@MASTERSTHESIS{ 2019:1655342064, title = {Misuser stories : an extended agile framework for handling security requirements in agile software development}, year = {2019}, url = "http://tede2.pucrs.br/tede2/handle/tede/9014", abstract = "Agile teams are multidisciplinary and focus on delivering working and verifiable software within predefined periods in a continuous way. In order to satisfy users? expectations, the agile team has to deal with functional and non functional requirements. The functional requirements are directly linked to the business rules, being more noticeable than the nonfunctional ones, which may be subtle and might require a wider range of knowledge. Thus, in many situations, security requirements are classified as non-functional requirements. These can derive from a variety of sources, requiring expertise beyond business or even development techniques. Therefore, there are some critics about the way agile deals with nonfunctional requirements specially the security ones. This research aimed to put together agile software development and information security areas, by proposing a set of practices to cope with security requirements in agile development teams. The main contribution of the present work is introducing a new artifact named misuser story, composed of related rules and recommended practices. That new artifact intends to define an extended agile framework for promoting the consideration on security requirements, making these requirements more explicit.", publisher = {Pontif?cia Universidade Cat?lica do Rio Grande do Sul}, scholl = {Programa de P?s-Gradua??o em Ci?ncia da Computa??o}, note = {Escola Polit?cnica} }