Implications of regulatory policy for building secure agile software in Nigeria: A grounded theory

نویسندگان

چکیده

Nigeria is ranked second worldwide, after India, in reported incidences of cyberattacks. Attackers usually exploit vulnerabilities software which may not have adequately considered security features during the development process. Agile methods potential to increase productivity and ensure faster delivery software, although they tend neglect non-functional requirements such as security. The implementation government policies, Data Protection Regulation (NDPR) Act 2019, impacts activities carried out by agile teams. Despite its significance, there a paucity research on issues especially Software Development (ASD) domain. To address this gap, grounded theory study was conducted with 15 practitioners Nigeria. Based our analysis interview transcripts, we developed challenges confronting practitioners. four identified were (a) lack collaboration between teams; (b) tendency use foreign hosting companies; (c) poor cybersecurity culture; (d) high cost building secure software. We used these identify gaps within existing ASD found indigenous companies Our also revealed tensions Nigerian regulatory environment developers' compliance. While acknowledged government's efforts, concerns about practicality implementing legislation. recommend action awareness local companies' capabilities, closer Thus, novel contribution article policy adherence (PAC) model.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Developing Secure Software in a Agile environment

Software developers can use agile software development methods to build secure information systems. Current agile methods have few explicit security features. While several discrete security methods can supplement agile methods, few of these integrate seamlessly into other software development methods. Because of the severe constraints imposed by agile methods, these discrete security technique...

متن کامل

making sense of grounded theory approach: implications for

this article first gives a definition of grounded theory and its development and use in medicine and medical education. the fundamental differences of grounded theory with quantitative methods are discussed along a full discussion of the steps required to use a grounded theory approach. at the end the questions in the area of medical education which can best addressed with this approach are pro...

متن کامل

Implications for Regulatory Policy

In this issue... The federal government designs the CRTC's regulatory policies to promote the entry of new firms into the market for wireline local access services using current facilities and technology. Yet the current pace of technological change means that competition cannot be measured simply by counting the number of competitors in the market. What is needed are incentives for firms to in...

متن کامل

Designing a policy-making model in skill based education using a Grounded Theory approach

The purpose of this study was to present a model for policy making in technical and skills education. Ruling paradigm over this study was a constructivist interpretation and a qualitatively methodology. This research was conducted using Grounded Theory (Strauss and Corbin design). In order to design a policy-making model, the experts in the subject of skill training policy were interviewed and ...

متن کامل

Challenges to Soil Erosion Control Measures among Farmers in Anambra State, Nigeria: Implications for Extension Policy

The study investigated challenges to soil erosion control measures among farmers in Anambra State, Nigeria. Purposive, multistage and random sampling techniques were employed in selecting a sample size of two hundred and forty (240) respondents. Structured interview schedule was used for data collection. Frequency counts, percentage, mean scores and factor analysis were used for data analysis. ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: EJISDC: The Electronic Journal on Information Systems in Developing Countries

سال: 2023

ISSN: ['1681-4835']

DOI: https://doi.org/10.1002/isd2.12285