{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T22:41:36Z","timestamp":1783636896496,"version":"3.55.0"},"reference-count":74,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2023,4,26]],"date-time":"2023-04-26T00:00:00Z","timestamp":1682467200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"UK NCSC, UKRI\/EPSRC","award":["EP\/R013144\/1, EP\/T017465\/1"],"award-info":[{"award-number":["EP\/R013144\/1, EP\/T017465\/1"]}]},{"name":"SFI","award":["13\/RC\/2094_P2"],"award-info":[{"award-number":["13\/RC\/2094_P2"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2023,7,31]]},"abstract":"<jats:p>The pressure on software developers to produce secure software has never been greater. But what does security look like in environments that do not produce security-critical software? In answer to this question, this multi-sited ethnographic study characterizes security episodes and identifies five typical behaviors in software development. Using theory drawn from information security and motivation research in software engineering, this article characterizes key ways in which individual developers form security responses to meet the demands of particular circumstances, providing a framework managers and teams can use to recognize, understand, and alter security activity in their environments.<\/jats:p>","DOI":"10.1145\/3563211","type":"journal-article","created":{"date-parts":[[2022,9,12]],"date-time":"2022-09-12T12:45:55Z","timestamp":1662986755000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":15,"title":["Security Responses in Software Development"],"prefix":"10.1145","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8766-1896","authenticated-orcid":false,"given":"Tamara","family":"Lopez","sequence":"first","affiliation":[{"name":"School ofComputing and Communications, The Open University, Walton Hall, Milton Keynes, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4376-1734","authenticated-orcid":false,"given":"Helen","family":"Sharp","sequence":"additional","affiliation":[{"name":"School ofComputing and Communications, The Open University, Walton Hall, Milton Keynes, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8974-0555","authenticated-orcid":false,"given":"Arosha","family":"Bandara","sequence":"additional","affiliation":[{"name":"School ofComputing and Communications, The Open University, Walton Hall, Milton Keynes, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8524-106X","authenticated-orcid":false,"given":"Thein","family":"Tun","sequence":"additional","affiliation":[{"name":"School ofComputing and Communications, The Open University, Walton Hall, Milton Keynes, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5696-6021","authenticated-orcid":false,"given":"Mark","family":"Levine","sequence":"additional","affiliation":[{"name":"Department of Psychology, University of Lancaster, Bailrigg, Lancaster, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3476-053X","authenticated-orcid":false,"given":"Bashar","family":"Nuseibeh","sequence":"additional","affiliation":[{"name":"School of Computing and Communications, The Open University, Walton Hall, Milton Keynes, UK and Lero-The Irish Software Research Centre, Republic of Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,26]]},"reference":[{"key":"e_1_3_4_2_2","first-page":"3","volume-title":"Proceedings of the IEEE Conference on Cybersecurity Development (SecDev\u201916)","author":"Acar Yasemin","year":"2016","unstructured":"Yasemin Acar, Sascha Fahl, and Michelle L. Mazurek. 2016. You are not your developer, either: A research agenda for usable security and privacy research beyond end users. In Proceedings of the IEEE Conference on Cybersecurity Development (SecDev\u201916). IEEE, 3\u20138."