Skip to main content

Research Repository

Advanced Search

Implications of regulatory policy for building secure agile software in Nigeria: A grounded theory

Ardo, Abdulhamid A.; A. Ardo, Abdulhamid A.; Bass, Julian M.; Gaber, Tarek

Implications of regulatory policy for building secure agile software in Nigeria: A grounded theory Thumbnail


Authors

Abdulhamid A. Ardo

Abdulhamid A. A. Ardo

Tarek Gaber



Abstract

Nigeria is ranked second worldwide, after India, in reported incidences of cyberattacks. Attackers usually exploit vulnerabilities in software which may not have adequately considered security features during the development process. Agile methods have the potential to increase productivity and ensure faster delivery of software, although they tend to neglect non-functional requirements such as security. The implementation of government policies, such as the Nigeria Data Protection Regulation (NDPR) Act 2019, impacts the security activities carried out by agile teams. Despite its significance, there is a paucity of research on security issues especially in the Agile Software Development (ASD) domain. To address this gap, a grounded theory study was conducted with 15 agile software practitioners in Nigeria. Based on our analysis of the interview transcripts, we developed a grounded theory of the security challenges confronting agile practitioners. The four challenges identified were (a) a lack of collaboration between
security and agile teams; (b) the tendency to use foreign software hosting companies; (c) a poor cybersecurity culture; and (d) the high cost of building secure agile software. We used these challenges to identify gaps within the existing secure ASD and found a lack of indigenous software hosting companies in Nigeria. Our study also revealed tensions between the Nigerian regulatory environment and agile software developers' compliance. While practitioners acknowledged the government's efforts, there were concerns about the practicality of implementing such legislation. We recommend government action to increase awareness of local software hosting companies' capabilities, and closer collaboration between agile and security teams. Thus, the novel contribution of this article is the development of the policy adherence challenges (PAC) model.

Citation

Ardo, A. A., A. Ardo, A. A., Bass, J. M., & Gaber, T. (2023). Implications of regulatory policy for building secure agile software in Nigeria: A grounded theory. The Electronic Journal of Information Systems in Developing Countries, 89(6), https://doi.org/10.1002/isd2.12285

Journal Article Type Article
Acceptance Date May 31, 2023
Online Publication Date Jun 18, 2023
Publication Date Jun 18, 2023
Deposit Date Jun 29, 2023
Publicly Available Date Jun 29, 2023
Journal The Electronic Journal of Information Systems in Developing Countries
Electronic ISSN 1681-4835
Publisher Wiley
Peer Reviewed Peer Reviewed
Volume 89
Issue 6
DOI https://doi.org/10.1002/isd2.12285
Keywords Information Systems

Files




You might also like



Downloadable Citations