Assessing Team Security Maturity in Large-Scale Agile Development

Sascha Nägele, Jan Philipp Watzelt, Florian Matthes

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Organizations struggle to balance agile team autonomy and strict security governance in large-scale agile development environments. In particular, conventional top-down IT governance mechanisms often conflict with the desired autonomy of decentralized agile teams. Our research presents a novel approach to resolve the tension between security governance and development agility: a criteria-based security maturity assessment that enables greater autonomy for mature agile teams. Leveraging design science research, a literature review, and an interview study, we introduce two key contributions: a criteria catalog for evaluating a team's capabilities and a team security maturity model. Our expert evaluation confirms their value for systematically assessing the teams' capabilities to deliver secure and compliant applications, allowing organizations to grant more autonomy to mature teams and prioritize supporting lower-maturity teams. Future work could go beyond expert interviews and implement and evaluate the team security maturity model through a case study or experiments.

Original languageEnglish
Title of host publicationProceedings of the 57th Annual Hawaii International Conference on System Sciences, HICSS 2024
EditorsTung X. Bui
PublisherIEEE Computer Society
Pages7259-7268
Number of pages10
ISBN (Electronic)9780998133171
StatePublished - 2024
Event57th Annual Hawaii International Conference on System Sciences, HICSS 2024 - Honolulu, United States
Duration: 3 Jan 20246 Jan 2024

Publication series

NameProceedings of the Annual Hawaii International Conference on System Sciences
ISSN (Print)1530-1605

Conference

Conference57th Annual Hawaii International Conference on System Sciences, HICSS 2024
Country/TerritoryUnited States
CityHonolulu
Period3/01/246/01/24

Keywords

  • Large-scale agile development
  • compliance
  • governance
  • security
  • team maturity

Fingerprint

Dive into the research topics of 'Assessing Team Security Maturity in Large-Scale Agile Development'. Together they form a unique fingerprint.

Cite this