2022
DOI: 10.1007/s10664-022-10252-0
|View full text |Cite
|
Sign up to set email alerts
|

Incorporating software security: using developer workshops to engage product managers

Abstract: Evidence from data breach reports shows that many competent software development teams still do not implement secure, privacy-preserving software, even though techniques to do so are now well-known. A major factor causing this is simply a lack of priority and resources for security, as decided by product managers. So, how can we help developers and product managers to work together to achieve appropriate decisions on security and privacy issues? This paper explores using structured workshops to support teams o… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1

Citation Types

0
3
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
2
2
1

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(3 citation statements)
references
References 47 publications
0
3
0
Order By: Relevance
“…the authors in [30] explain that the primary reason why software development teams do not implement security is due to a lack of knowledge and experience in different types of vulnerabilities. This is supported by the authors in [31], who point out that datamany competent software development teams still do not implement secure, privacy-preserving software, even though techniques to do so are now well-known. The major cause of this is lack of priority and resources for security.…”
Section: Sources Of Software Quality and Security Issuesmentioning
confidence: 95%
“…the authors in [30] explain that the primary reason why software development teams do not implement security is due to a lack of knowledge and experience in different types of vulnerabilities. This is supported by the authors in [31], who point out that datamany competent software development teams still do not implement secure, privacy-preserving software, even though techniques to do so are now well-known. The major cause of this is lack of priority and resources for security.…”
Section: Sources Of Software Quality and Security Issuesmentioning
confidence: 95%
“…Security concerns are not implemented by software engineers as a continuous process in early software development; they are valued at the end of software development (Humayun et al, 2023;Nazir & Nazir, 2018). According to the research "Veracode, 2018," software developers aren't paying enough attention to security issues; therefore, all applications are vulnerable to threats (Weir et al, 2022). The majority of software engineers initially do not care about security concerns, Yet, the software engineers are gradually realizing that security for requirements engineering is essential for software development (Weir et al, 2021;Weir et al, 2022).…”
Section: Literature Reviewmentioning
confidence: 99%
“…According to the research "Veracode, 2018," software developers aren't paying enough attention to security issues; therefore, all applications are vulnerable to threats (Weir et al, 2022). The majority of software engineers initially do not care about security concerns, Yet, the software engineers are gradually realizing that security for requirements engineering is essential for software development (Weir et al, 2021;Weir et al, 2022). According to recent study, many software development procedures do not clearly contain methods for integrating software security from the early stages of software development (Khan & Khan, 2018b).…”
Section: Literature Reviewmentioning
confidence: 99%