Security Thinking in Online Freelance Software Development

被引:3
|
作者
Rauf, Irum [1 ]
Petre, Marian [1 ]
Tun, Thein [1 ]
Lopez, Tamara [1 ]
Nuseibeh, Bashar [1 ,2 ]
机构
[1] Open Univ, Milton Keynes, England
[2] Lero, Limerick, Ireland
基金
英国工程与自然科学研究理事会;
关键词
freelance software development; payment for security; security; developer; software development in society; societal challenges of secure software development;
D O I
10.1109/ICSE-SEIS58686.2023.00008
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Online freelance software development (OFSD) is a significant part of the software industry and is a thriving online economy; a recent survey by Stack Overflow reported that nearly 15% of developers are independent contractors, freelancers, or self-employed. Although security is an important quality requirement for the social sustainability of software, existing studies have shown differences in the way security issues are handled by developers working in OFSD compared to those working in organisational environments. This paper investigates the security culture of OFSD developers, and identifies significant themes in how security is conceived, practiced, and compensated. Based on in-depth interviews with 20 freelance (FL) developers, we report that (a) security thinking is evident in descriptions of their work, (b) security thinking manifests in different ways within OFSD practice, and (c) the dynamics of the freelance development ecosystem influence financial investment in secure development. Our findings help to understand the reasons why insecure software development is evident in freelance development, and they contribute toward developing security interventions that are tailored to the needs of freelance software developers. General Summary- Online freelance software development (OFSD) is a significant part of the software industry and is a thriving online economy. Although security is an important quality requirement for the social sustainability of software, existing studies have shown differences in the way security issues are handled by developers working in OFSD compared to those working in organisational environments. Based on in-depth interviews with 20 freelance developers, this paper investigates the security culture of OFSD developers, and identifies significant themes in how security is conceived, practiced, and compensated.
引用
收藏
页码:13 / 24
页数:12
相关论文
共 50 条
  • [1] Predicting budget for Crowdsourced and Freelance Software development Projects
    Abhinav, Kumar
    Dubey, Alpana
    PROCEEDINGS OF THE 10TH INNOVATIONS IN SOFTWARE ENGINEERING CONFERENCE, 2017, : 165 - 171
  • [2] Development of a software security assessment instrument to reduce software security risk
    Gilliam, DP
    Kelly, JC
    Powell, JD
    Bishop, M
    PROCEEDINGS OF THE TENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, 2001, : 144 - 149
  • [3] Security requirements for software development
    Kim, TH
    Shin, MC
    Kim, SH
    Cha, JS
    KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT 3, PROCEEDINGS, 2004, 3215 : 116 - 122
  • [4] Security realities in software development
    Stackpole, William
    Computer Security Journal, 2002, 18 (01): : 9 - 14
  • [5] Security in the Software Development Lifecycle
    Assal, Hala
    Chiasson, Sonia
    PROCEEDINGS OF THE FOURTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY, 2018, : 281 - 296
  • [6] Security Responses in Software Development
    Lopez, Tamara
    Sharp, Helen
    Bandara, Arosha
    Tun, Thein
    Levine, Mark
    Nuseibeh, Bashar
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2023, 32 (03)
  • [7] Study and implementation of a software development pattern for online transient security early warning and protecting system
    State Key Lab. of Power Systems, Department of Electrical Engineering, Tsinghua University, Beijing 100084, China
    Dianli Xitong Zidonghue, 2007, 22 (6-10+35): : 6 - 10
  • [8] Security Assurance Model of Software Development for Global Software Development Vendors
    Khan, Rafiq Ahmad
    Khan, Siffat Ullah
    Alzahrani, Musaad
    Ilyas, Muhammad
    IEEE ACCESS, 2022, 10 : 58458 - 58487
  • [9] Economic Impact of Software Security Activities in Software Development
    Chehrazi, Golriz
    2013 INTERNATIONAL CONFERENCE ON RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS), 2013,
  • [10] Online ethnography: a study of software developers and software development
    Cordoba-Pachon, Jose Rodrigo
    Loureiro-Koechlin, Cecilia
    BALTIC JOURNAL OF MANAGEMENT, 2015, 10 (02) : 188 - 202