Paper Title
Agile Secure Software Lifecycle Management, Results of a Devsecops Assurance Maturity Model Measurement
Abstract
Cyber Security, Zero Trust, and Shift Left Security are today’s terms to prevent our digital society being threatened by malicious actors. DevOps, Scrum, and Agile are today’s terms for faster and more flexible delivery of modern software. To combine these two major trends (Security & Agile) methods are needed to improve modern Software Lifecycle Management. The Agile Software Assurance Maturity Model (ASAMM) is a strong security application framework aiming atsoftware development with modern software development methods such as DevOps & Agile whereas Shift Left and Zero Trust security can be adapted from the beginning. The ASAMM is a measurement-based approach based upon an Agile / DevOps Security maturity model on a scale of zero to three and provides practical improvement opportunities for the company using the model. In this article, the results of a (DevSecOps / Agile) Assurance Maturity Model Measurement at 53 companies are discussed providing novel insights, perspectives and advisories for both academics as practitioners and the researched companies around the globe. The research was action based developing scientific knowledge while improving the maturity of the researched organizations.
Keywords - Digital society, Cyber Security, Agile, DevOps, DevSecOps, Maturity, Zero Trust Security