Awareness of cybersecurity topics facilitates software developers to produce secure code. This awareness is especially important in industrial environments for the products and services in critical infrastructures. In this work, we address how to raise awareness of software developers on the topic of secure coding. We propose the "CyberSecurity Challenges", a serious game designed to be used in an industrial environment and address software developers' needs. Our work distils the experience gained in conducting these CyberSecurity Challenges in an industrial setting. The main contributions are the design of the CyberSecurity Challenges events, the analysis of the perceived benefits, and practical advice for practitioners who wish to design or refine these games.
翻译:对网络安全议题的认识有助于软件开发者制作安全代码。这种认识在关键基础设施产品和服务的工业环境中尤其重要。在这项工作中,我们讨论了如何提高软件开发者对安全编码议题的认识。我们建议“网络安全挑战”是一个严肃的游戏,旨在用于工业环境中,满足软件开发者的需要。我们的工作总结了在工业环境中开展网络安全挑战过程中取得的经验。主要贡献是设计网络安全挑战事件,分析所察觉到的好处,以及向希望设计或改进这些游戏的从业人员提供实用建议。