V. Dorca, R. Munteanu, S. Popescu, A. Chioreanu, Claudius A. Peleskei
{"title":"Agile approach with Kanban in information security risk management","authors":"V. Dorca, R. Munteanu, S. Popescu, A. Chioreanu, Claudius A. Peleskei","doi":"10.1109/AQTR.2016.7501278","DOIUrl":null,"url":null,"abstract":"In an ever changing business environment, in order to bring value, security risk management must keep engaged at pace with the company, by following the enterprise goals and using the same methodologies as core business units. This paper analyses how information security risk management can be automated and interlinked with the processes in a software development company, using an Agile approach with Kanban. The methodology used has been tested (Proof of Concept) applying relevant information security risks for an e-commerce business, the results showing an increase in efficiency of the risk management team, better business response and improvements of the defined risk management SLAs (Service Level Agreement).","PeriodicalId":110627,"journal":{"name":"2016 IEEE International Conference on Automation, Quality and Testing, Robotics (AQTR)","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-05-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 IEEE International Conference on Automation, Quality and Testing, Robotics (AQTR)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/AQTR.2016.7501278","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13
Abstract
In an ever changing business environment, in order to bring value, security risk management must keep engaged at pace with the company, by following the enterprise goals and using the same methodologies as core business units. This paper analyses how information security risk management can be automated and interlinked with the processes in a software development company, using an Agile approach with Kanban. The methodology used has been tested (Proof of Concept) applying relevant information security risks for an e-commerce business, the results showing an increase in efficiency of the risk management team, better business response and improvements of the defined risk management SLAs (Service Level Agreement).