},{"key":"e_1_3_4_3_2","first-page":"22","volume-title":"Proceedings of the IEEE Conference on Cybersecurity Development (SecDev\u201917)","author":"Acar Yasemin","year":"2017","unstructured":"Yasemin Acar, Christian Stransky, Dominik Wermke, Charles Weir, Michelle L. Mazurek, and Sascha Fahl. 2017. Developers need support, too: A survey of security advice for software developers. In Proceedings of the IEEE Conference on Cybersecurity Development (SecDev\u201917). IEEE, 22\u201326."},{"key":"e_1_3_4_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/322796.322806"},{"issue":"5","key":"e_1_3_4_5_2","first-page":"72\u201383, 144","article-title":"Inner work life: Understanding the subtext of business performance","volume":"85","author":"Amabile Teresa M.","year":"2007","unstructured":"Teresa M. Amabile and Steven J. Kramer. 2007. Inner work life: Understanding the subtext of business performance. Harv. Bus. Rev. 85, 5 (2007), 72\u201383, 144.","journal-title":"Harv. Bus. Rev."},{"key":"e_1_3_4_6_2","first-page":"159","volume-title":"The Encyclopedia of Microcomputers","author":"Anderson Bob","year":"1997","unstructured":"Bob Anderson. 1997. Work, ethnography and system design. In The Encyclopedia of Microcomputers, Vol. 20. Marcel Dekker, 159\u2013183."},{"key":"e_1_3_4_7_2","doi-asserted-by":"publisher","DOI":"10.5555\/1373319"},{"key":"e_1_3_4_8_2","doi-asserted-by":"publisher","DOI":"10.1002\/9781119644682"},{"key":"e_1_3_4_9_2","doi-asserted-by":"crossref","first-page":"67","DOI":"10.4135\/9781849208932.n6","volume-title":"Doing Ethnographic and Observational Research","author":"Angrosino Michael","year":"2007","unstructured":"Michael Angrosino. 2007. Analyzing ethnographic data. In Doing Ethnographic and Observational Research. SAGE Publications Ltd, 67\u201376."},{"key":"e_1_3_4_10_2","first-page":"281","volume-title":"Proceedings of the 14th Symposium on Usable Privacy and Security (SOUPS\u201918)","author":"Assal Hala","year":"2018","unstructured":"Hala Assal and Sonia Chiasson. 2018. Security in the software development lifecycle. In Proceedings of the 14th Symposium on Usable Privacy and Security (SOUPS\u201918). 281\u2013296."},{"key":"e_1_3_4_11_2","article-title":"Finding security champions in blends of organisational culture","volume":"11","author":"Becker Ingolf","year":"2017","unstructured":"Ingolf Becker, Simon Parkin, and M. Angela Sasse. 2017. Finding security champions in blends of organisational culture. Proc. USEC 11 (2017).","journal-title":"Proc. USEC"},{"key":"e_1_3_4_12_2","doi-asserted-by":"publisher","DOI":"10.1080\/01972243.2019.1583296"},{"key":"e_1_3_4_13_2","doi-asserted-by":"crossref","unstructured":"Hal Berghel. 2017. Equifax and the latest round of identity theft roulette. Computer 50 12 (2017-12) 72\u201376.","DOI":"10.1109\/MC.2017.4451227"},{"key":"e_1_3_4_14_2","unstructured":"Marcus Beyer Sarah Ahmed Katja Doerlemann Simon Arnell Simon Parkin M. A. Sasse and Neil Passingham. 2015. Awareness is only the first step. A Framework for Progressive Engagement of Staff in Cyber Security Hewlett Packard Business white paper (December 2015). Retrieved from https:\/\/www.riscs.org.uk\/wp-content\/uploads\/2015\/12\/Awareness-is-Only-the-First-Step.pdf."},{"issue":"7","key":"e_1_3_4_15_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1177\/016146812112300704","article-title":"How distributed leadership facilitates technology integration: A case study of \u201cpilot teachers.\u201d","volume":"123","author":"Bingham Andrea J.","year":"2021","unstructured":"Andrea J. Bingham. 2021. How distributed leadership facilitates technology integration: A case study of \u201cpilot teachers.\u201dTeachers Coll. Rec. 123, 7 (2021), 1\u201334.","journal-title":"Teachers Coll. Rec."