as software development processes are more frequently guided by agility and the adoption of DevOps. Several authors have contributed studies about the framing of secure agile development and secure DevOps, motivating acade… ▽ More

    Submitted 12 January, 2024; originally announced January 2024.

  3. Using Process Models to understand Security Standards

    Authors: Fabiola Moyón, Daniel Méndez, Kristian Beckers, Sebastian Klepper

    Abstract: Many industrial software development processes today have to comply with security standards such as the IEC~62443-4-1. These standards, written in natural language, are ambiguous and complex to understand. This is especially true for non-security experts. Security practitioners thus invest much effort into comprehending standards and, later, into introducing them to development teams. However, our… ▽ More

    Submitted 27 May, 2021; originally announced May 2021.

    Comments: Authors Copy

    Journal ref: International Conference on Current Trends in Theory and Practice of Informatics SOFSEM 2021: Theory and Practice of Computer Science pp 458-471

  4. How to Integrate Security Compliance Requirements with Agile Software Engineering at Scale?

    Authors: Fabiola Moyón, Daniel Méndez Fernández, Kristian Beckers, Sebastian Klepper

    Abstract: Integrating security into agile software development is an open issue for research and practice. Especially in strongly regulated industries, complexity increases not only when scaling agile practices but also when aiming for compliance with security standards. To achieve security compliance in a large-scale agile context, we developed S2C-SAFe: An extension of the Scaled Agile Framework that is c… ▽ More

    Submitted 27 May, 2021; originally announced May 2021.

    Comments: Authors' Copy

    Journal ref: Product-Focused Software Process Improvement - 21st International Conference, PROFES 2020

  5. Integration of Security Standards in DevOps Pipelines: An Industry Case Study

    Authors: Fabiola Moyón Constante, Rafael Soares, Maria Pinto-Albuquerque, Daniel Méndez, Kristian Beckers

    Abstract: In the last decade, companies adopted DevOps as a fast path to deliver software products according to customer expectations, with well aligned teams and in continuous cycles. As a basic practice, DevOps relies on pipelines that simulate factory swim-lanes. The more automation in the pipeline, the shorter a lead time is supposed to be. However, applying DevOps is challenging, particularly for indus… ▽ More

    Submitted 27 May, 2021; originally announced May 2021.

    Comments: Author's Copy of the Manuscript

    Journal ref: International Conference on Product-Focused Software Process Improvement PROFES 2020: 434-452

  6. Enterprise-Driven Open Source Software: A Case Study on Security Automation

    Authors: Florian Angermeir, Markus Voggenreiter, Fabiola Moyón, Daniel Mendez

    Abstract: Agile and DevOps are widely adopted by the industry. Hence, integrating security activities with industrial practices, such as continuous integration (CI) pipelines, is necessary to detect security flaws and adhere to regulators' demands early. In this paper, we analyze automated security activities in CI pipelines of enterprise-driven open source software (OSS). This shall allow us, in the long-r… ▽ More

    Submitted 10 February, 2021; originally announced February 2021.

    Comments: To be published in: Proceedings of the 43rd International Conference on Software Engineering: Software Engineering in Practice (SEIP)

    ACM Class: D.2.0