Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese Industries
Authors
Title of the Paper
Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese Industries
Bibliographic Information
- Subject Area: Security in Software Development, Human Factors in Software Engineering
- Keywords: Software security, public guidelines, in-house guidelines, secure programming, HCI development, survey
Research Background and Issues
-
Identified Problems or Challenges:
- Existing research primarily focuses on the use of public secure development guidelines, with limited attention to in-house secure development guidelines constructed by enterprises.
- There is a lack of validation for recommended practices in implementing secure development guidelines within industrial settings.
- Most studies focus on single-country investigations (e.g., the U.S.), with few comparative studies, especially considering differences in development models and cultural factors (e.g., Japan's more prevalent outsourcing development model).
-
Significance: As software-related cyberattacks become increasingly frequent, improving developers' adherence to secure development guidelines is critical for enhancing software security. The combined use of public and in-house guidelines remains unclear, and comprehensive analysis of regional and cultural differences is lacking.
-
Research Motivation: This study aims to understand the practical application of public and in-house secure development guidelines in software development through industry surveys, as well as the impact of project characteristics and national development cultures on their implementation.
Solution
-
Proposed Methods/Solutions:
- Collect quantitative and qualitative data from 870 software development professionals in the U.S. and Japan through an online survey (396 participants from the U.S., 474 from Japan).
- Focus on analyzing:
- Frequency and reasons for using public and in-house secure development guidelines.
- Feasibility of recommended practices for implementing secure development guidelines proposed in existing research.
- Differences in guideline usage between Japanese and U.S. developers.
-
Innovations:
- Conducting the first systematic study on the combined use of public and in-house secure development guidelines and their functional differences.
- Comparing the practical application of guidelines across different countries and development environments, revealing the influence of culture, project scale, and organizational structure on guideline implementation.
-
Implementation Steps and Techniques:
- Survey Design: Develop questions based on literature review and interviews, covering guideline types, usage, usability, and the operability of recommended practices.
- Data Collection: Conduct online surveys targeting developers and managers in the U.S. and Japan, ensuring a diverse participant pool.
- Data Analysis:
- Perform quantitative analysis using SPSS (e.g., regression analysis, chi-square tests).
- Conduct thematic analysis of qualitative responses to open-ended questions to identify patterns.
Research Findings
-
Specific Findings:
- In-house guidelines are widely adopted in industrial settings (usage rate: 87.1% in the U.S., 85.9% in Japan).
- In-house guidelines are more frequently mandated by companies compared to public guidelines (especially in the U.S.).
- Participants who use both public and in-house guidelines tend to perceive higher usability of the guidelines.
-
Experimental or Evaluation Results:
- Participants from small-scale projects (e.g., teams with fewer than five members) and outsourced development projects find it more challenging to implement recommended practices for secure development guidelines.
- Companies with a CSO (Chief Security Officer) or CISO (Chief Information Security Officer) are more likely to implement recommended practices effectively.
- Japanese participants tend to evaluate secure development guidelines more conservatively, while novice developers in the U.S. are more optimistic.
-
Advantages:
- Comprehensive data provides detailed comparisons of the practical application of public and in-house secure development guidelines.
- The findings have practical implications for improving the operability of secure development guidelines in the industry.
-
Limitations and Future Directions:
- Limitations:
- The survey does not analyze the specific content of public guidelines in detail, focusing instead on guideline types and general characteristics.
- Social desirability bias may exist in the data (e.g., participants may tend to report positive outcomes).
- Future Directions:
- Use qualitative methods such as interviews to explore the development and usage processes of in-house guidelines in detail.
- Investigate lightweight and easy-to-implement guideline strategies to accommodate resource-constrained development environments.
- Compare the potential impact of development cultures on guideline operability across more countries and regions.
- Limitations:
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How are public and enterprise-developed secure development guidelines actually applied in software development?Category: Coding Assistants and Multi-Turn Code SupportSimilar questionsarrow_forward
- What cultural and project differences exist between US and Japanese developers in using secure development guidelines?Category: Coding Assistants and Multi-Turn Code SupportSimilar questionsarrow_forward
- Are recommended secure development guideline practices feasible across different enterprise environments?Category: Coding Assistants and Multi-Turn Code SupportSimilar questionsarrow_forward
Practical Problems
1- Developers struggle to efficiently adopt secure development guidelines to address increasingly serious cyberattacks.Category: Coding Assistants and Multi-Turn Code SupportSimilar questionsarrow_forward
- 67%
Security Fictions: Bridging Speculative Design and Computer Security
DIS '20· Explainable AI (XAI) +3
- 60%
Passquerade: Improving Error Correction of Text Passwords on Mobile Devices by using Graphic Filters for Password Masking
CHI '19· Privacy by Design & User Control +1
- 60%
Security Managers Are Not The Enemy Either
CHI '19· Privacy by Design & User Control +1
- 60%
On the Usability of HTTPS Deployment
CHI '19· Privacy by Design & User Control +1
- 60%
No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
CHI '25· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)