{"title":"程序员信息安全意识对安全应用程序脆弱性评估结果的影响","authors":"Hermawan Effendi, S. Sumpeno, A. Affandi","doi":"10.1109/ICITE54466.2022.9759867","DOIUrl":null,"url":null,"abstract":"The existence of application innovation is important for the operations of an organization. Information security is currently a challenge in building secure applications because hacking often occurs in critical or transactional information applications, such as the financial sector. In addition to applying good programming techniques, application programmers must have information security awareness to produce secure applications. Application security vulnerabilities are caused by programmers' lack of information security awareness. In this study, the measurement of programmer information awareness is juxtaposed with testing application security vulnerabilities. Measuring the level of information security awareness using knowledge, attitude, and behavior modeling with Manage Security Services indicators on COBIT 5 as the focus area and testing application security vulnerabilities using OWASP-ZAP according to OWASP TOP 10 best practices. Data processing using Structural Equation Modeling-Partial Least Square can provide information about the effect of programmer information security awareness on application security vulnerabilities. The information becomes input in improving the competence of programmers in the field of information security. As a result of the research, some findings and discussions are given at the end of this article to achieve secure application programming through increasing awareness of information security.","PeriodicalId":123775,"journal":{"name":"2022 2nd International Conference on Information Technology and Education (ICIT&E)","volume":"27 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-01-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"The Effect of Programmer Information Security Awareness on the Results of Vulnerability Assessments in Achieving Secure Applications\",\"authors\":\"Hermawan Effendi, S. Sumpeno, A. Affandi\",\"doi\":\"10.1109/ICITE54466.2022.9759867\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The existence of application innovation is important for the operations of an organization. Information security is currently a challenge in building secure applications because hacking often occurs in critical or transactional information applications, such as the financial sector. In addition to applying good programming techniques, application programmers must have information security awareness to produce secure applications. Application security vulnerabilities are caused by programmers' lack of information security awareness. In this study, the measurement of programmer information awareness is juxtaposed with testing application security vulnerabilities. Measuring the level of information security awareness using knowledge, attitude, and behavior modeling with Manage Security Services indicators on COBIT 5 as the focus area and testing application security vulnerabilities using OWASP-ZAP according to OWASP TOP 10 best practices. Data processing using Structural Equation Modeling-Partial Least Square can provide information about the effect of programmer information security awareness on application security vulnerabilities. The information becomes input in improving the competence of programmers in the field of information security. As a result of the research, some findings and discussions are given at the end of this article to achieve secure application programming through increasing awareness of information security.\",\"PeriodicalId\":123775,\"journal\":{\"name\":\"2022 2nd International Conference on Information Technology and Education (ICIT&E)\",\"volume\":\"27 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-01-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 2nd International Conference on Information Technology and Education (ICIT&E)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICITE54466.2022.9759867\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 2nd International Conference on Information Technology and Education (ICIT&E)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICITE54466.2022.9759867","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
摘要
应用创新的存在对组织的运作至关重要。信息安全目前是构建安全应用程序的一个挑战,因为黑客攻击经常发生在关键或事务性信息应用程序中,例如金融部门。除了应用良好的编程技术外,应用程序程序员还必须具有信息安全意识,以生成安全的应用程序。应用安全漏洞是程序员缺乏信息安全意识造成的。在本研究中,程序员信息意识的测量与测试应用程序安全漏洞并置。使用知识、态度和行为建模来度量信息安全意识的水平,并将COBIT 5上的管理安全服务指示器作为重点区域,并根据OWASP TOP 10最佳实践使用OWASP- zap测试应用程序安全漏洞。使用结构方程建模-偏最小二乘的数据处理方法可以提供程序员信息安全意识对应用程序安全漏洞影响的信息。这些信息成为提高程序员在信息安全领域能力的输入。通过研究,本文最后给出了一些结论和讨论,以通过提高信息安全意识来实现安全的应用程序编程。
The Effect of Programmer Information Security Awareness on the Results of Vulnerability Assessments in Achieving Secure Applications
The existence of application innovation is important for the operations of an organization. Information security is currently a challenge in building secure applications because hacking often occurs in critical or transactional information applications, such as the financial sector. In addition to applying good programming techniques, application programmers must have information security awareness to produce secure applications. Application security vulnerabilities are caused by programmers' lack of information security awareness. In this study, the measurement of programmer information awareness is juxtaposed with testing application security vulnerabilities. Measuring the level of information security awareness using knowledge, attitude, and behavior modeling with Manage Security Services indicators on COBIT 5 as the focus area and testing application security vulnerabilities using OWASP-ZAP according to OWASP TOP 10 best practices. Data processing using Structural Equation Modeling-Partial Least Square can provide information about the effect of programmer information security awareness on application security vulnerabilities. The information becomes input in improving the competence of programmers in the field of information security. As a result of the research, some findings and discussions are given at the end of this article to achieve secure application programming through increasing awareness of information security.