Putting the Sec in DevSecOps: Using Social Practice Theory to Improve Secure Software Development

Putting the Sec in DevSecOps: Using Social Practice Theory to Improve Secure Software Development
复制标题

将 Sec 纳入 DevSecOps:利用社会实践理论改进安全软件开发

DOI:
10.1145/3442167.3442178
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Ashenden D
Ashenden D
中科院分区:
--
文献类型:
--
作者:
Ashenden D

文献摘要

参考文献

被引文献

相似文献

开源开发、敏捷、DevOps和DevSecOps等实践意味着网络安全专业人员需要找到将网络安全与软件开发实践相结合的方法。解决这个问题的一种方法是作为一个意识,教育和培训问题,许多组织都专注于在网络安全方面培训软件开发人员。然而,在本文中,我们通过研究软件开发人员的社会实践,更广泛地关注群体行为,而不是个人行为。不断变化的软件开发实践正在塑造软件开发人员的生活经验,我们认为,了解这些做法将使我们能够提高安全的软件开发。我们使用社会实践理论作为框架,为调整和融合网络安全和软件开发提出建议。为了实现这一目标,我们对软件开发实践的研究进行了快速回顾,并补充了来自10个关键线人访谈的数据,以确定我们在开发安全软件开发干预措施时需要考虑的问题。最后,我们概述了如何使用我们的研究来开发一个研讨会,这将有助于共同创建软件开发的安全实践。最后,我们对未来的研究提出了建议。
Practices such as open source development, agile, DevOps and DevSecOps mean that cyber security professionals need to find ways to blend cyber security with software development practices. One way of approaching this is as an awareness, education and training problem and many organisations are focusing on training software developers in cyber security. In this paper, however, we make the case for looking more broadly at group rather than individual behaviours, by examining the social practices of software developers. Changing software development practices are shaping the lived experience of software developers and we argue that understanding these practices will enable us to improve secure software development. We use social practice theory as a framework to develop recommendations for aligning and blending cyber security and software development. To achieve this, we carried out a rapid review of research on software development practices and supplemented this with data from ten key informant interviews to ascertain what we need to consider when developing an intervention for secure software development. Finally, we outline how our research could be used to develop a workshop that would facilitate the co-creation of security practices for software development. We conclude with suggestions for future research.
将安全目标与敏捷软件开发保持一致
DOI: --
发表时间: 2018
期刊: XP Companion
影响因子: --
作者:
Kalle Rindell;Sami Hyrynsalmi;Ville Leppänen
通讯作者: Ville Leppänen
敏捷环境下软件安全技能、使用和培训需求之间关系的实证研究
DOI: --
发表时间: 2016
期刊: ARES
影响因子: --
作者:
Tosin Daniel Oyetoyan;D. Cruzes;M. Jaatun
通讯作者: M. Jaatun
DOI: 10.1016/j.jss.2018.02.041
发表时间: 2017-07
期刊: ArXiv
影响因子: --
作者:
D. Graziotin;Fabian Fagerholm;Xiaofeng Wang;P. Abrahamsson
通讯作者: D. Graziotin;Fabian Fagerholm;Xiaofeng Wang;P. Abrahamsson
DOI: 10.1109/msp.2005.103
发表时间: 2005-07
期刊: IEEE Security & Privacy Magazine
影响因子: --
作者:
A. Apvrille;M. Pourzandi
通讯作者: A. Apvrille;M. Pourzandi
DOI: 10.21606/nordes.2005.061
发表时间: 2005
期刊: Nordes 2005: In the Making
影响因子: --
作者:
E. Shove
通讯作者: E. Shove