Practices and challenges of threat modelling in agile environments

dc.contributor.authorTheurich, Paul
dc.contributor.authorWitt, Josepha
dc.contributor.authorRichter, Sebastian
dc.date.accessioned2026-01-29T12:36:25Z
dc.date.available2026-01-29T12:36:25Z
dc.date.issued2023
dc.date.updated2025-12-04T16:36:58Z
dc.description.abstractFacing the increasing annual cybersecurity costs, threat modelling (TM) is a method to consider security as early as possible in the software development life cycle (SDLC). Thereby, TM helps to identify and address security-related design flaws in information systems. As the original TM approach is based on sequential development, it is not aligned with today’s predominantly agile environments. This results in several challenges. However, TM’s implementation in an agile development approach lacks the recommendations on how to tackle these challenges. Therefore, we assess the state-of-the-art of TM challenges and practices in agile environments by conducting a literature review covering 220 papers. Thereby, we identify nine categories of challenges and six categories of practices. We propose a valuable artefact for practitioners by mapping challenges and practices to the agile SDLC and by creating a matrix highlighting how the practices address the challenges of TM in an agile environment.en
dc.description.sponsorshipOpen Access funding enabled and organized by Projekt DEAL.
dc.description.sponsorshipUniversität Hohenheim (3153)
dc.identifier.urihttps://doi.org/10.1007/s00287-023-01549-5
dc.identifier.urihttps://hohpublica.uni-hohenheim.de/handle/123456789/18607
dc.language.isoeng
dc.rights.licensecc_by
dc.subjectThreat modelling
dc.subjectCybersecurity
dc.subjectAgile software development
dc.subjectSecure SDLC
dc.subjectSecurity-by-design
dc.subject.ddc000
dc.titlePractices and challenges of threat modelling in agile environmentsen
dc.type.diniArticle
dcterms.bibliographicCitationInformatik-Spektrum, 46 (2023), 4, 220-229. https://doi.org/10.1007/s00287-023-01549-5. ISSN: 1432-122X
dcterms.bibliographicCitation.issn1432-122X
dcterms.bibliographicCitation.issue4
dcterms.bibliographicCitation.journaltitleInformatik-Spektrum
dcterms.bibliographicCitation.pageend229
dcterms.bibliographicCitation.pagestart220
dcterms.bibliographicCitation.volume46
local.export.bibtex@article{Theurich2023, doi = {10.1007/s00287-023-01549-5}, author = {Theurich, Paul and Witt, Josepha and Richter, Sebastian et al.}, title = {Practices and challenges of threat modelling in agile environments}, journal = {Informatik Spektrum}, year = {2023}, volume = {46}, number = {4}, pages = {220--229}, }
local.subject.sdg9
local.subject.sdg16
local.title.fullPractices and challenges of threat modelling in agile environments
local.university.bibliographyhttps://hohcampus.verw.uni-hohenheim.de/qisserver/a/fs.res.frontend/pub/view/43316

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
s00287-023-01549-5.pdf
Size:
924.35 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
7.85 KB
Format:
Item-specific license agreed to upon submission
Description: