Raising Secure Coding Awareness for Software Developers in the Industry

02/20/2021
by   Tiago Espinha Gasiba, et al.
0

Many industrial IT security standards and policies mandate the usage of a secure coding methodology in the software development process. This implies two different aspects: first, secure coding must be based on a set of secure coding guidelines, and second software developers must be aware of these secure coding practices. On the one side, secure coding guidelines seems a bit like a black-art: while there exist abstract guidelines that are widely accepted, low-level secure coding guidelines for different programming languages are scarce. On the other side, once a set of secure coding guidelines is chosen, a good methodology is needed to make them known by the people which should be using them, i.e. software developers. Motivated both by the secure coding requirements from industry standards and also by the mandate to train staff on IT security by the global industry initiative "Charter of Trust", this paper presents an overview of important research questions on how to choose secure coding guidelines and on how to raise software developer awareness for secure coding using serious games.

READ FULL TEXT

page 1

page 2

page 3

research
12/10/2020

Integration of Security Modules in Software Development Lifecycle Phases

Information protection is becoming a focal point for designing, creating...
research
02/10/2021

Is Secure Coding Education in the Industry Needed? An Investigation Through a Large Scale Survey

The Department of Homeland Security in the United States estimates that ...
research
12/28/2022

Coding Guidelines and Undecidability

The C and C++ programming languages are widely used for the implementati...
research
02/20/2021

Cybersecurity Awareness Platform with Virtual Coach and Automated Challenge Assessment

Over the last years, the number of cyber-attacks on industrial control s...
research
09/18/2019

Prolog Coding Guidelines: Status and Tool Support

The importance of coding guidelines is generally accepted throughout dev...
research
04/20/2018

Securing Email

Email is the most ubiquitous and interoperable form of online communicat...
research
12/23/2021

A Rationale-Based Classification of MISRA C Guidelines

MISRA C is the most authoritative language subset for the C programming ...

Please sign up or login with your details

Forgot password? Click here to reset