2019 IEEE/ACM 41st International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP) 2019
DOI: 10.1109/icse-seip.2019.00013
|View full text |Cite
|
Sign up to set email alerts
|

Interventions for Software Security: Creating a Lightweight Program of Assurance Techniques for Developers

Abstract: Summary Though some software development teams are highly effective at delivering security, others either do not care or do not have access to security experts to teach them how. Unfortunately, these latter teams are still responsible for the security of the systems they build: systems that are ever more important to ever more people. We propose that a series of lightweight interventions, six hours of facilitated workshops delivered over three months, can improve a team's motivation to consider security and aw… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
19
0

Year Published

2019
2019
2024
2024

Publication Types

Select...
5
2

Relationship

2
5

Authors

Journals

citations
Cited by 12 publications
(19 citation statements)
references
References 20 publications
0
19
0
Order By: Relevance
“…Such behaviours and attitudes are valuable in organisations that prioritise security [35]. Peer developers view Security Champions as essential players in software security [70,77,78]. They can be an experienced hacker who helps testers in fnding vulnerabilities [74], an intermediary between the security and development teams [25,70], or the leader in threat modelling activities [10,63].…”
Section: Related Workmentioning
confidence: 99%
“…Such behaviours and attitudes are valuable in organisations that prioritise security [35]. Peer developers view Security Champions as essential players in software security [70,77,78]. They can be an experienced hacker who helps testers in fnding vulnerabilities [74], an intermediary between the security and development teams [25,70], or the leader in threat modelling activities [10,63].…”
Section: Related Workmentioning
confidence: 99%
“…• Network Effect -Choosing solutions based on the number of their users. Group behavior is also observed in case of assurance mechanisms [30]- [32], [43], [54]…”
Section: Biasmentioning
confidence: 99%
“…• Organizational Goals -Software development methods rush for functionality. Developers need regular motivation and organization push [2]- [4], [28], [30], [33], [36], [40], [55]- [58] Take-away. The API providers are ideally placed to collaborate with developers and link the security benefits and pitfalls of how their APIs are used.…”
Section: Incentivesmentioning
confidence: 99%
See 1 more Smart Citation
“…This paper presents research into these questions: a survey of security professionals who work with software developers to address the first question and, based on the results, the subsequent creation and trials of a package, “Developer Security Essentials,” to address the second. It expands on an earlier paper by the authors, incorporating new longitudinal data from interviews one year after the intervention (Section 6.7), a comparison of the activities of different teams (Section 5.3), a more extensive literature survey (Section 2), and a discussion of “Blockers and Motivators” encountered by the different teams (Section 6.7).…”
Section: Introductionmentioning
confidence: 98%