Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese Industries

Privacy by Design & User ControlCybersecurity Training & AwarenessSoftware Engineers & DevelopersCybersecurity Engineers

Title of the Paper

Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese Industries

Bibliographic Information

  • Subject Area: Security in Software Development, Human Factors in Software Engineering
  • Keywords: Software security, public guidelines, in-house guidelines, secure programming, HCI development, survey

Research Background and Issues

  • Identified Problems or Challenges:

    1. Existing research primarily focuses on the use of public secure development guidelines, with limited attention to in-house secure development guidelines constructed by enterprises.
    2. There is a lack of validation for recommended practices in implementing secure development guidelines within industrial settings.
    3. Most studies focus on single-country investigations (e.g., the U.S.), with few comparative studies, especially considering differences in development models and cultural factors (e.g., Japan's more prevalent outsourcing development model).
  • Significance: As software-related cyberattacks become increasingly frequent, improving developers' adherence to secure development guidelines is critical for enhancing software security. The combined use of public and in-house guidelines remains unclear, and comprehensive analysis of regional and cultural differences is lacking.

  • Research Motivation: This study aims to understand the practical application of public and in-house secure development guidelines in software development through industry surveys, as well as the impact of project characteristics and national development cultures on their implementation.

Solution

  • Proposed Methods/Solutions:

    1. Collect quantitative and qualitative data from 870 software development professionals in the U.S. and Japan through an online survey (396 participants from the U.S., 474 from Japan).
    2. Focus on analyzing:
      • Frequency and reasons for using public and in-house secure development guidelines.
      • Feasibility of recommended practices for implementing secure development guidelines proposed in existing research.
      • Differences in guideline usage between Japanese and U.S. developers.
  • Innovations:

    1. Conducting the first systematic study on the combined use of public and in-house secure development guidelines and their functional differences.
    2. Comparing the practical application of guidelines across different countries and development environments, revealing the influence of culture, project scale, and organizational structure on guideline implementation.
  • Implementation Steps and Techniques:

    1. Survey Design: Develop questions based on literature review and interviews, covering guideline types, usage, usability, and the operability of recommended practices.
    2. Data Collection: Conduct online surveys targeting developers and managers in the U.S. and Japan, ensuring a diverse participant pool.
    3. Data Analysis:
      • Perform quantitative analysis using SPSS (e.g., regression analysis, chi-square tests).
      • Conduct thematic analysis of qualitative responses to open-ended questions to identify patterns.

Research Findings

  • Specific Findings:

    1. In-house guidelines are widely adopted in industrial settings (usage rate: 87.1% in the U.S., 85.9% in Japan).
    2. In-house guidelines are more frequently mandated by companies compared to public guidelines (especially in the U.S.).
    3. Participants who use both public and in-house guidelines tend to perceive higher usability of the guidelines.
  • Experimental or Evaluation Results:

    1. Participants from small-scale projects (e.g., teams with fewer than five members) and outsourced development projects find it more challenging to implement recommended practices for secure development guidelines.
    2. Companies with a CSO (Chief Security Officer) or CISO (Chief Information Security Officer) are more likely to implement recommended practices effectively.
    3. Japanese participants tend to evaluate secure development guidelines more conservatively, while novice developers in the U.S. are more optimistic.
  • Advantages:

    1. Comprehensive data provides detailed comparisons of the practical application of public and in-house secure development guidelines.
    2. The findings have practical implications for improving the operability of secure development guidelines in the industry.
  • Limitations and Future Directions:

    1. Limitations:
      • The survey does not analyze the specific content of public guidelines in detail, focusing instead on guideline types and general characteristics.
      • Social desirability bias may exist in the data (e.g., participants may tend to report positive outcomes).
    2. Future Directions:
      • Use qualitative methods such as interviews to explore the development and usage processes of in-house guidelines in detail.
      • Investigate lightweight and easy-to-implement guideline strategies to accommodate resource-constrained development environments.
      • Compare the potential impact of development cultures on guideline operability across more countries and regions.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/96593/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3580705
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Privacy by Design & User Control, Cybersecurity Training & Awareness
work
Professions
Software Engineers & Developers, Cybersecurity Engineers
article
Content Status
Full text indexed
hub
Related Papers
5 related papers