Un Marco de Trabajo para el Desarrollo de Software Web Seguro con Metodologías Ágiles

Descripción del Articulo

Software development using the agile approach with SCRUM presents itself as an alternative to traditional methodologies, offering incremental, iterative features and continuous code delivery that ensure a product adaptable to changes. However, this approach faces challenges in terms of secure develo...

Descripción completa

Detalles Bibliográficos
Autores: Valderrama Herrera, Gilmer Glicerio, Herrera Quispe, José Alfredo
Formato: artículo
Fecha de Publicación:2024
Institución:Universidad Nacional Mayor de San Marcos
Repositorio:Revistas - Universidad Nacional Mayor de San Marcos
Lenguaje:español
OAI Identifier:oai:revistasinvestigacion.unmsm.edu.pe:article/27402
Enlace del recurso:https://revistasinvestigacion.unmsm.edu.pe/index.php/rpcsis/article/view/27402
Nivel de acceso:acceso abierto
Materia:Secure software
Secure Development
Secure Agile Development
software Seguro
Desarrollo Seguro
Desarrollo Agile Seguro
Descripción
Sumario:Software development using the agile approach with SCRUM presents itself as an alternative to traditional methodologies, offering incremental, iterative features and continuous code delivery that ensure a product adaptable to changes. However, this approach faces challenges in terms of secure development, as threats and vulnerabilities may not be adequately addressed due to tight deadlines and frequent changes in requirements. In this context, a framework for secure web software development using Agile Methodologies (SCRUM) is proposed. Based on the literature, eight security activities have been selected for this purpose and integrated into the development process, considering their level of agility and cost-benefit. The validity of this proposal was confirmed through an instrument that gathered the opinions of 45 experts in the software development industry in Peru.
Nota importante:
La información contenida en este registro es de entera responsabilidad de la institución que gestiona el repositorio institucional donde esta contenido este documento o set de datos. El CONCYTEC no se hace responsable por los contenidos (publicaciones y/o datos) accesibles a través del Repositorio Nacional Digital de Ciencia, Tecnología e Innovación de Acceso Abierto (ALICIA).