Background: Implementing security standards is important to ensure proper functioning and avoid malicious attacks. Neglecting security can lead to Security Debt (SD), which can be disruptive. However, the industry does not have a generally accepted definition of SD thus far. Aims: This exploratory case study aims to provide a definition of SD, to find the relation between SD and Technical Debt (TD), to find the difference between SD and security vulnerabilities, and to identify SD accumulation patterns. Method: We interviewed 26 software practitioners from an international conglomerate of several software companies. Results: We propose a multifaceted SD definition. SD is a subset of TD, and security vulnerabilities have, to a varying degree, been shown to be part of SD. Conclusion: Our results can provide a clearer view of how practitioners perceive SD, facilitating its management.
The global Information Technology (IT) market was valued at approximately $3,110 million in 2022, marking a 7.4% increase over the previous year. Of this total, around 56% pertained to the software and services sector. This growth poses a global challenge for IT organizations due to a significant gap between the increasing demand for IT skills and the availability of qualified professionals. Currently, about 87% of organizations worldwide are experiencing the effects of this skills gap, hindering business operations. Traditional undergraduate computing programs often require more time than the current market demands can afford. To address this issue, universities and companies are developing innovative educational strategies. Our goal is to share the experience of implementing four distinct cases, three in Brazil and one in Norway, so that other universities and companies can adopt similar strategies to alleviate the IT skills shortage. Therefore, this paper presents strategies for the preparation of IT professionals to mitigate the impacts of the IT labor shortage. Each case includes an experience report on the context, structure, benefits, hard and soft skills developed, and lessons learned. Finally, we summarize the contributions of these four cases by reflecting on their differences and similarities, followed by a summary of the strategies that proved effective in collaborating with companies.
Creativity, the process of creating something new and valuable, benefits children by improving their skills and development, encouraging interaction and engagement, and enabling the generation and expression of novel ideas. In recent years, interactive digital tools have emerged to support the user’s creativity in the open-ended creation of new artifacts. However, the question of evaluating the creativity happening in the interplay between children, digital tools, and products is still open. This systematic literature review investigated the evaluations of digital creativity support tools for children and identified 81 peer-reviewed relevant articles from the last 10 years. This research contributes to practitioners and researchers by providing an overview of the evaluations in a framework based on 10 factors (value, novelty, fluency, enjoyment, user feeling, collaboration, expressiveness, immersion, flexibility, and interaction), nine product areas, three approaches, and five methods. The review demonstrated that the evaluations differ widely, and the area lacks a standard evaluation framework. We propose the dimensions of our analysis as an initial framework for situating the evaluation of digital creativity support tools for children that the child–computer interaction community can further refine.
The role of security practices is increasingly recognized in fast-paced software development paradigms in contributing to overall software security. Security champions have emerged as a promising role in addressing the shortage of explicit security activities within software teams. Despite the growing awareness of general security practices, there remains limited knowledge regarding security champions, including their establishment, effectiveness, challenges, and best practices. This paper aims to bridge this gap by presenting insights from a survey of 73 security champions and 11 interviews conducted within a large Norwegian software house. Through this study, we explore the diverse activities undertaken by security champions, highlighting notable differences in motivations and task descriptions between voluntary and assigned champions. We also reported challenges with onboarding, communication, and training security champions and how they can be better supported in the organization. Our insight can be relevant for similar software houses in establishing, implementing, and improving their strategic security programs.
Technology has become ubiquitous, providing us with easy access to information, enhanced social connectivity, and expanded employment opportunities. However, nearly one billion people face significant challenges when using common software applications due to their disabilities. Consequently, it is crucial to prioritize accessibility requirements when developing inclusive software. Adhering to accessibility standards not only fulfills legal obligations but also enables software teams to identify the essential accessibility aspects that should be incorporated into software requirements. Agile teams have implemented various strategies, including self-assessment, to meet accessibility requirements. Nevertheless, there is a limited understanding of how agile software development teams effectively implement accessibility standards and strive to enhance accessibility requirements. This study presents a case study of how ORG software teams use self-assessments to facilitate the implementation of accessibility requirements. We evaluated 23 product self-assessments and it was revealed that some teams demonstrated significant progress in meeting the criteria, while others encountered challenges along the way. Multiple factors contribute to the non-compliance to accessibility standards such as insufficient time, knowledge, guidance, understanding, and resources. To overcome these challenges, planning carefully and considering all aspects is essential. By addressing these critical aspects, software teams can enhance their understanding, skills, and resources, ultimately improving the accessibility of their products and ensuring equal opportunities for all individuals.
Social aspects in software sustainability refer to the impact of the software on the broader social and societal context. These aspects involve considerations such as accessibility, equity, inclusion, diversity, ethical and human values. While achieving software sustainability requires developers to embrace approaches that support the three dimensions of sustainability, there remains a lack of concrete approaches to address social aspects during software development. This literature review aims to facilitate the integration of social aspects into the software development process by identifying approaches related to social sustainability in software engineering. We extracted and analyzed data from 19 studies through thematic syntheses. The results of our analysis provide a list of recommended tools and practices to support social aspects and attain software sustainability goals. By incorporating these approaches into software development, we ensure that the software is not only technically sustainable but also socially responsible from a human perspective.
