Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Is Secure Coding Education in the Industry Needed?: An Investigation Through a Large Scale Survey
Siemens AG, DEU.
Univ Bundeswehr Munchen, DEU.
Inst Univ Lisboa ISCTE IUL, PRT.
Blekinge Tekniska Högskola, Fakulteten för datavetenskaper, Institutionen för programvaruteknik.ORCID-id: 0000-0003-0619-6027
2021 (engelsk)Inngår i: 2021 IEEE/ACM 43RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: JOINT TRACK ON SOFTWARE ENGINEERING EDUCATION AND TRAINING (ICSE-JSEET 2021), IEEE COMPUTER SOC , 2021, s. 241-252Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

The Department of Homeland Security in the United States estimates that 90% of software vulnerabilities can be traced back to defects in design and software coding. The financial impact of these vulnerabilities has been shown to exceed 380 million USD in industrial control systems alone. Since software developers write software, they also introduce these vulnerabilities into the source code. However, secure coding guidelines exist to prevent software developers from writing vulnerable code. This study focuses on the human factor, the software developer, and secure coding, in particular secure coding guidelines. We want to understand the software developersi awareness and compliance to secure coding guidelines and why, if at all, they arenit compliant or aware. We base our results on a large-scale survey on secure coding guidelines, with more than 190 industrial software developers. Our workis main contribution motivates the need to educate industrial software developers on secure coding guidelines, and it gives a list of fifteen actionable items to be used by practitioners in the industry. We also make our raw data openly available for further research.

sted, utgiver, år, opplag, sider
IEEE COMPUTER SOC , 2021. s. 241-252
Serie
Proceedings - International Conference on Software Engineering, ISSN 0270-5257, E-ISSN 1558-1225 ; 43
Emneord [en]
education; training; industry; secure coding guidelines; software developers; awareness; survey
HSV kategori
Identifikatorer
URN: urn:nbn:se:bth-22283DOI: 10.1109/ICSE-SEET52601.2021.00034ISI: 000704136000026ISBN: 978-0-7381-3320-1 (tryckt)OAI: oai:DiVA.org:bth-22283DiVA, id: diva2:1608824
Konferanse
43rd IEEE/ACM International Conference on Software Engineering - Joint Track on Software Engineering Education and Training (ICSE-JSEET) / IEEE/ACM 43rd International Conference on Software Engineering -Software Engineering in Society (ICSE-SEIS), Online, MAY 25-28, 2021
Merknad

open access

Tilgjengelig fra: 2021-11-04 Laget: 2021-11-04 Sist oppdatert: 2022-12-02bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Andre lenker

Forlagets fulltekstarXiv.org

Person

Mendez, Daniel

Søk i DiVA

Av forfatter/redaktør
Mendez, Daniel
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric

doi
isbn
urn-nbn
Totalt: 81 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf