{"id":{"repo_id":"de-montfort","oai_identifier":"oai:dora.dmu.ac.uk:2086/12491"},"canonical_url":"https://search.dev.ndltd.org/etd/de-montfort/oai:dora.dmu.ac.uk:2086/12491","repository":{"repo_id":"de-montfort","name":"De Montfort University","base_url":"https://dora.dmu.ac.uk/server/oai/request"},"display":{"title":"Modelling Security Requirements Through Extending Scrum Agile Development Framework","abstract":"Security is today considered as a basic foundation in software development and therefore, the modelling and implementation of security requirements is an essential part of the production of secure software systems. Information technology organisations are moving towards agile development methods in order to satisfy customers' changing requirements in light of accelerated evolution and time restrictions with their competitors in software production. Security engineering is considered difficult in these incremental and iterative methods due to the frequency of change, integration and refactoring. The objective of this work is to identify and implement practices to extend and improve agile methods to better address challenges presented by security requirements consideration and management. A major practices is security requirements capture mechanisms such as UMLsec for agile development processes. This thesis proposes an extension to the popular Scrum framework by adopting UMLsec security requirements modelling techniques with the introduction of a Security Owner role in the Scrum framework to facilitate such modelling and security requirements considerations generally. The methodology involved experimentation of the inclusion of UMLsec and the Security Owner role to determine their impact on security considerations in the software development process. The results showed that overall security requirements consideration improved and that there was a need for an additional role that has the skills and knowledge to facilitate and realise the benefits of the addition of UMLsec.","abstract_html":"Security is today considered as a basic foundation in software development and therefore, the modelling and implementation of security requirements is an essential part of the production of secure software systems. Information technology organisations are moving towards agile development methods in order to satisfy customers&#x27; changing requirements in light of accelerated evolution and time restrictions with their competitors in software production. Security engineering is considered difficult in these incremental and iterative methods due to the frequency of change, integration and refactoring. The objective of this work is to identify and implement practices to extend and improve agile methods to better address challenges presented by security requirements consideration and management. A major practices is security requirements capture mechanisms such as UMLsec for agile development processes. This thesis proposes an extension to the popular Scrum framework by adopting UMLsec security requirements modelling techniques with the introduction of a Security Owner role in the Scrum framework to facilitate such modelling and security requirements considerations generally. The methodology involved experimentation of the inclusion of UMLsec and the Security Owner role to determine their impact on security considerations in the software development process. The results showed that overall security requirements consideration improved and that there was a need for an additional role that has the skills and knowledge to facilitate and realise the benefits of the addition of UMLsec.","abstract_has_math":false,"creators":["Alotaibi, Minahi"],"institution":"De Montfort University","degree_name":"PhD","degree_level":"Doctoral","degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2016,"date_issued":"2016-02","date_published":"2016-02","updated_at":"2026-07-24T06:18:24Z","subjects":["UML","UMLsec","agile","Scrum","security requirements","Security Owner"],"languages":[],"rights":[],"rights_urls":["https://dora.dmu.ac.uk/bitstreams/524ef4a3-9b25-40e7-a851-c9669ba82785/download"],"identifier_entries":[]},"links":{"outbound_url":null,"outbound_label":null,"outbound_source":null},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Alotaibi, Minahi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.issued","label":"Date","values":["2016-02"]},{"key":"dc:publisher.department","label":"Dc Publisher Department","values":["Faculty of Technology"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["De Montfort University"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["http://hdl.handle.net/2086/12491"]},{"key":"dc:type","label":"Dc Type","values":["Thesis or dissertation"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["Doctoral"]},{"key":"dc:type.qualificationname","label":"Dc Type Qualificationname","values":["PhD"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["UML","UMLsec","agile","Scrum","security requirements","Security Owner"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["https://dora.dmu.ac.uk/bitstreams/524ef4a3-9b25-40e7-a851-c9669ba82785/download"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://dora.dmu.ac.uk/bitstreams/20a2bb59-534a-4461-9cb3-4f8bf3305f8d/download"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Security is today considered as a basic foundation in software development and therefore, the modelling and implementation of security requirements is an essential part of the production of secure software systems. Information technology organisations are moving towards agile development methods in order to satisfy customers' changing requirements in light of accelerated evolution and time restrictions with their competitors in software production. Security engineering is considered difficult in these incremental and iterative methods due to the frequency of change, integration and refactoring. The objective of this work is to identify and implement practices to extend and improve agile methods to better address challenges presented by security requirements consideration and management. A major practices is security requirements capture mechanisms such as UMLsec for agile development processes. This thesis proposes an extension to the popular Scrum framework by adopting UMLsec security requirements modelling techniques with the introduction of a Security Owner role in the Scrum framework to facilitate such modelling and security requirements considerations generally. The methodology involved experimentation of the inclusion of UMLsec and the Security Owner role to determine their impact on security considerations in the software development process. The results showed that overall security requirements consideration improved and that there was a need for an additional role that has the skills and knowledge to facilitate and realise the benefits of the addition of UMLsec."]},{"key":"dc:format.checksum.md5","label":"Dc Format Checksum Md5","values":["42c42823f168ab153ae907ac093da069","cadc57e87fe58fdcd5ae1f8f84f87f29","78074e3b8a5534add636297b434f123a"]},{"key":"dc:title","label":"Title","values":["Modelling Security Requirements Through Extending Scrum Agile Development Framework"]}]}],"canonical_facts":{"dc:creator":["Alotaibi, Minahi"],"dc:date.issued":["2016-02"],"dc:description.abstract":["Security is today considered as a basic foundation in software development and therefore, the modelling and implementation of security requirements is an essential part of the production of secure software systems. Information technology organisations are moving towards agile development methods in order to satisfy customers' changing requirements in light of accelerated evolution and time restrictions with their competitors in software production. Security engineering is considered difficult in these incremental and iterative methods due to the frequency of change, integration and refactoring. The objective of this work is to identify and implement practices to extend and improve agile methods to better address challenges presented by security requirements consideration and management. A major practices is security requirements capture mechanisms such as UMLsec for agile development processes. This thesis proposes an extension to the popular Scrum framework by adopting UMLsec security requirements modelling techniques with the introduction of a Security Owner role in the Scrum framework to facilitate such modelling and security requirements considerations generally. The methodology involved experimentation of the inclusion of UMLsec and the Security Owner role to determine their impact on security considerations in the software development process. The results showed that overall security requirements consideration improved and that there was a need for an additional role that has the skills and knowledge to facilitate and realise the benefits of the addition of UMLsec."],"dc:format.checksum.md5":["42c42823f168ab153ae907ac093da069","cadc57e87fe58fdcd5ae1f8f84f87f29","78074e3b8a5534add636297b434f123a"],"dc:identifier.uri":["https://dora.dmu.ac.uk/bitstreams/20a2bb59-534a-4461-9cb3-4f8bf3305f8d/download"],"dc:publisher.department":["Faculty of Technology"],"dc:publisher.institution":["De Montfort University"],"dc:relation.isreferencedby":["http://hdl.handle.net/2086/12491"],"dc:rights":["https://dora.dmu.ac.uk/bitstreams/524ef4a3-9b25-40e7-a851-c9669ba82785/download"],"dc:subject":["UML","UMLsec","agile","Scrum","security requirements","Security Owner"],"dc:title":["Modelling Security Requirements Through Extending Scrum Agile Development Framework"],"dc:type":["Thesis or dissertation"],"dc:type.qualificationlevel":["Doctoral"],"dc:type.qualificationname":["PhD"]},"updated_at":"2026-07-24T06:18:24Z"}