Secure Coding mailing list archives

Re: Agile (Scrum) best security practices and experiences?


From: Jari Pirhonen <japi () iki fi>
Date: Wed, 08 Sep 2010 15:05:09 +0300

8.9.2010 11:37, Martin Gilje Jaatun kirjoitti:

I may have mentioned before on this list that my dream is to do an
in-depth comparative study of "traditional" and "agile" development
organizations to determine which produces the best (i.e., most secure)
code? The first challenge would be to figure out how to compare the
"security level" of two different types of software products...
(Actually, the first challenge is to get funding for this...)


This study would be very interesting. I've asked around if there're any studies/papers showing that agile actually produces better (or as good) software than waterfall/iterative methods. I understand that there are many advantages and many organizations are happy with agile development. It would be nice see some serious studies, though.

Jari
_______________________________________________
Secure Coding mailing list (SC-L) SC-L () securecoding org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates
_______________________________________________


Current thread: