Dancing, not Wrestling: Moving from Compliance to Concordance for Secure Software Development

Dancing, not Wrestling: Moving from Compliance to Concordance for Secure Software Development
复制标题

跳舞,而不是摔跤:安全软件开发从合规性转向一致性

DOI:
10.1145/3551349.3561145
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Ashenden D
Ashenden D
中科院分区:
--
文献类型:
--
作者:
Ashenden D

文献摘要

参考文献

被引文献

相似文献

近年来,安全软件开发已成为越来越重要的研究重点,尤其是因为人工智能、机器学习(AI/ML)、机器人学和自主系统(RAS)等技术的进步。AI/ML和RAS促进了自动化决策,并有能力对社会产生重大影响。因此,这种技术需要具有可信性,而安全的软件开发是可信性的关键属性。软件开发人员通常有责任和责任交付安全的代码,但对如何实现这一点的权力有限。权威往往掌握在网络安全专业人士手中,他们要求执行安全流程、工具和培训,但往往收效甚微。我们的研究目标是更好地了解如何弥合软件开发人员和网络安全从业人员之间的差距,以便平等分担权力、责任和问责。我们从医疗保健研究中获得灵感,这些研究着眼于合规、坚守和和谐之间的关系。我们以这项研究为视角,通过对35名专业软件开发人员的访谈来分析定性数据。我们的研究表明,如果软件开发人员和网络安全专业人员在互动中达到一致的程度,可能会导致就更现实的网络安全解决方案进行谈判,并消除软件开发人员实践中的摩擦,最终导致更安全、更值得信赖的系统。
Secure software development has become an increasingly important focus for research in recent years, not least because of advances in technology such as AI, machine learning (AI/ML), robotics, and autonomous systems (RAS). AI/ML and RAS facilitate automated decision-making and have the capability to have a significant impact on society. As such this technology needs to be trustworthy, and secure software development is a key attribute for trustworthiness. Software developers frequently have responsibility and accountability for delivering secure code but limited authority over how this is achieved. Authority tends to lie with cyber security professionals who mandate security processes, tools and training, often with limited success. Our research objective was to better understand how to bridge this gap between software developers and cyber security practitioners so that authority, responsibility and accountability are shared equally. We took inspiration from healthcare research that looks at the relationship between compliance, adherence and concordance. We use this research as a lens through which to analyse qualitative data from 35 interviews with professional software developers. Our research suggests that if software developers and cyber security professionals move to a point of concordance in their interactions it could lead to the negotiation of more realistic cyber security solutions, as well as removing friction from the practice of software developers and ultimately lead to more secure and trustworthy systems.
长期软件安全的干预措施:为开发人员创建轻量级的保证技术程序
DOI: 10.1002/spe.2774
发表时间: 2019
期刊: Software: Practice and Experience
影响因子: --
作者:
Charles Weir;Ingolf Becker;J. Noble;L. Blair;M. Sasse;A. Rashid
通讯作者: A. Rashid
机器人和自主系统——愿景、挑战和行动
DOI: --
发表时间: --
期刊:
影响因子: --
作者:
Jessica D. K. Love
通讯作者: Jessica D. K. Love
DOI: --
发表时间: 2021
期刊:
影响因子: --
作者:
Bernadette Rae
通讯作者: Bernadette Rae
一致性:一个广泛使用的术语,但它是什么意思呢?
DOI: --
发表时间: 2006
影响因子: --
作者:
A. Hobden
通讯作者: A. Hobden
信息过多:质疑后数字社会的安全性
DOI: 10.1145/3313831.3376214
发表时间: 2020
期刊: --
影响因子: --
作者:
Coles-Kemp L
通讯作者: Coles-Kemp L