DOI: 10.22215/etd/2018-13347
|View full text |Cite
|
Sign up to set email alerts
|

The Human Dimension of Software Security and Factors Affecting Security Processes

Abstract: Usable security for software developers is a research direction that is in its early stages. Even though developers typically have technical expertise, they are not necessarily security experts and need support when dealing with security. This thesis focuses on the human aspect of software security within the overall development process. The research employes mixed methods, including Cognitive Walkthrough studies, interviews, and an online survey study. We started by studying usability issues in code analysis … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
10
0

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 10 publications
(14 citation statements)
references
References 87 publications
0
10
0
Order By: Relevance
“…The outcome is the reduction in the risk of overlooking critical security requirements or introducing security flaws throughout the implementation process. To build and deploy a secure software system, there is need for the integration of security features into the life cycle of application development and align current SSE methods [186], [187]. However, most organizations view security as a post-development process, and hence security is not considered during the pre-development phase.…”
Section: Approaches To Software Quality and Securitymentioning
confidence: 99%
“…The outcome is the reduction in the risk of overlooking critical security requirements or introducing security flaws throughout the implementation process. To build and deploy a secure software system, there is need for the integration of security features into the life cycle of application development and align current SSE methods [186], [187]. However, most organizations view security as a post-development process, and hence security is not considered during the pre-development phase.…”
Section: Approaches To Software Quality and Securitymentioning
confidence: 99%
“…On the other hand, a strong correlation has been found in [34] between the financial records of the software development enterprises (such as sales and financial performance) and the number of vulnerabilities that their products may contain. As discussed in [35], organizations' security efforts are less effective when developers perceive a disinterest in adopting software security practices. This usually occurs when there are no perceived negative consequences to the customers or the business from the lack of security in the SDLC.…”
Section: Sources Of Software Quality and Security Issuesmentioning
confidence: 99%
“…Several studies have pointed out the need to investigate the behavioral aspects of security adoption. In particular, developers' motivations and attitudes towards security [49], [50], [58], [35] is a hot topic. However, despite the availability of these many resources, developers continue to introduce security vulnerabilities in source code, and organizations lack proper guidelines for designing strategies to mitigate poor security.…”
Section: Sources Of Software Quality and Security Issuesmentioning
confidence: 99%
See 1 more Smart Citation
“…However, cybersecurity is often not seen as an 'essential design principle' (Schwartz et al, 2018), and research suggests that cybersecurity awareness across the design process is inconsistent (Kim et al, 2018). Efforts to incorporate cybersecurity in the design process have focused on software (Assal, 2018;Lukowiak et al, 2014), but less attention has been paid to early-stage conceptual design, and specifically, human-centered design (HCD). HCD, often described with phases of Research, Analyze, Ideate, Build, and Communicate (Roschuni et al, 2011), intends to help designers tackle complex problems, including cybersecurity.…”
Section: Introductionmentioning
confidence: 99%