The Influence of Cybersecurity Practices on Project Management in Software Engineering
DOI:
https://doi.org/10.33387/ijeeic.v3i2.12635Keywords:
Cybersecurity Practices, Cybersecurity integration, Project management effectiveness, Risk management, SDLC security, Software engineering.Abstract
Cyber threats are becoming more common and complex, making cybersecurity an integral part of the software engineering project management process. Although this correlation is seen in my mind, there is very little empirical data that a connection between cybersecurity practices and project management performance exists. This research examines how the five cybersecurity principles of secure coding, threat modeling, encryption and authentication, penetration testing and continuous monitoring affect four project management principles – project timeline, project budget, project team collaboration and project risk management. The method used was mixed-methods, which involved surveys with 128 software engineering professionals and thematic analysis. The results show that project success is most closely related to risk management preparedness, followed by budgeting for cybersecurity and collaboration among team members. Projects that introduced cybersecurity early in the Software Development Lifecycle (SDLC) indicated that they had a 19% reduced perceived risk of delays, compared to those that integrated security later in the SDLC. Qualitative results also revealed that the main organizational barriers were too little training, budget limitation and delayed security integration. In general, the study demonstrates empirical evidence that cybersecurity needs to be thought of as a tactical organizational capability rather than simply a technical protection. The proposed findings provide practical recommendations to support the integration of cybersecurity in the SDLC to enhance the predictability, collaboration, risk management, and software engineering project performance.
Downloads
References
[1] M. T. Baldassarre, V. S. Barletta, D. Caivano, and M. Scalera, “Integrating security and privacy in software development,” Software Quality Journal, vol. 28, no. 3, pp. 987–1018, 2020, doi: 10.1007/s11219-020-09501-6.
[2] D. J. Ferreira, N. Mateus-Coelho, and H. S. Mamede, “Methodology for Predictive Cyber Security Risk Assessment (PCSRA),” Procedia Computer Science, vol. 219, pp. 1555–1563, 2023, doi: 10.1016/j.procs.2023.01.447.
[3] M. Harake, “Integrating Cybersecurity into Project Management: Best Practices, Emerging Trends, and Strategic Approaches,” 2025.
[4] V. Tynchenko et al., “Adaptive Management of Multi-Scenario Projects in Cybersecurity: Models and Algorithms for Decision-Making,” vol. 8, no. 11, Art. no. 150, 2024.
[5] M. S. Farooq, A. Hamid, A. Alvi, and U. Omer, “Blended Learning Models, Curricula, and Gamification in Project Management Education,” IEEE Access, vol. 10, pp. 60341–60361, 2022, doi: 10.1109/ACCESS.2022.3180355.
[6] M. J. Karamthulla, M. Muthusubramanian, A. Tadimarri, and R. Tillu, “Navigating the future: AI-driven project management in the digital era,” vol. 6, no. 2, pp. 1–11, 2024.
[7] H. M. Yahya and D. B. Taha, “Detection Bad Code Smells By Using Deep Machine Learning Approaches,” in 2023 1st International Conference on Advanced Engineering and Technologies (ICONNIC), 2023, pp. 281–286, doi: 10.1109/ICONNIC59854.2023.10467672.
[8] M. A. Akbar, A. A. Khan, N. Islam, and S. Mahmood, “DevOps project management success factors: A decision-making framework,” Software: Practice and Experience, vol. 54, no. 2, pp. 257–280, 2024, doi: 10.1002/spe.3269.
[9] P. Amajuoyi, L. B. Benjamin, and K. B. Adeusi, “Optimizing agile project management methodologies in high-tech software development,” GSC Advanced Research and Reviews, vol. 19, no. 2, pp. 268–274, 2024, doi: 10.30574/gscarr.2024.19.2.0182.
[10] National Institute of Standards and Technology, “Advanced Encryption Standard (AES),” U.S. Department of Commerce, 2023.
[11] G. McGraw, “Software security,” IEEE Security & Privacy, vol. 2, no. 2, pp. 80–83, 2004.
[12] M. Parveen and M. A. Shaik, “Review on penetration testing techniques in cyber security,” in 2023 Second International Conference on Augmented Intelligence and Sustainable Systems (ICAISS), 2023, pp. 1265–1270, IEEE.
[13] M. Howard and S. Lipner, The Security Development Lifecycle. Redmond, WA, USA: Microsoft Press, 2006.
[14] H. Tyagi and S. Watanabe, Information-Theoretic Cryptography. Cambridge, U.K.: Cambridge University Press, 2023.
[15] H. Singh and P. S. Williams, “A guide to the project management body of knowledge: PMBOK® Guide,” Project Management Institute, 2021, pp. 1–8.
[16] M. Stadnyk and A. Palamar, “Project management features in the cybersecurity area,” vol. 106, no. 2, pp. 54–62, 2022.
[17] H. van Zyl, “The ranking of dimensions for project-management efficiency in the public sector,” Journal of Economic and Financial Sciences, vol. 1, no. 1, pp. 39–50, 2007.
[18] C. Battistella, T. Bortolotti, S. Boscari, F. Nonino, and G. Palombi, “The impact of cultural dimensions on project management performance,” International Journal of Operations & Production Management, vol. 32, no. 1, pp. 108–130, 2024.
[19] “OWASP Secure Coding Practices Checklist and Training: Assessment of Effectiveness in a Technology Company.”
[20] R. Potturi, “Integrating Cybersecurity into Project Management: A Comprehensive Approach Across SDLC Phases,” ISACA, 2024.
[21] S. Kumar and G. Nagar, “Threat Modeling for Cyber Warfare Against Less Cyber-Dependent Adversaries,” in European Conference on Cyber Warfare and Security, vol. 23, no. 1, pp. 257–264, 2024.
[22] M. Humayun, N. Jhanjhi, M. F. Almufareh, and M. I. Khalil, “Security threat and vulnerability assessment and measurement in secure software development,” vol. 71, pp. 5039–5059, 2022.
Downloads
Published
How to Cite
Issue
Section
License
Authors who publish with this journal agree to the following terms:
- The copyright of the accepted for publication articles shall be assigned toInternational Journal of Electrical Engineering and Intelligent Computing (IJEEIC) as the publisher of the journal. The intended copyright includes the rights to publish articles in various forms (including reprints).
- International Journal of Electrical Engineering and Intelligent Computing (IJEEIC) maintain the publishing rights of the published articles.
- Authors are permitted to republish or disseminate published articles by sharing the link/DOI of the article at International Journal of Electrical Engineering and Intelligent Computing (IJEEIC). Authors are allowed to use their articles for any legal purposes deemed necessary without written permission from International Journal of Electrical Engineering and Intelligent Computing (IJEEIC) with an acknowledgment of initial publication to this journal.
International Journal of Electrical Engineering and Intelligent Computing (IJEEIC) by Universitas Khairun
This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.


