Awareness of secure coding guidelines in the industry - A first data analysis
2020 (English) In: Proceedings - 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2020 / [ed] Wang G.,Ko R.,Bhuiyan M.Z.A.,Pan Y., Institute of Electrical and Electronics Engineers Inc. , 2020, p. 345-352Conference paper, Published paper (Refereed)
Abstract [en]
Software needs to be secure, in particular, when deployed to critical infrastructures. Secure coding guidelines capture practices in industrial software engineering to ensure the security of code. This study aims to assess the level of awareness of secure coding in industrial software engineering, the skills of software developers to spot weaknesses in software code, avoid them, and the organizational support to adhere to coding guidelines. The approach draws on well-established theories of policy compliance, neutralization theory, and security-related stress and the authors' many years of experience in industrial software engineering and on lessons identified from training secure coding in the industry. The paper presents the questionnaire design for the online survey and the first analysis of data from the pilot study. © 2020 IEEE.
Place, publisher, year, edition, pages Institute of Electrical and Electronics Engineers Inc. , 2020. p. 345-352
Keywords [en]
Best Practices, Industry, Secure Coding, Security, Security Awareness, Software Development, Codes (symbols), Computation theory, Information analysis, Network security, Software engineering, Surveys, Analysis of data, Lessons identified, Online surveys, Organizational support, Policy compliance, Questionnaire design, Software codes, Software developer, Privacy by design
National Category
Software Engineering
Identifiers URN: urn:nbn:se:bth-21181 DOI: 10.1109/TrustCom50675.2020.00055 ISI: 000671077600041 Scopus ID: 2-s2.0-85101275922 ISBN: 9780738143804 (print) OAI: oai:DiVA.org:bth-21181 DiVA, id: diva2:1534398
Conference 19th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2020, Guangzhou, China, 29 December 2020 through 1 January 2021
Part of project SERT- Software Engineering ReThought, Knowledge Foundation 2021-03-052021-03-052021-09-03 Bibliographically approved