Human factors in software security risk management
Shareeful Islam, Wei Yu Dong · 2008
All kinds of human factors can deeply affect the results and efficiency of software risk management. This paper focuses on our ongoing work of studying human factors in security risk management. The human factors are identified and classified for the categories of individual, team, management and stakeholder, as well as for the activities of security risk identification, analysis and mitigation. Then some considerations and recommendations for mitigating these factors and risks are presented, and the generic framework of evolving them into the secure software architecture is also figured.