},{"key":"e_1_3_4_16_2","volume-title":"National Cyber Awareness System: Weekly Bulletins","year":"2021","unstructured":"CISA. 2021. National Cyber Awareness System: Weekly Bulletins. Cybersecurity & Infrastructure Security Agency. Retrieved from https:\/\/us-cert.cisa.gov\/ncas\/bulletins."},{"key":"e_1_3_4_17_2","volume-title":"Practising Creative Securities","author":"Coles-Kemp Lizzie","year":"2018","unstructured":"Lizzie Coles-Kemp. 2018. Practising Creative Securities. Royal Hall University of London."},{"key":"e_1_3_4_18_2","doi-asserted-by":"crossref","first-page":"464","DOI":"10.1007\/978-3-319-58460-7_32","volume-title":"Human Aspects of Information Security, Privacy and Trust (Lecture Notes in Computer Science)","author":"Coles-Kemp Lizzie","year":"2017","unstructured":"Lizzie Coles-Kemp and Ren\u00e9 Rydhof Hansen. 2017. Walking the line: The everyday security ties that bind. In Human Aspects of Information Security, Privacy and Trust (Lecture Notes in Computer Science). Springer International Publishing, 464\u2013480."},{"key":"e_1_3_4_19_2","volume-title":"Are Developers Your First Line of Security Risk or Defense?","author":"Danhieux Pieter","year":"2018","unstructured":"Pieter Danhieux. 2018. Are Developers Your First Line of Security Risk or Defense? Retrieved from https:\/\/devops.com\/are-developers-your-first-line-of-security-risk-or-defense\/."},{"key":"e_1_3_4_20_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-84800-044-5_11"},{"key":"e_1_3_4_21_2","doi-asserted-by":"publisher","DOI":"10.1080\/158037042000225245"},{"key":"e_1_3_4_22_2","doi-asserted-by":"publisher","DOI":"10.4324\/9781315596389"},{"key":"e_1_3_4_23_2","volume-title":"Ethnography: Step-by-Step","author":"Fetterman David M.","year":"2009","unstructured":"David M. Fetterman. 2009. Ethnography: Step-by-Step. Sage Publications."},{"key":"e_1_3_4_24_2","first-page":"121","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (SP\u201917)","author":"Fischer Felix","year":"2017","unstructured":"Felix Fischer, Konstantin B\u00f6ttinger, Huang Xiao, Christian Stransky, Yasemin Acar, Michael Backes, and Sascha Fahl. 2017. Stack overflow considered harmful? The impact of copy&paste on Android application security. In Proceedings of the IEEE Symposium on Security and Privacy (SP\u201917). IEEE, 121\u2013136."},{"key":"e_1_3_4_25_2","doi-asserted-by":"crossref","unstructured":"C\u00e9sar Fran\u00e7a F. Da Silva and Helen Sharp. 2018. Motivation and satisfaction of software engineers. IEEE Trans. Softw. Eng. 46 2 (2018) 118\u2013140.","DOI":"10.1109\/TSE.2018.2842201"},{"key":"e_1_3_4_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(09)70019-3"},{"key":"e_1_3_4_27_2","volume-title":"Cybok: The CyberSecurity Body of Knowledge","author":"Gollman Dieter","year":"2019","unstructured":"Dieter Gollman. 2019. Authentication, authorisation & accountability issue 1.0. In Cybok: The CyberSecurity Body of Knowledge. The University of Bristol. Retrieved from https:\/\/www.cybok.org\/knowledgebase\/."},{"key":"e_1_3_4_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.111"},{"key":"e_1_3_4_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9517-1"},{"key":"e_1_3_4_30_2","doi-asserted-by":"publisher","DOI":"10.4324\/9781315146027"},{"key":"e_1_3_4_31_2","volume-title":"Proceedings of the Workshop on Usable Security","author":"Kirlappos Iacovos","year":"2014","unstructured":"Iacovos Kirlappos, Simon Parkin, and M. Angela Sasse. 2014. Learning from shadow security: Why understanding non-compliance provides the basis for effective security. In Proceedings of the Workshop on Usable Security."