A Software Security Study among German Developers, Product Owners, and Managers
Abstract
Online news portals report almost daily on security incidents in all kinds of software products in finance, health, and engineering. Moreover, multiple security reports conclude that there is a growing number of security vulnerabilities, attacks, and incidents. This raises the question of the extent to which companies address software security while developing and operating their products. This paper reports on the results of an extensive study among developers, product owners, and managers in Germany. Our results show that ensuring security is a multi-faceted challenge for German companies, involving low awareness, inaccurate self-assessment, and a lack of competence on the topic of secure software development among all stakeholders. Thus, there is an urgent need to improve the current situation.
Keywords: Software Security, Study, Developer, Product Owner, Manager, Awareness, Security Tools, Training
DOI: 10.54941/ahfe1002208
Cite this paper
More from this volume
- A Metric to Assist in Detecting International Phishing or Ransomware Cyberattacks
- Insider Threat: Cognitive Effects of Modern Apathy towards Privacy, Trust, and Security
- A Didactic Tool for Digital Forensics
- A Closer Look at Insider Threat Research
- Social Engineering and Human-Robot Interactions' Risks
- Isolating Key Phrases to Identify Ransomware Attackers
- Information Security Awareness and Training as a Holistic Key Factor – How Can a Human Firewall Take on a Complementary Role in Information Security?
- Cyberdefense Adaptive Training Based on the Classification of Operator Cognitive State
- Exploring Human and Environmental Factors that Make Organizations Resilient to Social Engineering Attacks
- Assessing Human Factors and Cyber Attacks at the Human-Machine Interface: Threats to Safety and Pilot and Controller Performance
- Navigating through Cyber Threats, A Maritime Navigator’s Experience
- A Coherence Model to Outline Obstacles and Success Factors for Information Security from the CISO's Point of View


AHFE Open Access