在Devsecops环境中进行可用性测试

Emerson Czerwinski Burkard
{"title":"在Devsecops环境中进行可用性测试","authors":"Emerson Czerwinski Burkard","doi":"10.1109/ICNS50378.2020.9222919","DOIUrl":null,"url":null,"abstract":"Software Development, Security, and Operations, or \"DevSecOps\", is a concept that has been implemented in the engineering domain to enable faster iteration release and increased fluidity with enhanced security. As iterations become smaller and more frequent, less risk is involved with each deployment. Reducing risk is a significant part of any engineering endeavor, particularly in the aviation domain. Of the fundamental DevSecOps elements, the meshing of teams enables more free-flowing communication. DevSecOps is also an ideal methodology for inviting change in how teams operate during product creation. A team’s interpretation of a product does not always align with the needs of end-users and their requirements. Formally bringing end-users into the feedback loop would be the logical step for amending this misalignment. One fundamental aspect is ensuring a vehicle exists to bring user feedback into the team's field of view. The solution to this is to integrate a formalized testing methodology that invokes this feedback from future users. An ideal method of accomplishing this is through a process called usability testing. This process involves inviting representative users to utilize major touchpoints and features, ensuring safety and effectivity. Usability testing is best performed \"early and often\" to allow corrective measures to be taken if needed. As the DevSecOps cycle is iterative in nature, this poses the ideal opportunity to include user-based testing, enabling user facing modifications to become more dynamically engineered and honed to the area of interest, while maintaining built-in security. By testing software and user-facing elements in multiple times within each release the team is afforded more granular insight into the holistic state of the product without negating security considerations.","PeriodicalId":424869,"journal":{"name":"2020 Integrated Communications Navigation and Surveillance Conference (ICNS)","volume":"76 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Usability Testing within a Devsecops Environment\",\"authors\":\"Emerson Czerwinski Burkard\",\"doi\":\"10.1109/ICNS50378.2020.9222919\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Software Development, Security, and Operations, or \\\"DevSecOps\\\", is a concept that has been implemented in the engineering domain to enable faster iteration release and increased fluidity with enhanced security. As iterations become smaller and more frequent, less risk is involved with each deployment. Reducing risk is a significant part of any engineering endeavor, particularly in the aviation domain. Of the fundamental DevSecOps elements, the meshing of teams enables more free-flowing communication. DevSecOps is also an ideal methodology for inviting change in how teams operate during product creation. A team’s interpretation of a product does not always align with the needs of end-users and their requirements. Formally bringing end-users into the feedback loop would be the logical step for amending this misalignment. One fundamental aspect is ensuring a vehicle exists to bring user feedback into the team's field of view. The solution to this is to integrate a formalized testing methodology that invokes this feedback from future users. An ideal method of accomplishing this is through a process called usability testing. This process involves inviting representative users to utilize major touchpoints and features, ensuring safety and effectivity. Usability testing is best performed \\\"early and often\\\" to allow corrective measures to be taken if needed. As the DevSecOps cycle is iterative in nature, this poses the ideal opportunity to include user-based testing, enabling user facing modifications to become more dynamically engineered and honed to the area of interest, while maintaining built-in security. By testing software and user-facing elements in multiple times within each release the team is afforded more granular insight into the holistic state of the product without negating security considerations.\",\"PeriodicalId\":424869,\"journal\":{\"name\":\"2020 Integrated Communications Navigation and Surveillance Conference (ICNS)\",\"volume\":\"76 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 Integrated Communications Navigation and Surveillance Conference (ICNS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICNS50378.2020.9222919\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 Integrated Communications Navigation and Surveillance Conference (ICNS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICNS50378.2020.9222919","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

软件开发、安全和运维,或者“DevSecOps”,是一个已经在工程领域实现的概念,以实现更快的迭代发布和增强安全性的流动性。随着迭代变得越来越小,越来越频繁,每次部署所涉及的风险也越来越小。降低风险是任何工程努力的重要组成部分,特别是在航空领域。在DevSecOps的基本元素中,团队的网格化实现了更自由的通信。DevSecOps也是一种理想的方法,可以改变团队在产品创建过程中的运作方式。团队对产品的解释并不总是与最终用户的需求和他们的需求保持一致。将最终用户正式引入反馈循环将是修正这种偏差的合乎逻辑的步骤。一个基本的方面是确保车辆的存在能够将用户反馈带入团队的视野。这个问题的解决方案是集成一个正式的测试方法,调用来自未来用户的反馈。实现这一目标的理想方法是通过可用性测试。这个过程包括邀请有代表性的用户使用主要的接触点和功能,以确保安全性和有效性。可用性测试最好“尽早且经常”进行,以便在需要时采取纠正措施。由于DevSecOps周期本质上是迭代的,这为包含基于用户的测试提供了理想的机会,使用户面对的修改能够更加动态地设计和磨练到感兴趣的领域,同时保持内置的安全性。通过在每个版本中多次测试软件和面向用户的元素,团队可以更细致地了解产品的整体状态,而不会否定安全性考虑。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Usability Testing within a Devsecops Environment
Software Development, Security, and Operations, or "DevSecOps", is a concept that has been implemented in the engineering domain to enable faster iteration release and increased fluidity with enhanced security. As iterations become smaller and more frequent, less risk is involved with each deployment. Reducing risk is a significant part of any engineering endeavor, particularly in the aviation domain. Of the fundamental DevSecOps elements, the meshing of teams enables more free-flowing communication. DevSecOps is also an ideal methodology for inviting change in how teams operate during product creation. A team’s interpretation of a product does not always align with the needs of end-users and their requirements. Formally bringing end-users into the feedback loop would be the logical step for amending this misalignment. One fundamental aspect is ensuring a vehicle exists to bring user feedback into the team's field of view. The solution to this is to integrate a formalized testing methodology that invokes this feedback from future users. An ideal method of accomplishing this is through a process called usability testing. This process involves inviting representative users to utilize major touchpoints and features, ensuring safety and effectivity. Usability testing is best performed "early and often" to allow corrective measures to be taken if needed. As the DevSecOps cycle is iterative in nature, this poses the ideal opportunity to include user-based testing, enabling user facing modifications to become more dynamically engineered and honed to the area of interest, while maintaining built-in security. By testing software and user-facing elements in multiple times within each release the team is afforded more granular insight into the holistic state of the product without negating security considerations.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Distributed Mobility Anchoring Using LISP Mobile Node Likelihood of Unmitigated Collision Risks for Uas in Defined Airspace Volumes Tree-Based Airspace Capacity Estimation Design of a Vertiport Design Tool Comparing Regain Well Clear Guidance
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1