2023
DOI: 10.1145/3563211
|View full text |Cite
|
Sign up to set email alerts
|

Security Responses in Software Development

Abstract: The pressure on software developers to produce secure software has never been greater. But what does security look like in environments that don’t produce security-critical software? In answer to this question, this multi-sited ethnographic study characterises security episodes and identifies five typical behaviors in software development. Using theory drawn from information security and motivation research in software engineering, this paper characterizes key ways in which individual developers form security … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
12
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
3
2
1
1

Relationship

0
7

Authors

Journals

citations
Cited by 10 publications
(12 citation statements)
references
References 58 publications
0
12
0
Order By: Relevance
“…Software security is often made up of smaller, independent decisions, each with their own framing and outcome value. Typically, software engineers perceive security as a barrier (Lopez et al, 2022), or lower priority than functionality . Whilst this invokes a negative framing -producing risk aversion -maybe this does not directly translate into their mental model of the software.…”
Section: Risk Aversionmentioning
confidence: 99%
“…Software security is often made up of smaller, independent decisions, each with their own framing and outcome value. Typically, software engineers perceive security as a barrier (Lopez et al, 2022), or lower priority than functionality . Whilst this invokes a negative framing -producing risk aversion -maybe this does not directly translate into their mental model of the software.…”
Section: Risk Aversionmentioning
confidence: 99%
“…According to [136], secure software development practices should be followed during the development of WBAN devices and applications. This includes incorporating security considerations from the initial design phase, conducting security testing and code reviews, and ensuring timely software updates and patches to address vulnerabilities [137]- [138].…”
Section: Figure 4 Wban Security Mechanismsmentioning
confidence: 99%
“…Software security is often made up of smaller, independent decisions, each with their own framing and outcome value. Typically, software engineers perceive security as a barrier (Lopez et al, 2022), or lower priority than functionality , but this may not translate well into mental models of software, meaning that security is poorly considered in terms of risk aversion. It could also be interpreted that risk aversion is unrelated to risk taking behavior as there are other factors that determine the behavior.…”
Section: Risk Aversionmentioning
confidence: 99%