Towards Automated Continuous Security Compliance
Florian Angermeir, Jannik Fischbach, Fabiola Moy\'on, Daniel Mendez

TL;DR
This paper defines continuous security compliance, reviews current challenges through literature, and proposes a research roadmap to advance automation in continuous security compliance for regulated industries.
Contribution
It offers a clear definition, analyzes challenges, and outlines a research roadmap for automating continuous security compliance in software engineering.
Findings
Defined continuous security compliance precisely.
Identified key challenges through literature review.
Proposed a research roadmap for automation.
Abstract
Context: Continuous Software Engineering is increasingly adopted in highly regulated domains, raising the need for continuous compliance. Adherence to especially security regulations -- a major concern in highly regulated domains -- renders Continuous Security Compliance of high relevance to industry and research. Problem: One key barrier to adopting continuous software engineering in the industry is the resource-intensive and error-prone nature of traditional manual security compliance activities. Automation promises to be advantageous. However, continuous security compliance is under-researched, precluding an effective adoption. Contribution: We have initiated a long-term research project with our industry partner to address these issues. In this manuscript, we make three contributions: (1) We provide a precise definition of the term continuous security compliance aligning with…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Information and Cyber Security · Network Security and Intrusion Detection
