2021 IEEE/ACM 2nd International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) 2021
DOI: 10.1109/encycris52570.2021.00013
|View full text |Cite
|
Sign up to set email alerts
|

Understanding Developer Security Archetypes

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
13
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
3
2

Relationship

1
4

Authors

Journals

citations
Cited by 5 publications
(13 citation statements)
references
References 20 publications
0
13
0
Order By: Relevance
“…Tahaei et al [34] examined the experience of privacy 'champions' in software teams, finding that they play an important advocacy role. Ryan et al [35] identified a 'hero' software security archetype; a coder struggling to introduce secure coding practices in a security-hostile environment. Such environments are difficult to study, since most security experts work in roles where security is already a focus [36].…”
Section: B Security Culturementioning
confidence: 99%
“…Tahaei et al [34] examined the experience of privacy 'champions' in software teams, finding that they play an important advocacy role. Ryan et al [35] identified a 'hero' software security archetype; a coder struggling to introduce secure coding practices in a security-hostile environment. Such environments are difficult to study, since most security experts work in roles where security is already a focus [36].…”
Section: B Security Culturementioning
confidence: 99%
“…The result is four archetypes: a) pragmatists, who are unmotivated but have resources, b) optimists, who are neither motivated nor have resources, c) champions, who are motivated and have resources, and d) heroes, who are motivated but do not have resources. Their position is that developers are not homogenous and need to have their differences represented [29]. Although the idea that developers are not homogenous is also considered valid in the present study, a key distinction between Ryan et al's work and the focus of this thesis is that Ryan et al focus on two-dimensional developer archetypes, while the focus of this thesis is the creation of a framework to guide the persona creation process.…”
Section: Security Focused Developer Characteristicsmentioning
confidence: 76%
“…There is limited research on the creation of personas for software developers from the lens of software security within the Developer Centered Security (DCS) literature, a field that studies Human-Computer Interaction methods in conjunction to software development and security [27,28]. Prior research either focuses on preconceived dimensions of software developers [20,29], or it focuses on developers who are already security conscious (security champions) [30] (see section 2.3). Additionally, there are numerous research contributions [31,32,33,34,35,36,37,38] that focus on (a) a particular aspect of software security, and (b) the developer characteristics that may result in that behaviour, such as developer security decision making [33,39], or security rationale [36].…”
Section: List Of Figuresmentioning
confidence: 99%
See 2 more Smart Citations