Security is increasingly recognized as an important aspect of software development processes. In agile software development, adoption of security practices is still facing a lot of challenges due to the perception and management of software teams. A security champion is an important strategic mechanism for creating a better security culture, however it is little known about how they can be achieved. In this paper, we present the results of a systematic literature review investigating approaches to establishing and maintaining a security champion in an organization with Agile teams. Gathering empirical evidence from 11 primary studies, we presented how security champion is characterized, the conditions for establishing and reported challenges in maintaining security champion programs. One of our main findings is a classification schema of 14 steps and 32 actions can be taken to establish a security champion program. The study has practical recommendations for organizations who want to establish or improve their security program in Agile teams.
Software sustainability has been a trending topic in the last decade in academia. Studies related to software sustainability propose models, frameworks, or practices that can be applied in the industry. But most of these proposals are still not systematically adopted in the industry. Therefore, there is an opportunity to create a structured meeting to support the concrete adoption of sustainability practices in software development. This paper aims to provide an overview of these frameworks and how they can help facilitate sustainability-driven meetings (SusDM). Seeking this, we present practical examples and a workflow to prepare the meeting by applying the existing sustainability frameworks in SusDM. As a position paper, our hypothesis is that the contributions of this meeting may be related to improving the knowledge of software developers on sustainable software engineering, discovering new sustainability requirements, prioritization, and implementing software sustainability practices.
As organizations increasingly host their services in the cloud, Infrastructure as Codesolutions(IaC) are widely used to automate the provisioning of cloud services. These tools can introduce security weaknesses and risky changes to the cloud platforms which have become a highly attractive attack surface for hackers. The purpose of this research is to analyze the IaC security of industrial projects and to assist infrastructure and system engineers in order to find vulnerabilities in their code and understand the features and limitations of the current tools. Compared to previous studies that focused on the quality of IaC code in terms of security smells and their type, this study evaluates IaC static analysis tools, and analysis the cloud vulnerabilities identified across multiple projects. Furthermore, this research contributes to the empirical understanding of vulnerabilities in IaC for an industrial setting as opposed to an open source context. The results show the current level of practice in 20 industrial projects.Based on this analysis, we developed recommendations for improvements in practice and discussed the perceived challenges and advantages of using these tools for software development teams in a shift-left approach to security.
Context: Security and performance (S&P) are critical non-functional requirements on software systems. Therefore, verification activities should be included in the development process to identify related defects and avoiding S&P failures after deployment. However, the state of the practice of S&P verification is unclear, challenging academia to offer solutions for real-world problems faced by the S&P verification practitioners. Thus, identifying factors moderating the S&P verification helps software development organizations improve the S&P verification, releasing software that meets security and performance requirements. Objective: To present moderator factors influencing S&P verification activities and actions to promote S&P moderator factors. Method: Multiple case study using qualitative analysis of observational data to identify S&P moderators factors. Literature Rapid Reviews with Snowballing to strengthen confidence in the identified S&P moderators factors. Practitioners Survey to classify the S&P moderator factors regarding their relevance. Results: Identification of eight S&P moderator factors regarding organizational awareness, crossfunctional team, S&P requirements, support tools, verification environment, verification methodology, verification planning, and reuse practices. The literature reviews allowed us to confirm the identified S&P moderator factors and identify a set of actions to promote each of them. A survey with 37 valid participants allowed us to classify the identified S&P moderators factors and their actions relevant to S&P verification activities. Conclusions: The S&P moderator factors can be considered key points in which software development organizations should invest to implement or improve S&P verification activities.
To remain competitive in the market, software development teams must innovate. Focusing on security can increase the sales of software products because software security is a proven differentiator in competitive industries. In this case, software security requires continuous innovations, which can be seen either as discrete products or as outcomes that turn into new ideas, methods or process of introducing something new. The goal of such innovations would be to create a sustainable security program that can ensure that software development teams continue to use the practices that improve and address the security of their products by adopting a long-term perspective. This chapter describes the stages of effective and sustainable implementation of a software security program while using one systematic model for purposefully disseminating innovations in software security practices.
Software security needs to be a continuous endeavour in current software development practices. Frequent software updates, paired with an ongoing flow of security breaches, requires software companies to address software security throughout development and post deployment. Prescriptive software security approaches do not match well with agile software development and its emphasis on self-management. Agile approaches are however in favour of meetings as a coordination and problem-solving strategy. This article investigates the role of regular security meetings centred on making security priorities and decisions for achieving continuous software security. Through technical action research and an observational case study, we studied variations of such meetings in three companies. We found that such meetings can reach key stakeholders, make security more visible, and contribute to ongoing security prioritisation. Thus, security meetings are a promising approach, especially for small and medium sized development companies with basic yet immature security competence. Future research should investigate further the role of such meetings and how best to organise them for different contexts and needs. For this we outline implications for research and practice, e.g., related to participants and how to organise the discussions and prioritisations in the meeting.
