首页> 外文会议>IEEE/ACM International Workshop on Cooperative and Human Aspects of Software Engineering >'Hopefully We Are Mostly Secure': Views on Secure Code in Professional Practice
【24h】

'Hopefully We Are Mostly Secure': Views on Secure Code in Professional Practice

机译:“希望我们大多是安全的”:关于专业练习中安全守则的观点

获取原文

摘要

Security of software systems is of general concern, yet breaches caused by common vulnerabilities still occur. Software developers are routinely called upon to "do more" to address this situation. However there has been little focus on the developers' point of view, and understanding how security features in their day-to-day activities. This paper reports preliminary findings of semi-structured interviews taken during an ethnographic study of professional software developers in one organization who are not security experts. The overall study aims to understand how security features in day-to-day practice, while analysis of the interview data asks whether developers are responsible for security. The study reveals that awareness around security matters is raised through several paths including processes, standards, practices and company training and that a focus on security is driven by contextual factors. Security is taken care of with policies and through safeguards, and is handled differently depending on whether a team is developing new features, and hence "looking forward", or working with existing code and hence "looking back". Developers take and share responsibility for security in the code, but suggest that their responsibility has limits, and relies on collective practice.
机译:软件系统的安全性是一般关注的,但常见的漏洞仍然发生违规。软件开发人员经常要求“做更多”来解决这种情况。然而,在开发人员的角度上几乎没有焦点,并了解其日常活动中的安全功能如何。本文报告了在一个不是安全专家的一个组织中的专业软件开发人员的民族造型研究中采取了半结构化访谈的初步调查。整体研究旨在了解日常惯例中的安全功能,同时对面试数据的分析询问开发人员是否负责安全。该研究表明,通过包括流程,标准,实践和公司培训,以及对安全性的关注受到上下文因素,提出了关于安全事项的认识。安全性得到了策略和通过保护措施,并根据团队是否正在开发新功能,而“期待”,或使用现有代码并因此“回顾”并“回顾”,以不同的方式处理。开发人员在守则中占据安全性的责任,但建议他们的责任有限,并依赖于集体实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号