},{"key":"e_1_3_4_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIS.2019.00012"},{"issue":"1","key":"e_1_3_4_33_2","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1109\/MS.2019.2945300","article-title":"Taking the middle path: Learning about security through online social interaction","volume":"37","author":"Lopez Tamara","year":"2019","unstructured":"Tamara Lopez, Thein T. Tun, Arosha K. Bandara, Mark Levine, Bashar Nuseibeh, and Helen Sharp. 2019. Taking the middle path: Learning about security through online social interaction. IEEE Softw. 37, 1 (2019), 25\u201330.","journal-title":"IEEE Softw."},{"key":"e_1_3_4_34_2","doi-asserted-by":"publisher","DOI":"10.1146\/annurev.an.24.100195.000523"},{"key":"e_1_3_4_35_2","first-page":"24","volume-title":"Multi-sited Ethnography","author":"Marcus George E.","year":"2012","unstructured":"George E. Marcus. 2012. Multi-sited ethnography: Five or six things I know about it now. In Multi-sited Ethnography. Routledge, 24\u201340."},{"key":"e_1_3_4_36_2","doi-asserted-by":"publisher","DOI":"10.4230\/DagRep.9.6.i"},{"key":"e_1_3_4_37_2","volume-title":"Microsoft Security Development Lifecycle","unstructured":"Microsoft. [n.d.]. Microsoft Security Development Lifecycle. Technical Report. Retrieved from https:\/\/www.microsoft.com\/en-us\/securityengineering\/sdl."},{"key":"e_1_3_4_38_2","first-page":"59","volume-title":"Proceedings of the European Symposium on Usable Security","author":"Mokhberi Azadeh","year":"2021","unstructured":"Azadeh Mokhberi and Konstantin Beznosov. 2021. SoK: Human, organizational, and technological dimensions of developers\u2019 challenges in engineering secure software. In Proceedings of the European Symposium on Usable Security. 59\u201375."},{"key":"e_1_3_4_39_2","first-page":"935","volume-title":"Proceedings of the IEEE\/ACM 38th International Conference on Software Engineering (ICSE\u201916)","author":"Nadi S.","year":"2016","unstructured":"S. Nadi, S. Kr\u00fcger, M. Mezini, and E. Bodden. 2016. Jumping through hoops: Why do Java developers struggle with cryptography APIs? In Proceedings of the IEEE\/ACM 38th International Conference on Software Engineering (ICSE\u201916). 935\u2013946."},{"key":"e_1_3_4_40_2","first-page":"311","volume-title":"Proceedings of the ACM CHI Conference on Human Factors in Computing Systems","author":"Naiakshina Alena","year":"2018","unstructured":"Alena Naiakshina, Anastasia Danilova, Eva Gerlitz, Emanuel von Zezschwitz, Matthew Smith, Karoline Busse, Karoline Busse, Dominik Wermke, Sabrina Amft, and Sascha Fahl. 2018. If you want, I can store the encrypted password. A password-storage field study with freelance developers. In Proceedings of the ACM CHI Conference on Human Factors in Computing Systems. USENIX Association, 311\u2013328."},{"key":"e_1_3_4_41_2","first-page":"311","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Naiakshina Alena","year":"2017","unstructured":"Alena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog, Sergej Dechand, and Matthew Smith. 2017. Why do developers get password storage wrong? A qualitative usability study. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. 311\u2013328."},{"key":"e_1_3_4_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664254"},{"key":"e_1_3_4_43_2","first-page":"315","volume-title":"Proceedings of the 14th Symposium on Usable Privacy and Security (SOUPS\u201918)","author":"Oliveira Daniela Seabra","year":"2018","unstructured":"Daniela Seabra Oliveira, Tian Lin, Muhammad Sajidur Rahman, Rad Akefirad, Donovan Ellis, Eliany Perez, Rahul Bobhate, Lois A. DeLong, Justin Cappos, and Yuriy Brun. 2018. API blindspots: Why experienced developers write vulnerable code. In Proceedings of the 14th Symposium on Usable Privacy and Security (SOUPS\u201918). 315\u2013328."