Software security in practice: knowledge and motivation

被引:0
|
作者
Assal, Hala [1 ]
Morkonda, Srivathsan G. [2 ]
Arif, Muhammad Zaid [2 ]
Chiasson, Sonia [2 ]
机构
[1] Dept Syst & Comp Engn, 1125 Colonel By Dr, Ottawa, ON K1S 5B6, Canada
[2] Carleton Univ, Sch Comp Sci, 1125 Colonel Dr, Ottawa, ON K1S 5B6, Canada
来源
JOURNAL OF CYBERSECURITY | 2025年 / 11卷 / 01期
基金
加拿大自然科学与工程研究理事会;
关键词
usable security; software security; software developers; interview; security knowledge; security motivation; SELF-DETERMINATION THEORY; INTRINSIC MOTIVATION; WORK;
D O I
10.1093/cybsec/tyaf005
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
Developing secure software remains a challenge for developers despite the availability of security resources and secure development tools. Common factors affecting software security include the developer's security awareness and the rationales behind their development decisions with respect to security. In this work, we conducted interviews with software developers to examine how developers in organizations acquire security knowledge, and what factors motivate or prevent developers from adopting software security practices. Our analysis reveals that developers' security knowledge and motivations are intertwined aspects that are both important for promoting security in development teams. We identified a variety of learning opportunities used by developers and employers for increasing security awareness, including in-context learning activities preferred by developers. Based on our application of the self-determination theory, better security outcomes are expected when developers are internally driven toward security, rather than motivated by external factors; this aligns with our interpretation of participants' descriptions relating to security outcomes within their teams. Based on our analysis, we provide ideas on how to motivate developers to internalize security and improve their security practices.
引用
收藏
页数:22
相关论文
共 50 条
  • [41] An Empirical Study on Security Knowledge Sharing and Learning in Open Source Software Communities
    Wen, Shao-Fang
    COMPUTERS, 2018, 7 (04)
  • [42] Maintaining Requirements for Long-Living Software Systems by Incorporating Security Knowledge
    Gaertner, Stefan
    Ruhroth, Thomas
    Buerger, Jens
    Schneider, Kurt
    Juerjens, Jan
    2014 IEEE 22ND INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE), 2014, : 103 - 112
  • [43] An Exploratory Study of the Effects of Knowledge Sharing Methods on Cyber Security Practice
    Hiep Cong Pham
    Ulhaq, Irfan
    Minh Nhat Nguyen
    Nkhoma, Mathews
    AUSTRALASIAN JOURNAL OF INFORMATION SYSTEMS, 2021, 25 : 1 - 23
  • [44] Individual Benefit from Knowledge Sharing in Software Development Communities of Practice
    Nxumalo, Lindelani
    Mnkandla, Ernest
    2019 IEEE AFRICON, 2019,
  • [45] Globalising Security Culture and Knowledge in Practice: Nigeria's Hybrid Model
    Hills, Alice
    GLOBALIZATIONS, 2012, 9 (01) : 91 - 106
  • [46] Information Security Practice of Intelligent Knowledge Ecological Communities with Cloud Computing
    Ma, Yingjue
    Ni, Hui-jun
    Li, Yanping
    2021 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS AND COMPUTER ENGINEERING (ICCECE), 2021, : 242 - 245
  • [47] Towards a model to transfer knowledge from software engineering research to practice
    Cartaxo, Bruno
    Pinto, Gustavo
    Soares, Sergio
    INFORMATION AND SOFTWARE TECHNOLOGY, 2018, 97 : 80 - 82
  • [48] Factors Influencing Quality of Knowledge Shared in Software Development Community of Practice
    Buthelezi, Mokateko
    Mkhize, Peter
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON INTELLECTUAL CAPITAL, KNOWLEDGE MANAGEMENT AND ORGANISATIONAL LEARNING (ICICKM 2014), 2014, : 91 - 100
  • [49] Designing Practice Courses Based on Open Source Software For Information Security Students
    Tang Yi
    Zhou Quan
    NATIONAL TEACHING SEMINAR ON CRYPTOGRAPHY AND INFORMATION SECURITY (2010NTS-CIS), PROCEEDINGS, 2010, : 387 - 391
  • [50] Motivation and Knowledge Workers
    Mladkova, Ludmila
    Zouharova, Jarmila
    Novy, Jindrich
    11TH INTERNATIONAL STRATEGIC MANAGEMENT CONFERENCE, 2015, 207 : 768 - 776