Security in Online Freelance Software Development: A case for Distributed Security Responsibility

07/12/2023
by   Irum Rauf, et al.
0

Secure software is a cornerstone to safe and resilient digital ecosystems. It offers strong foundation to protect users' sensitive data and guard against cyber-threats. The rapidly increasing landscape of digital economy has encouraged developers from different socio-technical and socio-economic backgrounds to join online freelance marketplaces. While, secure software practices facilitate software developers in developing secure software, there is paucity of research on how freelance developers adhere to security practices and how they can be facilitated to improve their security behavior in under-resourced environments. Moreover, freelance developers are often held responsible for producing insecure code. In this position paper, we review existing literature and argue for the case of distributed security responsibilities in online freelance environment. We propose a research agenda aimed at offering an organized and systematic effort by researchers to address security needs and challenges of online freelance marketplaces. These include: characterising software security and defining separation of responsibilities, building trust in online freelance development communities, leveraging the potential of online freelancing platforms in the promotion of secure software development and building adaptive security interventions for online freelance software development. The research has the potential to bring forth existing security solutions to wider developer community and deliver substantial benefits to the broader security ecosystem.

READ FULL TEXT
research
12/30/2020

Importance of Secure Software Development Processes and Tools for Developers

In this research paper of secure software systems, authors have discusse...
research
11/04/2022

Better Call Saltzer & Schroeder: A Retrospective Security Analysis of SolarWinds & Log4j

Saltzer & Schroeder's principles aim to bring security to the design of ...
research
09/09/2023

The Effectiveness of Security Interventions on GitHub

In 2017, GitHub was the first online open source platform to show securi...
research
11/29/2022

Secure Software Development Methodologies: A Multivocal Literature Review

In recent years, the number of cyber attacks has grown rapidly. An effec...
research
12/20/2020

Software, Attacker and Asset-centric Approach for Improving Security in System Development Process

Secure development process is a procedure taken by developers to ensure ...
research
04/20/2018

Securing Email

Email is the most ubiquitous and interoperable form of online communicat...
research
05/12/2022

Conversational DevBots for Secure Programming: An Empirical Study on SKF Chatbot

Conversational agents or chatbots are widely investigated and used acros...

Please sign up or login with your details

Forgot password? Click here to reset