A Cross-role and Bi-national Analysis on Security Efforts and Constraints of Software Development Projects

Fumihiro Kanei, A. Hasegawa, Eitaro Shioji, Mitsuaki Akiyama
{"title":"A Cross-role and Bi-national Analysis on Security Efforts and Constraints of Software Development Projects","authors":"Fumihiro Kanei, A. Hasegawa, Eitaro Shioji, Mitsuaki Akiyama","doi":"10.1145/3485832.3485922","DOIUrl":null,"url":null,"abstract":"Software security, which is often regarded as a non-functional requirement, tends to be less prioritized than other explicit requirements in development projects. For designing security measures that can be used in software development, we must understand the obstacles that prevent the adoption of secure software development practices. In this study, we quantitatively analyzed security efforts and constraints of software development projects through an online survey of software development professionals in the US and Japan (N=664). We revealed how certain characteristics of a development project, such as the project’s contractual relationships or the software’s target users, influence security efforts and constraints. In addition, by comparing the survey results of two groups (developers and managers), we revealed how the gap in their security efforts and constraints influences software security. We believe the results provide insights toward designing usable measures to assist security-related decision-making in software development and conducting appropriate surveys targeting software development professionals.","PeriodicalId":175869,"journal":{"name":"Annual Computer Security Applications Conference","volume":"26 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Annual Computer Security Applications Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3485832.3485922","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Software security, which is often regarded as a non-functional requirement, tends to be less prioritized than other explicit requirements in development projects. For designing security measures that can be used in software development, we must understand the obstacles that prevent the adoption of secure software development practices. In this study, we quantitatively analyzed security efforts and constraints of software development projects through an online survey of software development professionals in the US and Japan (N=664). We revealed how certain characteristics of a development project, such as the project’s contractual relationships or the software’s target users, influence security efforts and constraints. In addition, by comparing the survey results of two groups (developers and managers), we revealed how the gap in their security efforts and constraints influences software security. We believe the results provide insights toward designing usable measures to assist security-related decision-making in software development and conducting appropriate surveys targeting software development professionals.
软件开发项目安全工作与约束的跨角色、跨国家分析
软件安全性通常被视为非功能性需求,在开发项目中,它的优先级往往低于其他明确的需求。为了设计可以在软件开发中使用的安全措施,我们必须了解阻止采用安全软件开发实践的障碍。在这项研究中,我们通过对美国和日本的软件开发专业人员(N=664)的在线调查,定量地分析了软件开发项目的安全工作和约束。我们揭示了开发项目的某些特征,例如项目的合同关系或软件的目标用户,是如何影响安全工作和约束的。此外,通过比较两组(开发人员和管理人员)的调查结果,我们揭示了他们在安全工作和约束方面的差距如何影响软件安全性。我们相信这些结果为设计可用的方法提供了见解,以帮助软件开发中与安全相关的决策,并针对软件开发专业人员进行适当的调查。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信