“Have Heard of it”: A Study with Practitioners on Adoption of Secure Software Development Frameworks
Alex Wee, Arina Kudriavtseva, Olga Gadyatskaya · 2024
The ever-growing incidence of software vulnera-bilities giving rise to devastating cyber attacks pushes orga-nizations and governments to take software security more seriously. To avoid vulnerabilities, organizations producing software strive to adopt secure software development frame-works (SSDFs). Our mixed-methods study with software development practitioners focuses on the SSD Fs' adoption trends and examines the key factors influencing organizational decisions regarding secure software development. Our findings from a survey ($n=37$) and interviews ($n=8$) with software development practitioners indicate that, while being aware of the existing SSDFs, organizations mostly use custom-made frameworks that afford more flexibility and align better with the development processes.