Awang Abu Bakar, Normi Sham and Yahya, Norzariyah and Maidin, Siti Sarah (2026) A framework for secure software engineering in hybrid agile software development. Pertanika Journal of Science & Technology, 34 (4). pp. 2255-2273. ISSN 0128-7680 E-ISSN 2231-8526
|
PDF
- Published Version
Restricted to Registered users only Download (653kB) | Request a copy |
||
|
PDF
- Supplemental Material
Download (284kB) | Preview |
Abstract
This study examines how Secure Software Engineering (SSE) practices can be applied while developing with Hybrid Agile methods. The Hybrid Agile approach combines disciplined planning and extensive documentation, which are the hallmarks of traditional software development, with flexibility, incremental delivery and quick adoption for changing requirements contributed by Agile practices. Generally, existing secure software engineering frameworks only support either classical or Agile methods. As a result, Hybrid Agile implementations rarely provide enough guidance to integrate security throughout the full development life cycle. The purpose of this research is to investigate the current utilisation of secure software engineering practices in Hybrid Agile to identify and introduce security-focused coding elements designed for those environments. In line with the qualitative research approach being used, we evaluate current secure software practices in Hybrid Agile project implementation. In this study, interviews with professional programmers in diverse business sectors were conducted. It is evident that there is a lack of standardised security practices and that it is crucial for managers and project managers to encourage and support these. In addition, it is important that this study highlights the importance of automation tools in secure software engineering practices. With these findings in mind, this paper provides a structured approach for these organisations seeking to integrate security into Hybrid Agile projects and for improving the reliability and integrity of their software applications. The shift towards proactive environments in hybrid software applications requires an assessment of their software development life cycle to deal with security weaknesses and build tools for detecting possible threats in their applications.
| Item Type: | Article (Journal) |
|---|---|
| Uncontrolled Keywords: | Hybrid agile, qualitative analysis, secure software engineering, Software Development Lifecycle (SDLC), software security framework |
| Subjects: | T Technology > T Technology (General) |
| Kulliyyahs/Centres/Divisions/Institutes (Can select more than one option. Press CONTROL button): | Kulliyyah of Information and Communication Technology > Department of Computer Science Kulliyyah of Information and Communication Technology > Department of Computer Science Kulliyyah of Information and Communication Technology Kulliyyah of Information and Communication Technology |
| Depositing User: | Dr. Normi Sham Awang Abu Bakar |
| Date Deposited: | 08 Sep 2026 09:04 |
| Last Update: | 08 Sep 2026 09:04 |
| Queue Number: | 2026-09-Q5018 |
| URI: | http://irep.iium.edu.my/id/eprint/131123 |
| Indexed In: | WOS Core Collection, ERA, Google Scholar, MyCite |
Actions (login required)
![]() |
View Item |
