Software needs to be secure, in particular, when deployed to critical infrastructures. Secure coding guidelines capture practices in industrial software engineering to ensure the security of code. This study aims to assess the level of awareness of secure coding in industrial software engineering, the skills of software developers to spot weaknesses in software code, avoid them, and the organizational support to adhere to coding guidelines. The approach draws on well-established theories of policy compliance, neutralization theory, and security-related stress and the authors' many years of experience in industrial software engineering and on lessons identified from training secure coding in the industry. The paper presents the questionnaire design for the online survey and the first analysis of data from the pilot study.
翻译:该研究旨在评估工业软件工程安全编码的认识水平、软件开发者发现软件编码弱点的技能、避免这些弱点的技能以及遵守编码准则的组织支助。该方法借鉴了既定的政策遵守理论、失效理论、与安全有关的压力、作者多年来在工业软件工程方面的经验,以及从工业安全编码培训中获得的经验教训。