...
首页> 外文期刊>Software >Interventions for long-term software security: Creating a lightweight program of assurance techniques for developers
【24h】

Interventions for long-term software security: Creating a lightweight program of assurance techniques for developers

机译:长期软件安全的干预措施:为开发人员创建轻量级的保证技术程序

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Though some software development teams are highly effective at delivering security, others either do not care or do not have access to security experts to teach them how. Unfortunately, these latter teams are still responsible for the security of the systems they build: systems that are ever more important to ever more people. We propose that a series of lightweight interventions, six hours of facilitated workshops delivered over three months, can improve a team's motivation to consider security and awareness of assurance techniques, changing its security culture even when no security experts are involved. The interventions were developed after an Appreciative Inquiry and Grounded Theory survey of security professionals to find out what approaches work best. We tested the interventions in a participatory action research field study where we delivered the workshops to three software development organizations and evaluated their effectiveness through interviews beforehand, immediately afterwards, and after twelve months. We found that the interventions can be effective with teams with limited or no security experience and that improvement is long-lasting. This approach and the learning points arising from the work here have the potential to be applied in many development teams, improving the security of software worldwide.
机译:尽管某些软件开发团队在提供安全性方面非常有效,但其他软件开发团队要么不在乎,要么没有安全专家来教他们如何做。不幸的是,这些后面的团队仍然对他们构建的系统的安全性负责:对于越来越多的人而言,这些系统变得越来越重要。我们建议进行一系列轻量级干预,在三个月内进行为时六个小时的研讨会,以提高团队考虑安全性和保证技术意识的动力,即使没有安全专家参与,也可以改变其安全文化。这些干预措施是在对安全专业人员进行的欣赏性调查和扎根理论调查之后开发出来的,以找出最有效的方法。我们在参与性行动研究现场研究中对干预措施进行了测试,在该研究中,我们向三个软件开发组织提供了研讨会,并通过事前,事后和十二个月后的访谈来评估其有效性。我们发现,对于只有很少或没有安全经验的团队来说,干预措施是有效的,并且改进是持久的。这种方法和从这里的工作中获得的学习要点有可能在许多开发团队中得到应用,从而提高了全球软件的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号