},{"key":"e_1_3_4_44_2","first-page":"205","volume-title":"Proceedings of the 16th Symposium on Usable Privacy and Security (SOUPS\u201920)","author":"Palombo Hernan","year":"2020","unstructured":"Hernan Palombo, Armin Ziaie Tabari, Daniel Lende, Jay Ligatti, and Xinming Ou. 2020. An ethnographic understanding of software (in)security and a co-creation model to improve secure software development. In Proceedings of the 16th Symposium on Usable Privacy and Security (SOUPS\u201920). 205\u2013220."},{"key":"e_1_3_4_45_2","doi-asserted-by":"publisher","DOI":"10.1515\/jhsem-2014-0035"},{"key":"e_1_3_4_46_2","first-page":"2489","volume-title":"Proceedings of the ACM Conference on Computer Supported Cooperative Work and Social Computing (CSCW\u201917)","author":"Poller Andreas","year":"2017","unstructured":"Andreas Poller, Laura Kocksch, Sven T\u00fcrpe, Felix Anand Epp, and Katharina Kinder-Kurlanda. 2017. Can security become a routine?: A study of organizational change in an agile software development group. In Proceedings of the ACM Conference on Computer Supported Cooperative Work and Social Computing (CSCW\u201917). ACM, 2489\u20132503."},{"issue":"5","key":"e_1_3_4_47_2","doi-asserted-by":"crossref","first-page":"551","DOI":"10.1016\/j.im.2014.03.009","article-title":"Bridging the divide: A qualitative comparison of information security thought patterns between information security professionals and ordinary organizational insiders","volume":"51","author":"Posey Clay","unstructured":"Clay Posey, Tom L. Roberts, Paul Benjamin Lowry, and Ross T. Hightower. 2014-07-01. Bridging the divide: A qualitative comparison of information security thought patterns between information security professionals and ordinary organizational insiders. Inf. Manag. 51, 5 (2014-07-01), 551\u2013567.","journal-title":"Inf. Manag."},{"issue":"1","key":"e_1_3_4_48_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3471930","article-title":"The case for adaptive security interventions","volume":"31","author":"Rauf Irum","year":"2021","unstructured":"Irum Rauf, Marian Petre, Thein Tun, Tamara Lopez, Paul Lunn, Dirk Van der Linden, John Towse, Helen Sharp, Mark Levine, Awais Rashid, et\u00a0al. 2021. The case for adaptive security interventions. ACM Trans. Softw. Eng. Methodol. 31, 1 (2021), 1\u201352.","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"e_1_3_4_49_2","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781139062367"},{"key":"e_1_3_4_50_2","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/ADC.2005.36","volume-title":"Proceedings of the Agile Development Conference (ADC\u201905)","author":"Robinson Hugh","year":"2005","unstructured":"Hugh Robinson and Helen Sharp. 2005. Organisational culture and XP: Three case studies. In Proceedings of the Agile Development Conference (ADC\u201905). IEEE, 49\u201358."},{"key":"e_1_3_4_51_2","doi-asserted-by":"publisher","DOI":"10.1080\/01449290701494548"},{"key":"e_1_3_4_52_2","volume-title":"Real World Research: A Resource for Users of Social Research Methods in Applied Settings","author":"Robson Colin","year":"2016","unstructured":"Colin Robson and Kieran McCartan. 2016. Real World Research: A Resource for Users of Social Research Methods in Applied Settings. Wiley."},{"key":"e_1_3_4_53_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-008-9102-8"},{"key":"e_1_3_4_54_2","volume-title":"Cybok: The CyberSecurity Body of Knowledge","author":"Sasse M. Angela","year":"2019","unstructured":"M. Angela Sasse and Awais Rashid. 2019. Human factors knowledge area issue 1.0. In Cybok: The CyberSecurity Body of Knowledge. The University of Bristol. Retrieved from https:\/\/www.cybok.org\/knowledgebase\/."