Agile Implementations in Cyber Security: Issues Arising and Recommendations
摘要
As Agile project management methodologies increasingly move from the Software Engineering area of the company to universal adoption across the whole Enterprise, implementations of Agile are becoming increasingly common in operational departments. The Agile framework chosen for implementation is usually “Scrum” as this is the most common Agile framework. Unfortunately, many of these large-scale organizations are finding that Scrum is problematic when it is taken from Software Engineering into other, more operationally focused, departments. This paper conducts a literature review that identifies the issues that emerge after implementing Agile practices (in the form of Scrum) within Cyber Security departments of large organizations. It then reviews alternative Agile Frameworks and identifies that Scaling Agile frameworks have been successfully used in environments analogous to Cyber Security Departments. It finds that some Scaling Agile frameworks fail to address all of the issues reported as a result of Scrum implementations in Cyber Security, so this study identifies which frameworks are useful in these circumstances and discusses the required implementation strategies.