...
首页> 外文期刊>International journal of human-computer studies >Investigation of IS professionals' intention to practise secure development of applications
【24h】

Investigation of IS professionals' intention to practise secure development of applications

机译:调查信息系统专业人员实施安全开发应用程序的意图

获取原文
获取原文并翻译 | 示例

摘要

It is well known that software errors may lead to information security vulnerabilities, the breach of which can have considerable negative impacts for organizations. Studies have found that a large percentage of security defects in e-business applications are due to design-related flaws, which could be detected and corrected during applications development. Traditional methods of managing software application vulnerabilities have often been ad hoc and inadequate. A recent approach that promises to be more effective is to incorporate security requirements as part of the application development cycle. However, there is limited practice of secure development of applications (SDA) and lack of research investigating the phenomenon. Motivated by such concerns, the goal of this research is to investigate the factors that may influence the intention of information systems (IS) professionals to practise SDA, i.e., incorporate security as part of the application development lifecycle. This study develops two models based on the widely used theory of planned behaviour (TPB) and theory of reasoned action (TRA) to explain the phenomenon. Following model operationalization, a field survey of 184 IS professionals was conducted to empirically compare the explanatory power of the TPB-based model versus the TRA-based model. Consistent with TPB and TRA predictions, attitude and subjective norm were found to significantly impact intention to practise SDA for the overall survey sample. Attitude was in turn determined by product usefulness and career usefulness of SDA, while subjective norm was determined by interpersonal influence, but not by external influence. Contrary to TPB predictions, perceived behavioural controls, conceptualized in terms of self-efficacy and facilitating conditions, had no significant effect on intention to practise SDA. Thus, a modified TRA-based model was found to offer the best explanation of behavioural intention to practise SDA. Implications for research and information security practice are suggested. (c) 2006 Elsevier Ltd. All rights reserved.
机译:众所周知,软件错误可能会导致信息安全漏洞,违反这些漏洞可能对组织产生相当大的负面影响。研究发现,电子商务应用程序中的安全缺陷中有很大一部分是与设计相关的缺陷引起的,可以在应用程序开发过程中对其进行检测和纠正。管理软件应用程序漏洞的传统方法通常是临时的和不足的。一种有望提高效率的最新方法是将安全要求纳入应用程序开发周期的一部分。但是,应用程序安全开发(SDA)的实践很少,缺乏研究该现象的研究。出于这样的考虑,本研究的目的是调查可能影响信息系统(IS)专业人员实施SDA的意图的因素,即将安全性纳入应用程序开发生命周期的一部分。本研究基于广泛使用的计划行为理论(TPB)和理性行为理论(TRA)开发了两种模型来解释这一现象。在模型运行之后,对184名IS专业人员进行了实地调查,以实证比较基于TPB的模型与基于TRA的模型的解释力。与TPB和TRA的预测一致,态度和主观规范对整个调查样本实施SDA的意图产生重大影响。态度反过来取决于SDA的产品有用性和职业有用性,而主观规范则取决于人际交往而不是外部影响。与TPB的预测相反,根据自我效能和促进条件的概念来感知的行为控制对实践SDA的意图没有重大影响。因此,发现一种改进的基于TRA的模型可以为实践SDA的行为意图提供最佳解释。建议用于研究和信息安全实践。 (c)2006 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号