Designing a Security-First Scrum Framework with AI Enhancements
| dc.contributor.author | Asad, Arslaan | |
| dc.contributor.department | fi=Tietotekniikan laitos|en=Department of Computing| | |
| dc.contributor.faculty | fi=Teknillinen tiedekunta|en=Faculty of Technology| | |
| dc.contributor.studysubject | fi=Tietotekniikka|en=Information and Communication Technology| | |
| dc.date.accessioned | 2026-06-17T19:31:29Z | |
| dc.date.issued | 2026-06-05 | |
| dc.description.abstract | This thesis addresses the challenge of integrating software security into Scrum-based Agile development, where security activities are often neglected or treated as separate from the development process. Despite extensive research on securing Scrum, many existing approaches remain impractical for real-world adoption due to their complexity or reliance on specialised expertise. To address this gap, this study proposes an LLM-Supported Secure Scrum (LSS) framework that embeds security practices directly into Scrum artefacts, thereby ensuring continuous visibility and prioritisation of security early in the development lifecycle. The framework design is grounded in a structured literature review with thematic synthesis, which identifies security practices suitable for Agile environments. In addition, the framework incorporates Large Language Models (LLMs) as an enabling mechanism to operationalise and support these practices within development workflows. Specifically, in this thesis, LLMs are used to assist key security activities, including risk identification, S-Tag generation, misuse and abuser stories, security acceptance criteria (SAC), and an adaptive security Definition of Done (DoD). A prototype tool is developed to demonstrate the feasibility of integrating these capabilities into a practical development setting. The proposed framework is evaluated through a mixed-method approach combining a controlled demonstration with expert evaluation and a survey. The results suggest that the framework may improve security visibility, reduce the knowledge gap between developers and security practices, and support integration with existing Agile workflows without substantially disrupting perceived development velocity. Overall, this research contributes an approach for achieving AI-assisted security integration in Scrum, helping to bridge the gap between Secure Scrum research and its application in real-world development environments. | |
| dc.format.extent | 166 | |
| dc.identifier.uri | https://www.utupub.fi/handle/11111/62156 | |
| dc.identifier.urn | URN:NBN:fi-fe2026061772740 | |
| dc.language.iso | eng | |
| dc.rights | fi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.| | |
| dc.rights.accessrights | avoin | |
| dc.subject | Security in Scrum | |
| dc.subject | Secure Agile Development | |
| dc.subject | Software Security | |
| dc.subject | Large Language Models (LLMs) | |
| dc.subject | Security-First Framework | |
| dc.subject | Agile Security Integration | |
| dc.subject | Security User Stories | |
| dc.subject | S-Tags | |
| dc.subject | AI-Assisted Software Engineering | |
| dc.title | Designing a Security-First Scrum Framework with AI Enhancements | |
| dc.type.ontasot | fi=Diplomityö|en=Master's thesis| |
Tiedostot
1 - 1 / 1
Ladataan...
- Name:
- Designing_a_Security_First_Scrum_Framework_with_AI_Enhancements.pdf
- Size:
- 1.82 MB
- Format:
- Adobe Portable Document Format