Understanding Developer Security Archetypes

Research output: Chapter in Book/Report/Conference proceedingsChapterpeer-review

Abstract

As software systems penetrate our everyday lives, security has risen to be a key concern. Despite decades of research leading to new tools and practices for writing secure code, achieving security as a key attribute remains highly challenging. We observe that much of the literature considers developers to be homogeneous and interchangeable. The differing circumstances of developers that might play a role in the writing of secure code have not been clearly defined. In this position paper we introduce the concept of developer security archetypes. Specifically, we suggest two key factors: developers' personal interest in security, and the support that developers receive from their environment. Together, these two dimensions define four archetypes which can be uniquely characterized. By distinguishing developer archetypes, we seek to better understand how developers perceive security-related issues in systems development, as well as how to better support them.

Original languageEnglish
Title of host publicationProceedings - 2021 IEEE/ACM 2nd International Workshop on Engineering and Cybersecurity of Critical Systems, EnCyCriS 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages37-40
Number of pages4
ISBN (Electronic)9781665445535
DOIs
Publication statusPublished - Jun 2021
Event2nd IEEE/ACM International Workshop on Engineering and Cybersecurity of Critical Systems, EnCyCriS 2021 - Virtual, Online
Duration: 3 Jun 20214 Jun 2021

Publication series

NameProceedings - 2021 IEEE/ACM 2nd International Workshop on Engineering and Cybersecurity of Critical Systems, EnCyCriS 2021

Conference

Conference2nd IEEE/ACM International Workshop on Engineering and Cybersecurity of Critical Systems, EnCyCriS 2021
CityVirtual, Online
Period3/06/214/06/21

Keywords

  • archetype
  • developer
  • developer centred security
  • developer security
  • software security

Fingerprint

Dive into the research topics of 'Understanding Developer Security Archetypes'. Together they form a unique fingerprint.

Cite this