Building and Validating a Scale for Secure Software Development Self-Efficacy

Building and Validating a Scale for Secure Software Development Self-Efficacy
复制标题

DOI:
10.1145/3313831.3376754
复制
发表时间:
2020-04
期刊:
Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems
影响因子:
--
通讯作者:
Daniel Votipka;Desiree Abrokwa;Michelle L. Mazurek
Daniel Votipka;Desiree Abrokwa;Michelle L. Mazurek
中科院分区:
其他
文献类型:
--
作者:
Daniel Votipka;Desiree Abrokwa;Michelle L. Mazurek

文献摘要

相似文献

安全性是软件开发生命周期的重要组成部分。研究人员和实践者开发了旨在提高安全性的教育干预措施、指南、安全分析工具和新的API。然而,衡量由此带来的安全开发技能的任何改进都是具有挑战性的。作为技能的替代,我们建议测量自我效能感,这已经被证明在其他情况下与技能相关。在这里,我们提出了一个经过验证的测量安全软件开发自我效能的量表(SSD-SES)。我们首先回顾了流行的安全开发框架,并调查了22位安全开发专家,以确定58项独特的任务。接下来,我们分多轮询问了311名开发人员,让他们对每项任务的技能进行评分。我们反复更新我们的问题,以确保它们易于理解,在参与者之间显示出足够的差异,并证明了可靠性。我们最终的15项量表包含两个子量表,衡量人们对执行漏洞识别和缓解以及安全通信任务的能力的信心。
Security is an essential component of the software development lifecycle. Researchers and practitioners have developed educational interventions, guidelines, security analysis tools, and new APIs aimed at improving security. However, measuring any resulting improvement in secure development skill is challenging. As a proxy for skill, we propose to measure self-efficacy, which has been shown to correlate with skill in other contexts. Here, we present a validated scale measuring secure software-development self-efficacy (SSD-SES). We first reviewed popular secure-development frameworks and surveyed 22 secure-development experts to identify 58 unique tasks. Next, we asked 311 developers - over multiple rounds - to rate their skill at each task. We iteratively updated our questions to ensure they were easily understandable, showed adequate variance between participants, and demonstrated reliability. Our final 15-item scale contains two sub-scales measuring belief in ability to perform vulnerability identification and mitigation as well as security communications tasks.