FACTORS AFFECTING THE ADOPTION OF SECURE SOFTWARE PRACTICES IN SMALL AND MEDIUM ENTERPRISES THAT BUILD SOFTWARE IN-HOUSE

Wisdom Umeugo
{"title":"FACTORS AFFECTING THE ADOPTION OF SECURE SOFTWARE PRACTICES IN SMALL AND MEDIUM ENTERPRISES THAT BUILD SOFTWARE IN-HOUSE","authors":"Wisdom Umeugo","doi":"10.26483/ijarcs.v14i2.6955","DOIUrl":null,"url":null,"abstract":"Software has grown enormously in value because of its wide use for domestic, public, and economic activities. Software must be secure because exploited software vulnerabilities can negatively affect individuals’ and organizations' financial, health, and economic well-being. Various authors recommended practicing a secure software development lifecycle (SSDLC) to ensure that software is released secured. Software small and medium enterprises (SMEs), the dominant software publishers, have not widely adopted the SSDLC. This study approached the problem of software SMEs’ inadequate adoption of SSDLC from an innovation adoption perspective based on the diffusion of innovation theoretical framework (DOI). Five DOI factors, relative advantage, compatibility, complexity, trialability, and observability, were assessed for significance to software SMEs’ intention to adopt SSDLC. A random sample of 200 participants from a population of software security decision-makers of software SMEs based in the United States that develop software in-house were surveyed via an online close-ended questionnaire. Relative advantage, compatibility, and trialability were statistically significant to SME SSDLC adoption intention. Complexity and observability were not statistically significant to SME SSDLC adoption intention. Trialability was the strongest predictor of SME SSDLC adoption intention. SME software security decision-makers may find that the results of this study help to determine the factors they should consider when deciding to introduce the SSDLC into their software development process. The result of the study has implications for practice and social change because increased SME SSDLC adoption potentially results in the development of more secure software and fewer software security incidents.","PeriodicalId":287911,"journal":{"name":"International Journal of Advanced Research in Computer Science","volume":"26 4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Advanced Research in Computer Science","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.26483/ijarcs.v14i2.6955","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Software has grown enormously in value because of its wide use for domestic, public, and economic activities. Software must be secure because exploited software vulnerabilities can negatively affect individuals’ and organizations' financial, health, and economic well-being. Various authors recommended practicing a secure software development lifecycle (SSDLC) to ensure that software is released secured. Software small and medium enterprises (SMEs), the dominant software publishers, have not widely adopted the SSDLC. This study approached the problem of software SMEs’ inadequate adoption of SSDLC from an innovation adoption perspective based on the diffusion of innovation theoretical framework (DOI). Five DOI factors, relative advantage, compatibility, complexity, trialability, and observability, were assessed for significance to software SMEs’ intention to adopt SSDLC. A random sample of 200 participants from a population of software security decision-makers of software SMEs based in the United States that develop software in-house were surveyed via an online close-ended questionnaire. Relative advantage, compatibility, and trialability were statistically significant to SME SSDLC adoption intention. Complexity and observability were not statistically significant to SME SSDLC adoption intention. Trialability was the strongest predictor of SME SSDLC adoption intention. SME software security decision-makers may find that the results of this study help to determine the factors they should consider when deciding to introduce the SSDLC into their software development process. The result of the study has implications for practice and social change because increased SME SSDLC adoption potentially results in the development of more secure software and fewer software security incidents.
在内部构建软件的中小型企业中,影响采用安全软件实践的因素
由于在国内、公共和经济活动中的广泛应用,软件的价值已经大幅增长。软件必须是安全的,因为利用软件漏洞会对个人和组织的财务、健康和经济福利产生负面影响。许多作者建议实践安全的软件开发生命周期(SSDLC),以确保软件的发布是安全的。占主导地位的软件发行商中小型软件企业(SMEs)尚未广泛采用SSDLC。本研究基于创新理论框架(DOI)的扩散,从创新采用的角度探讨了软件中小企业不充分采用SSDLC的问题。本文评估了相对优势、兼容性、复杂性、可试性和可观察性这五个DOI因子对软件中小企业采用SSDLC意愿的显著性。通过在线封闭式问卷调查了来自美国软件中小企业内部开发软件的软件安全决策者的200个随机样本。相对优势、兼容性和可试性对中小企业SSDLC采用意愿有统计学意义。复杂性和可观察性对中小企业SSDLC采用意愿的影响无统计学意义。可试性是中小企业SSDLC采用意向的最强预测因子。中小企业软件安全决策者可能会发现,这项研究的结果有助于确定他们在决定将SSDLC引入其软件开发过程时应该考虑的因素。该研究的结果对实践和社会变革具有启示意义,因为越来越多的中小企业采用SSDLC可能导致开发更安全的软件和更少的软件安全事件。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信