2019 IEEE/ACM 12th International Workshop on Cooperative and Human Aspects of Software Engineering (CHASE) 2019
DOI: 10.1109/chase.2019.00023
|View full text |Cite
|
Sign up to set email alerts
|

"Hopefully We Are Mostly Secure": Views on Secure Code in Professional Practice

Abstract: Security of software systems is of general concern, yet breaches caused by common vulnerabilities still occur. Software developers are routinely called upon to "do more" to address this situation. However there has been little focus on the developers' point of view, and understanding how security features in their day-to-day activities. This paper reports preliminary findings of semi-structured interviews taken during an ethnographic study of professional software developers in one organization who are not sec… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
17
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
4
3

Relationship

2
5

Authors

Journals

citations
Cited by 18 publications
(18 citation statements)
references
References 28 publications
1
17
0
Order By: Relevance
“…Our interviews taken with engineers in office environments suggest that developers who are not in specialist cyber security teams often understand, in principle, how to counter common vulnerabilities, and have an awareness of the need to protect information for companies and for users of software [9]. But at the same time, and in agreement with other findings [11], these developers report that security is not at the forefront of their daily activity or decision making.…”
Section: Introductionsupporting
confidence: 80%
See 3 more Smart Citations
“…Our interviews taken with engineers in office environments suggest that developers who are not in specialist cyber security teams often understand, in principle, how to counter common vulnerabilities, and have an awareness of the need to protect information for companies and for users of software [9]. But at the same time, and in agreement with other findings [11], these developers report that security is not at the forefront of their daily activity or decision making.…”
Section: Introductionsupporting
confidence: 80%
“…The interactions and conversations we have observed within office settings [9] and comment streams on Stack Overflow [7], [8] suggest that secure coding practice is supported in both kinds of environment through personal networks of practice [14] that operate within larger environments. Online, in websites like Stack Overflow, such networks operate within the comment streams attached to question and answer posts.…”
Section: Network Of Practicementioning
confidence: 99%
See 2 more Smart Citations
“…Applicability. We intend to conduct a more comprehensive empirical study in order to evaluate relevance of the suggested revisions, and compare their acceptability by so ware developers, who may not always follow security practices [38]. In particular, OASIS assumes that the requirements can be expressed in LTL, which might not always be the case, especially for cases relating to complex data structures.…”
Section: Discussionmentioning
confidence: 99%