Improving software security in software development teams is an enduring challenge for software companies. In this chapter, the authors present one strategy for addressing this pursuit of improvement. The approach is ambidextrous in the sense that it focuses on approaching software security activities both from a top-down and a bottom-up perspective, combining elements usually found separately in software security initiatives. The approach combines (1) top-down formal regulatory mechanisms deterring breaches of protocol and enacting penalties where they occur and (2) bottom-up capacity building and persuasive encouragement of adherence to guidance by professional self-determination, implementation, and improvement support (e.g., training, stimulating, interventions). The ambidextrous governance framework illustrates distinct, yet complementary, global and local roles: (1) ensuring the adoption and implementation of software security practices, (2) enabling and (3) empowering software development teams to adapt and add to overall mandates, and (4) embedding cultures of improvement.
Software security is a complex topic, and for development projects it can be challenging to assess what security is necessary and cost-effective. Agile Software Development (ASD) values self-management. Thus, teams and their Product Owners are expected to also manage software security prioritisation. In this paper we build on the notion that security experts who want to influence the priority given to security in ASD need to do this through interactions and support for teams rather than prescribing certain activities or priorities. But to do this effectively, there is a need to understand what hinders and supports teams in prioritising security. Based on a longitudinal case study, this article offers insight into the strategy used by one security professional in an SME to influence the priority of security in software development projects in the company. The main result is a model of influences on security prioritisation that can assist in understanding what supports or hinders the prioritisation of security in ASD, thus providing recommendations for security professionals. Two alternative strategies are outlined for software security in ASD – prescribed and emerging – where we hypothesise that an emerging approach can be more relevant for SMEs doing ASD, and that this can impact how such companies should consider software security maturity.
Data from Internet of Things (IoT) devices has become a critical asset for decision-making. However, IoT devices have security challenges due to their low-resource constraints, heterogeneity, and deployment in hostile environments. Systems consuming IoT data must thus be designed with security measures to detect and prevent data tampering attacks. We develop a data-centric threat modeling method named Data Protection Fortification (DPF) that practitioners can use during planning to assess and mitigate the security risk of using IoT data sources. We use design science to develop and validate DPF on 5 development teams from 3 organizations. Results show that DPF can be used to identify and improve security practices of data sources. Practitioners have a positive attitude towards using DPF and because it is easily understood, it has the potential to become a communication tool for security between developers and stakeholders.
Security is increasingly recognized as an important aspect of software development processes. Improving processes for security in agile teams is very important to streamline the focus on security and keep the agility of the software development process. In Visma we use data to drive improvement of security services provided to the software teams. The improvement process involves changing the services or their structures after some period of usage and experience with it, driven by data collected during operations. We systematically identify the areas that need changes in order to become more valuable for the development teams and for the security program. In this paper we have described the improvement process used on the security static analysis service in Visma, the data we have used for that, how we extracted this data from the Static Application Security Testing (SAST) tool, the lessons learned and also provide some guidelines to other organizations that would like to use this method in their own services.
Replication package for the paper "Moderator Factors of Software Security and Performance Verification"
In agile software development, adoption of security practices poses challenges, often because security activities are not prioritized, or because the practitioners are not able to see the relevance and importance of the activities to the improvement of the security in the project. In many teams, security activities can be seen as an innovation and as such, there is a need for a champion to realize these innovations in the teams. Security champions make software security possible. Even though all developers need to know a minimum of software security, every team needs someone to lean on when the ride gets rough – and that person is the security champion. In this paper we present the results of a case study with security champions and possible steps for establishing and maintaining this role in agile teams.
Children are increasingly using the internet nowadays. While internet use exposes children to various privacy and security risks, few studies have examined how parents perceive and address their children's cybersecurity risks. To address this gap, we conducted a qualitative study with 25 parents living in Norway with children aged between 10 to 15. We conducted semi-structured interviews with the parents and performed a thematic analysis of the interview data. The results of this paper include a list of cybersecurity awareness needs for children from a parental perspective, a list of learning resources for children, and a list of challenges for parents to ensure cybersecurity at home. Our results are useful for developers and educators in developing cybersecurity solutions for children. Future research should focus on defining cybersecurity theories and practices that contribute to children's and parents' awareness about cybersecurity risks, needs, and solutions.
Cybersecurity for children has received much attention and has become a rapidly growing topic due to the increased availability of the internet to children and their consequent exposure to various online risks. This paper aims to summarize the current findings on cybersecurity awareness research for children and help guide future studies. We have performed a systematic literature review on cybersecurity awareness for children, analyzing 56 peer-reviewed studies that report in depth on various cybersecurity risks and awareness-raising approaches. The results of this review include a list of cybersecurity risks for children, a list of commonly used approaches and theories for raising cybersecurity awareness among children, and a list of factors that researchers have considered when evaluating cybersecurity awareness approaches and solutions.