Designing a Security-First Scrum Framework with AI Enhancements

dc.contributor.authorAsad, Arslaan
dc.contributor.departmentfi=Tietotekniikan laitos|en=Department of Computing|
dc.contributor.facultyfi=Teknillinen tiedekunta|en=Faculty of Technology|
dc.contributor.studysubjectfi=Tietotekniikka|en=Information and Communication Technology|
dc.date.accessioned2026-06-17T19:31:29Z
dc.date.issued2026-06-05
dc.description.abstractThis thesis addresses the challenge of integrating software security into Scrum-based Agile development, where security activities are often neglected or treated as separate from the development process. Despite extensive research on securing Scrum, many existing approaches remain impractical for real-world adoption due to their complexity or reliance on specialised expertise. To address this gap, this study proposes an LLM-Supported Secure Scrum (LSS) framework that embeds security practices directly into Scrum artefacts, thereby ensuring continuous visibility and prioritisation of security early in the development lifecycle. The framework design is grounded in a structured literature review with thematic synthesis, which identifies security practices suitable for Agile environments. In addition, the framework incorporates Large Language Models (LLMs) as an enabling mechanism to operationalise and support these practices within development workflows. Specifically, in this thesis, LLMs are used to assist key security activities, including risk identification, S-Tag generation, misuse and abuser stories, security acceptance criteria (SAC), and an adaptive security Definition of Done (DoD). A prototype tool is developed to demonstrate the feasibility of integrating these capabilities into a practical development setting. The proposed framework is evaluated through a mixed-method approach combining a controlled demonstration with expert evaluation and a survey. The results suggest that the framework may improve security visibility, reduce the knowledge gap between developers and security practices, and support integration with existing Agile workflows without substantially disrupting perceived development velocity. Overall, this research contributes an approach for achieving AI-assisted security integration in Scrum, helping to bridge the gap between Secure Scrum research and its application in real-world development environments.
dc.format.extent166
dc.identifier.urihttps://www.utupub.fi/handle/11111/62156
dc.identifier.urnURN:NBN:fi-fe2026061772740
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightsavoin
dc.subjectSecurity in Scrum
dc.subjectSecure Agile Development
dc.subjectSoftware Security
dc.subjectLarge Language Models (LLMs)
dc.subjectSecurity-First Framework
dc.subjectAgile Security Integration
dc.subjectSecurity User Stories
dc.subjectS-Tags
dc.subjectAI-Assisted Software Engineering
dc.titleDesigning a Security-First Scrum Framework with AI Enhancements
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Designing_a_Security_First_Scrum_Framework_with_AI_Enhancements.pdf
Size:
1.82 MB
Format:
Adobe Portable Document Format