Building and Validating a Scale for Secure Software Development Self-Efficacy

Explainable AI (XAI)User Research Methods (Interviews, Surveys, Observation)Computational Methods in HCISoftware Engineers & DevelopersCybersecurity EngineersAI/ML Researchers & Engineers

Security is an essential component of the software development lifecycle. Researchers and practitioners have developed educational interventions, guidelines, security analysis tools, and new APIs aimed at improving security. However, measuring any resulting improvement in secure development skill is challenging. As a proxy for skill, we propose to measure self-efficacy, which has been shown to correlate with skill in other contexts. Here, we present a validated scale measuring secure software-development self-efficacy (SSD-SES). We first reviewed popular secure-development frameworks and surveyed 22 secure-development experts to identify 58 unique tasks. Next, we asked 311 developers — over multiple rounds — to rate their skill at each task. We iteratively updated our questions to ensure they were easily understandable, showed adequate variance between participants, and demonstrated reliability. Our final 15-item scale contains two sub-scales measuring belief in ability to perform vulnerability identification and mitigation as well as security communications tasks.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/31765/2020

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3313831.3376754
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2020
emoji_events
Award
No award tagged
group
Authors
3 authors
sell
Subtopics
Explainable AI (XAI), User Research Methods (Interviews, Surveys, Observation), Computational Methods in HCI
work
Professions
Software Engineers & Developers, Cybersecurity Engineers, AI/ML Researchers & Engineers
article
Content Status
Abstract only
hub
Related Papers
1 related papers