Awareness of cybersecurity topics, e.g., related to secure coding guidelines, enables software developers to write secure code. This awareness is vital in industrial environments for the products and services in critical infrastructures. In this work, we introduce and discuss a new serious game designed for software developers in the industry. This game addresses software developers' needs and is shown to be well suited for raising secure coding awareness of software developers in the industry. Our work results from the experience of the authors gained in conducting more than ten CyberSecurity Challenges in the industry. The presented game design, which is shown to be well accepted by software developers, is a novel alternative to traditional classroom training. We hope to make a positive impact in the industry by improving the cybersecurity of products at their early production stages.
翻译:对网络安全问题的认识,例如与安全编码准则有关的网络安全专题,使软件开发者能够编写安全编码。这种认识在关键基础设施产品和服务的工业环境中至关重要。在这项工作中,我们介绍和讨论为该行业软件开发者设计的新的严肃游戏。这个游戏满足软件开发者的需要,并证明非常适合提高该行业软件开发者的安全编码意识。我们的工作成果来自作者在工业中进行10多项网络安全挑战的经验。展示的游戏设计被软件开发者广泛接受,是传统课堂培训的一种新颖的替代方法。我们希望通过提高产品早期生产阶段的网络安全,对行业产生积极影响。