The state of secure coding practice: Small organisations and “lone, rogue coders”

dc.contributor.authorRyan, Itaen
dc.contributor.authorStol, Klaas-Janen
dc.contributor.authorRoedig, Utzen
dc.contributor.funderScience Foundation Irelanden
dc.date.accessioned2023-07-11T10:24:01Z
dc.date.available2023-07-11T10:24:01Z
dc.date.issued2023-05en
dc.description.abstractSoftware security is a rapidly developing problem. Malware, ransomware and spyware routinely leverage vulnerabilities in software to gain access to systems, escalate privileges and run adversarial code. One approach to solving this issue is to use secure software methods, which attempt to guide organisations in improving their software assurance. However, these methods implicitly assume the presence of substantial resources deployed in a compliance-mandated environment. The distinct and often limited environment in which small organisations, independent teams and lone coders operate is not considered. Advice for software security in small teams is almost absent from the literature, as is a way to measure the levels of secure coding in such teams. In order to address this problem, we must begin by understanding it. As part of the analysis of a large survey on current software security practice, we examined the current software security practices of small and open source organisations, and of lone and non-company developers. We present our results in this paper. We hope that they will facilitate the targeting of security advice to these neglected developer categories.en
dc.description.sponsorshipScience Foundation Ireland (13/RC/2077 P2; 13/RC/2094 P2)en
dc.description.statusPeer revieweden
dc.description.versionAccepted Versionen
dc.format.mimetypeapplication/pdfen
dc.identifier.citationRyan, I., Stol, K.-J. and Roedig, U. (2023) ‘The state of secure coding practice: small organisations and “lone, rogue coders”’, in 2023 IEEE/ACM 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS). Melbourne, Australia: IEEE, pp. 37–44. https://doi.org/10.1109/EnCyCriS59249.2023.00010en
dc.identifier.doi10.1109/EnCyCriS59249.2023.00010
dc.identifier.endpage30
dc.identifier.isbn979-8-3503-3815-7
dc.identifier.startpage23
dc.identifier.urihttps://hdl.handle.net/10468/14709
dc.language.isoenen
dc.publisherInstitute of Electrical and Electronics Engineers (IEEE)en
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Centres for Research Training Programme::Data and ICT Skills for the Future/18/CRT/6222/IE/SFI Centre for Research Training in Advanced Networks for Sustainable Societies/en
dc.relation.projectinfo:eu-repo/grantAgreement/SFI/SFI Starting Investigator Research Grant (SIRG)/15/SIRG/3293/IE/Software Development with Alternative Workforces/en
dc.relation.urihttps://doi.org/10.1109/EnCyCriS59249.2023.00010
dc.rights© 2023, the Authors. For the purpose of Open Access, the authors have applied a CC-BY public copyright licence to any Author Accepted Manuscript version arising from this submission. Copyright of Published VOR: © IEEEen
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/en
dc.subjectSoftware securityen
dc.subjectSecure development toolsen
dc.subjectSecure development processesen
dc.subjectSecure developmenten
dc.subjectSoftware programmeren
dc.subjectSoftware developeren
dc.subjectApplication securityen
dc.subjectSecurity issueen
dc.subjectSecure programmingen
dc.subjectSecure application developmenten
dc.subjectSecure development lifecycleen
dc.subjectMeasuring securityen
dc.titleThe state of secure coding practice: Small organisations and “lone, rogue coders”en
dc.typeConference itemen
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
ICSE_Workshop_23_Lone_Devs.pdf
Size:
223.42 KB
Format:
Adobe Portable Document Format
Description:
Accepted Version
License bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.71 KB
Format:
Item-specific license agreed upon to submission
Description: