Integrating security into agile software development is an open issue for research and practice. Especially in strongly regulated industries, complexity increases not only when scaling agile practices but also when aiming for compliance with security standards. To achieve security compliance in a large-scale agile context, we developed S2C-SAFe: An extension of the Scaled Agile Framework that is compliant to the security standard IEC~62443-4-1 for secure product development. In this paper, we present the framework and its evaluation by agile and security experts within Siemens' large-scale project ecosystem. We discuss benefits and limitations as well as challenges from a practitioners' perspective. Our results indicate that \ssafe contributes to successfully integrating security compliance with lean and agile development in regulated environments. We also hope to raise awareness for the importance and challenges of integrating security in the scope of Continuous Software Engineering.
翻译:将安全纳入灵活软件开发是一个有待研究和实践的未决问题,特别是在受严格监管的行业,复杂性不仅在推广灵活做法时增加,而且在力求遵守安全标准时也增加。为了在大规模灵活环境下实现安全合规,我们开发了S2C-SAFe:扩大符合安全标准IEC~62443-4-1的大规模Agile框架,用于安全产品开发。在本文件中,我们介绍了框架及其由Siemens大型项目生态系统内灵活和安全专家进行的评估。我们从实践者的角度讨论了好处和限制以及挑战。我们的结果表明,安全有助于成功地将安全合规与受监管环境中的精细和灵活发展结合起来。我们还希望提高对将安全纳入持续软件工程范围的重要性和挑战的认识。