ICSE 2024
Fri 12 - Sun 21 April 2024 Lisbon, Portugal

Xhesika Ramaj1, Mary Sanchez-Gordon1, Vasileios Gkioulos2, Ricardo Colomo-Palacios3. 1: Østfold University College, Norway; 2: Norwegian University of Science and Technology, Norway; 3: Universidad Politécnica de Madrid, Spain.

Abstract:

Risk management is essential for ensuring the sustained viability of organizations over the long term. It plays a pivotal role in business by helping to identify potential threats and vulnerabilities, thereby enabling well-informed decision-making. Within the context of critical infrastructures, it takes on even greater significance. DevSecOps is an innovative approach to bolstering security of software applications. This approach is being heralded as a transformative solution that encourages the adoption of robust security practices, reduces risk, and ensures uninterrupted business continuity. This study conducts a qualitative approach to unveil the needs and goals of implementing DevSecOps in critical infrastructures from the perspective of DevOps, developers, and security experts. Findings show that the relevance of DevSecOps in critical infrastructures emerges from the need for proactive work, increased efficiency, automation, monitoring mechanisms, security, and outstanding products and services. Findings also identify the goals for establishing a stronger market presence, increasing revenues, and maintaining a leading position in the market. The study contributes to the existing DevSecOps literature by providing insights on DevSevOps in risk management in critical infrastructures. This can potentially encourage the adoption of DevSecOps and guide practitioners interested in leveraging the inherent benefits of this approach in the context of critical infrastructures.

Mon 15 Apr

Displayed time zone: Lisbon change

14:00 - 15:30
Training, knowledge and Industrial challengesEnCyCriS/SVM at Amadeo de Souza-Cardoso
Chair(s): John Eidar Simensen IFE
14:00
20m
Full-paper
Building a Cybersecurity Knowledge Graph with CyberGraph
EnCyCriS/SVM
A: Paolo Falcarin Ca' Foscari University of Venice, A: Fabio Dainese Ca' Foscari University of Venice
14:20
20m
Full-paper
Training Developers to Code Securely: Theory and Practice
EnCyCriS/SVM
A: Ita Ryan University College Cork, A: Utz Roedig University College Cork, A: Klaas-Jan Stol Lero; University College Cork; SINTEF Digital
14:40
20m
Full-paper
On DevSecOps and Risk Management in Critical Infrastructures: Practitioners´Insights on Needs and Goals
EnCyCriS/SVM
A: Xhesika Ramaj Østfold University College (HiØ) / Norwegian University of Science and Technology (NTNU), A: Mary Sánchez-Gordón Østfold University College, A: Vasileios Gkioulos NTNU, A: Ricardo Colomo-Palacios Universidad Politécnica de Madrid
15:00
20m
Full-paper
Cyber-incident Response in Industrial Control Systems: Practices and Challenges in the Petroleum Industry
EnCyCriS/SVM
A: Vahiny Gnanasekaran Norwegian University of Science and Technology NTNU, A: Maria Bartnes Norwegian University of Science and Technology NTNU, A: Tor Olav Grøtan SINTEF Digital, Poul Einar Heegaard Norwegian University of Science and Technology NTNU