Understanding developer security archetypes

dc.contributor.authorRyan, Ita
dc.contributor.authorRoedig, Utz
dc.contributor.authorStol, Klaas-Jan
dc.contributor.funderScience Foundation Irelanden
dc.date.accessioned2021-07-13T11:46:49Z
dc.date.available2021-07-13T11:46:49Z
dc.date.issued2021-06
dc.date.updated2021-07-13T11:33:46Z
dc.description.abstractAs software systems penetrate our everyday lives, security has risen to be a key concern. Despite decades of research leading to new tools and practices for writing secure code, achieving security as a key attribute remains highly challenging. We observe that much of the literature considers developers to be homogeneous and interchangeable. The differing circumstances of developers that might play a role in the writing of secure code have not been clearly defined. In this position paper we introduce the concept of developer security archetypes. Specifically, we suggest two key factors: developersâ personal interest in security, and the support that developers receive from their environment. Together, these two dimensions define four archetypes which can be uniquely characterized. By distinguishing developer archetypes, we seek to better understand how developers perceive security-related issues in systems development, as well as how to better support them.en
dc.description.sponsorshipScience Foundation Ireland (SFI Grant numbers 18/CRT/6222, 13/RC/2077_P2, 13/RC/2094_P2, and 15/SIRG/3293)en
dc.description.statusPeer revieweden
dc.description.versionAccepted Versionen
dc.format.mimetypeapplication/pdfen
dc.identifier.citationRyan, I., Roedig, U. and Stol, K. J. (2021) 'Understanding Developer Security Archetypes', 2021 IEEE/ACM 2nd International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS), Madrid, Spain, 3-4 June 2021, pp. 37-40. doi: 10.1109/EnCyCriS52570.2021.00013en
dc.identifier.doi10.1109/EnCyCriS52570.2021.00013en
dc.identifier.endpage40en
dc.identifier.isbn978-1-6654-4553-5
dc.identifier.startpage37en
dc.identifier.urihttps://hdl.handle.net/10468/11563
dc.language.isoenen
dc.publisherInstitute of Electrical and Electronics Engineers, IEEEen
dc.relation.ispartof2021 IEEE/ACM 2nd International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS)
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Research Centres/13/RC/2077/IE/CONNECT: The Centre for Future Networks & Communications/en
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Research Centres/13/RC/2094/IE/Lero - the Irish Software Research Centre/en
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Starting Investigator Research Grant (SIRG)/15/SIRG/3293/IE/Software Development with Alternative Workforces/en
dc.relation.urihttps://ieeexplore.ieee.org/document/9476058
dc.rightsFor the purpose of Open Access, the authors have applied a CC BY public copyright licence to this Author Accepted Manuscript; Copyright published version: © 2021, the Authors.en
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/en
dc.subjectDeveloper centred securityen
dc.subjectArchetypeen
dc.subjectDeveloper securityen
dc.subjectSoftware securityen
dc.subjectDeveloperen
dc.subjectTrainingen
dc.subjectSystematicsen
dc.subjectConferencesen
dc.subjectHuman factorsen
dc.subjectToolsen
dc.subjectWritingen
dc.subjectSoftware systemsen
dc.titleUnderstanding developer security archetypesen
dc.typeConference itemen
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Ryan.pdf
Size:
281.14 KB
Format:
Adobe Portable Document Format
Description:
Accepted version
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.71 KB
Format:
Item-specific license agreed upon to submission
Description: