Co-Creation in Secure Software Development: Applied Ethnography and the Interface of Software and Development

被引:0
作者
Lende, Daniel [1 ]
Monkhouse, Alexis [1 ]
Ligatti, Jay [2 ]
Ou, Xinming [2 ]
机构
[1] Univ South Florida USF, Dept Anthropol, Tampa, FL 33620 USA
[2] USF, Dept Comp Sci & Engn, Tampa, FL USA
基金
美国国家科学基金会;
关键词
cybersecurity; software development; business ethnography; co-creation; learning; DEFICIT MODEL; ANTHROPOLOGY; EDUCATION;
D O I
10.17730/1938-3525-82.1.13
中图分类号
Q98 [人类学];
学科分类号
030303 ;
摘要
Long-term ethnographic research conducted at a software company examined how security concerns and practices became part of software development. Participant observation over a two-year period was done by researchers with cybersecurity backgrounds and training in both computer science and qualitative research, with ongoing analysis done by a larger interdisciplinary team. In situ researchers joined as software engineers and participated in daily work activities while observing development practices and analyzing software (in)security. The first year of research found that improving security during software development can be helped by a co-creation model, whereby security experts work directly with software developers to provide security tools applicable to the specific software within the workflow. Researchers-as-developers fostered conversations, concerns, and considerations of how to implement security within the process of development. The second year used a situated learning approach to understand the interface between software development, security, and the development team. Through an interactive learning process, software engineers gathered knowledge and applied it, helping to foster greater concerns for security as part of the overall "culture" of development within the company. This locally situated co-creation approach has resonances with participatory approaches in business anthropology and implications for how to promote the co-creation of knowledge and expertise more broadly.
引用
收藏
页码:13 / 24
页数:12
相关论文
共 50 条
[21]   Reflections on Training Next-Gen Industry Workforce on Secure Software Development [J].
Gasiba, Tiago Espinha ;
Iosif, Andrei-Cristian ;
Suppan, Santiago ;
Lechner, Ulrike ;
Pinto-Albuquerque, Maria .
PROCEEDINGS OF THE 5TH EUROPEAN CONFERENCE ON SOFTWARE ENGINEERING EDUCATION, ECSEE 2023, 2023, :1-10
[22]   A Platform for Teaching Applied Distributed Software Development The Ongoing Journey of the Helsinki Software Factory [J].
Fagerholm, Fabian ;
Oza, Nilay ;
Muench, Juergen .
2013 3RD INTERNATIONAL WORKSHOP ON COLLABORATIVE TEACHING OF GLOBALLY DISTRIBUTED SOFTWARE DEVELOPMENT (CTGDSD), 2013, :1-5
[23]   CATS - An automated user interface for software development and testing [J].
Heimann, DI .
ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM, 1996 PROCEEDINGS, 1996, :163-166
[24]   ABET Cybersecurity Continual Course Improvements for Secure Software Development [J].
Schmeelk, Suzanna E. ;
Dragos, Denise M. ;
DeBello, Joan E. .
2021 IEEE FRONTIERS IN EDUCATION CONFERENCE (FIE 2021), 2021,
[25]   Authentic Learning Secure Software Development (SSD) in Computing Education [J].
Qian, Kai ;
Lo, Dan ;
Parizi, Reza ;
Wu, Fan ;
Agu, Emmanuel ;
Chu, Bei-Tseng .
2018 IEEE FRONTIERS IN EDUCATION CONFERENCE (FIE), 2018,
[26]   How valuable are your customers in the brand value co-creation process? The development of a Customer Co-Creation Value (CCCV) scale [J].
Merz, Michael A. ;
Zarantonello, Lia ;
Grappi, Silvia .
JOURNAL OF BUSINESS RESEARCH, 2018, 82 :79-89
[27]   Search-based co-creation of software models: The case of particle systems for video games [J].
Chueca, Jorge ;
Cetina, Carlos ;
Pastor, Oscar ;
Font, Jaime .
INFORMATION AND SOFTWARE TECHNOLOGY, 2024, 171
[28]   From Software Development to Software Assembly [J].
Sneed, Harry M. ;
Verhoef, Chris .
IEEE SOFTWARE, 2016, 33 (05) :80-85
[29]   SoftBook: Software Development as an Adventure [J].
Silva, L. F. ;
Jacome, W. C. .
IEEE LATIN AMERICA TRANSACTIONS, 2017, 15 (06) :1205-1211
[30]   Global Software Development Project [J].
Cao, Lan ;
Zhu, Hongwei ;
Su, Guiyang .
AMCIS 2012 PROCEEDINGS, 2012,