A Security Evaluation Framework for U.K. E-Goverment Services Agile Software Development
Steve Harrison, Antonis Tzounis, Leandros A. Maglaras, Francois Siewe,, Richard Smith, Helge Janicke

TL;DR
This paper proposes a security evaluation framework integrating Agile development with government accreditation processes in the UK, aiming to enhance security assurance without delaying deployment.
Contribution
It introduces a novel framework based on OWASP ASVS to align Agile practices with security accreditation requirements in UK government projects.
Findings
Framework enables secure Agile development within government context
Reduces delays caused by traditional Waterfall accreditation
Facilitates security assurance alongside rapid development cycles
Abstract
This study examines the traditional approach to software development within the United Kingdom Government and the accreditation process. Initially we look at the Waterfall methodology that has been used for several years. We discuss the pros and cons of Waterfall before moving onto the Agile Scrum methodology. Agile has been adopted by the majority of Government digital departments including the Government Digital Services. Agile, despite its ability to achieve high rates of productivity organized in short, flexible, iterations, has faced security professionals disbelief when working within the U.K. Government. One of the major issues is that we develop in Agile but the accreditation process is conducted using Waterfall resulting in delays to go live dates. Taking a brief look into the accreditation process that is used within Government for I.T. systems and applications, we focus on…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
