Interventions for long‐term software security: Creating a lightweight program of assurance techniques for developers

Interventions for long‐term software security: Creating a lightweight program of assurance techniques for developers
复制标题

长期软件安全的干预措施:为开发人员创建轻量级的保证技术程序

DOI:
10.1002/spe.2774
复制
发表时间:
2019
期刊:
Software: Practice and Experience
影响因子:
--
通讯作者:
A. Rashid
A. Rashid
中科院分区:
--
文献类型:
--
作者:
Charles Weir;Ingolf Becker;J. Noble;L. Blair;M. Sasse;A. Rashid

文献摘要

参考文献

被引文献

相似文献

虽然一些软件开发团队在提供安全性方面非常有效,但其他团队要么不关心,要么无法访问安全专家来教他们如何做到这一点。不幸的是,这些团队仍然对他们构建的系统的安全负责:这些系统对越来越多的人来说变得越来越重要。我们建议,一系列轻量级的干预措施,六个小时的促进研讨会在三个月内交付,可以提高一个团队的动机,考虑安全和保证技术的意识,改变其安全文化,即使没有安全专家参与。这些干预措施是在对安全专业人员进行欣赏性调查和扎根理论调查后制定的,以找出最有效的方法。我们在一个参与性的行动研究领域的研究,我们提供了研讨会,三个软件开发组织和评估其有效性,通过访谈之前,之后立即,和12个月后的干预措施进行测试。我们发现,对于安全经验有限或没有安全经验的团队来说,干预措施是有效的,而且这种改善是持久的。这种方法和从这里的工作中产生的学习点有可能应用于许多开发团队,提高全球软件的安全性。
Though some software development teams are highly effective at delivering security, others either do not care or do not have access to security experts to teach them how. Unfortunately, these latter teams are still responsible for the security of the systems they build: systems that are ever more important to ever more people. We propose that a series of lightweight interventions, six hours of facilitated workshops delivered over three months, can improve a team's motivation to consider security and awareness of assurance techniques, changing its security culture even when no security experts are involved. The interventions were developed after an Appreciative Inquiry and Grounded Theory survey of security professionals to find out what approaches work best. We tested the interventions in a participatory action research field study where we delivered the workshops to three software development organizations and evaluated their effectiveness through interviews beforehand, immediately afterwards, and after twelve months. We found that the interventions can be effective with teams with limited or no security experience and that improvement is long‐lasting. This approach and the learning points arising from the work here have the potential to be applied in many development teams, improving the security of software worldwide.
好、坏、丑:网络物理系统博弈中安全决策的研究
DOI: 10.1109/tse.2017.2782813
发表时间: 2019
影响因子: 7.4
作者:
Frey S
通讯作者: Frey S
安全对话:在安全与业务之间建立更好的关系
DOI: 10.1109/msp.2016.57
发表时间: 2016
影响因子: 1.9
作者:
Ashenden D
通讯作者: Ashenden D