Abdulhamid A. Ardo
Implications of regulatory policy for building secure agile software in Nigeria: A grounded theory
Ardo, Abdulhamid A.; A. Ardo, Abdulhamid A.; Bass, Julian M.; Gaber, Tarek
Authors
Abdulhamid A. A. Ardo
Prof Julian Bass J.Bass@salford.ac.uk
Professor of Software Engineering
Tarek Gaber
Abstract
Nigeria is ranked second worldwide, after India, in reported incidences of cyberattacks. Attackers usually exploit vulnerabilities in software which may not have adequately considered security features during the development process. Agile methods have the potential to increase productivity and ensure faster delivery of software, although they tend to neglect non-functional requirements such as security. The implementation of government policies, such as the Nigeria Data Protection Regulation (NDPR) Act 2019, impacts the security activities carried out by agile teams. Despite its significance, there is a paucity of research on security issues especially in the Agile Software Development (ASD) domain. To address this gap, a grounded theory study was conducted with 15 agile software practitioners in Nigeria. Based on our analysis of the interview transcripts, we developed a grounded theory of the security challenges confronting agile practitioners. The four challenges identified were (a) a lack of collaboration between
security and agile teams; (b) the tendency to use foreign software hosting companies; (c) a poor cybersecurity culture; and (d) the high cost of building secure agile software. We used these challenges to identify gaps within the existing secure ASD and found a lack of indigenous software hosting companies in Nigeria. Our study also revealed tensions between the Nigerian regulatory environment and agile software developers' compliance. While practitioners acknowledged the government's efforts, there were concerns about the practicality of implementing such legislation. We recommend government action to increase awareness of local software hosting companies' capabilities, and closer collaboration between agile and security teams. Thus, the novel contribution of this article is the development of the policy adherence challenges (PAC) model.
Citation
Ardo, A. A., A. Ardo, A. A., Bass, J. M., & Gaber, T. (2023). Implications of regulatory policy for building secure agile software in Nigeria: A grounded theory. The Electronic Journal of Information Systems in Developing Countries, 89(6), https://doi.org/10.1002/isd2.12285
Journal Article Type | Article |
---|---|
Acceptance Date | May 31, 2023 |
Online Publication Date | Jun 18, 2023 |
Publication Date | Jun 18, 2023 |
Deposit Date | Jun 29, 2023 |
Publicly Available Date | Jun 29, 2023 |
Journal | The Electronic Journal of Information Systems in Developing Countries |
Electronic ISSN | 1681-4835 |
Publisher | Wiley |
Peer Reviewed | Peer Reviewed |
Volume | 89 |
Issue | 6 |
DOI | https://doi.org/10.1002/isd2.12285 |
Keywords | Information Systems |
Files
Published Version
(1.7 Mb)
PDF
Publisher Licence URL
http://creativecommons.org/licenses/by/4.0/
You might also like
Managing nonâfunctional requirements in agile software development
(2021)
Journal Article
An architecture governance approach for Agile development by tailoring the Spotify model
(2021)
Journal Article
Overcoming team boundaries in agile software development
(2021)
Journal Article
Scrum for product innovation : a longitudinal embedded case study
(2018)
Journal Article
Downloadable Citations
About USIR
Administrator e-mail: library-research@salford.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search