Utilize este identificador para referenciar este registo: http://hdl.handle.net/10071/25497
Autoria: Gasiba, T. E.
Lechner, U.
Albuquerque, M. P.
Mendez, D.
Data: 2021
Título próprio: Is secure coding education in the industry needed? An investigation through a large scale survey
Paginação: 241 - 252
Título do evento: 43rd IEEE/ACM International Conference on Software Engineering: Joint Track on Software Engineering Education and Training, ICSE-JSEET 2021
ISBN: 978-1-6654-0138-8
DOI (Digital Object Identifier): 10.1109/ICSE-SEET52601.2021.00034
Palavras-chave: Education
Training
Industry
Secure coding guidelines
Software developers
Awareness
Survey
Resumo: The Department of Homeland Security in the United States estimates that 90% of software vulnerabilities can be traced back to defects in design and software coding. The financial impact of these vulnerabilities has been shown to exceed 380 million USD in industrial control systems alone. Since software developers write software, they also introduce these vulnerabilities into the source code. However, secure coding guidelines exist to prevent software developers from writing vulnerable code. This study focuses on the human factor, the software developer, and secure coding, in particular secure coding guidelines. We want to understand the software developers' awareness and compliance to secure coding guidelines and why, if at all, they aren't compliant or aware. We base our results on a large-scale survey on secure coding guidelines, with more than 190 industrial software developers. Our work's main contribution motivates the need to educate industrial software developers on secure coding guidelines, and it gives a list of fifteen actionable items to be used by practitioners in the industry. We also make our raw data openly available for further research.
Arbitragem científica: yes
Acesso: Acesso Aberto
Aparece nas coleções:ISTAR-CRI - Comunicações a conferências internacionais

Ficheiros deste registo:
Ficheiro Descrição TamanhoFormato 
conferenceobject_79828.pdfVersão Aceite416,53 kBAdobe PDFVer/Abrir


FacebookTwitterDeliciousLinkedInDiggGoogle BookmarksMySpaceOrkut
Formato BibTex mendeley Endnote Logotipo do DeGóis Logotipo do Orcid 

Todos os registos no repositório estão protegidos por leis de copyright, com todos os direitos reservados.