},{"issue":"4","key":"e_1_3_4_55_2","first-page":"80","article-title":"Career anchors revisited: Implications for career development in the 21st century","volume":"10","author":"Schein Edgar H.","year":"1996","unstructured":"Edgar H. Schein. 1996. Career anchors revisited: Implications for career development in the 21st century. Acad. Manag. Exec. 10, 4 (1996), 80\u201388.","journal-title":"Acad. Manag. Exec."},{"key":"e_1_3_4_56_2","volume-title":"The Security Mindset - Schneier on Security","author":"Schneier Bruce","year":"2008","unstructured":"Bruce Schneier. 2008. The Security Mindset - Schneier on Security. Retrieved from https:\/\/www.schneier.com\/blog\/archives\/2008\/03\/the_security_mi_1.html."},{"key":"e_1_3_4_57_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2008.05.009"},{"issue":"8","key":"e_1_3_4_58_2","doi-asserted-by":"crossref","first-page":"786","DOI":"10.1109\/TSE.2016.2519887","article-title":"The role of ethnographic studies in empirical software engineering","volume":"42","author":"Sharp H.","unstructured":"H. Sharp, Y. Dittrich, and C. R. B. de Souza. 2016-08. The role of ethnographic studies in empirical software engineering. IEEE Trans. Softw. Eng. 42, 8 (2016-08), 786\u2013804.","journal-title":"IEEE Trans. Softw. Eng."},{"key":"e_1_3_4_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/52.819967"},{"key":"e_1_3_4_60_2","volume-title":"Threat Modeling: Designing for Security","author":"Shostack Adam","year":"2014","unstructured":"Adam Shostack. 2014. Threat Modeling: Designing for Security. John Wiley & Sons."},{"key":"e_1_3_4_61_2","doi-asserted-by":"publisher","DOI":"10.1177\/1466138108099586"},{"key":"e_1_3_4_62_2","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-856x.2005.00204.x"},{"key":"e_1_3_4_63_2","first-page":"221","volume-title":"Proceedings of the 16th Symposium on Usable Privacy and Security (SOUPS\u201920)","author":"Smith Justin","year":"2020","unstructured":"Justin Smith, Lisa Nguyen Quang Do, and Emerson Murphy-Hill. 2020. Why can\u2019t Johnny fix vulnerabilities: A usability evaluation of static analysis tools for security. In Proceedings of the 16th Symposium on Usable Privacy and Security (SOUPS\u201920). 221\u2013238."},{"key":"e_1_3_4_64_2","doi-asserted-by":"crossref","unstructured":"Marius Steffens Christian Rossow Martin Johns and Ben Stock. 2019. Don\u2019t trust the Locals: Investigating the prevalence of persistent client-side cross-site scripting in the wild. Proceedings of the Network and Distributed Systems Security Symposium (NDSS).","DOI":"10.14722\/ndss.2019.23009"},{"key":"e_1_3_4_65_2","first-page":"129","volume-title":"Proceedings of the IEEE European Symposium on Security and Privacy Workshops (EuroS&PW\u201919)","author":"Tahaei Mohammad","year":"2019","unstructured":"Mohammad Tahaei and Kami Vaniea. 2019. A survey on developer-centred security. In Proceedings of the IEEE European Symposium on Security and Privacy Workshops (EuroS&PW\u201919). IEEE, 129\u2013138."},{"key":"e_1_3_4_66_2","first-page":"1","volume-title":"Proceedings of the 14th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM\u201920)","author":"T\u00f8ndel Inger Anne","year":"2020","unstructured":"Inger Anne T\u00f8ndel, Daniela Soares Cruzes, and Martin Gilje Jaatun. 2020. Using situational and narrative analysis for investigating the messiness of software security. In Proceedings of the 14th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM\u201920). 1\u20136."},{"key":"e_1_3_4_67_2","first-page":"617","volume-title":"Proceedings of the 17th Symposium on Usable Privacy and Security (SOUPS\u201921)","author":"Tuladhar Anwesh","year":"2021","unstructured":"Anwesh Tuladhar, Daniel Lende, Jay Ligatti, and Xinming Ou. 2021. An analysis of the role of situated learning in starting a security culture in a software company. In Proceedings of the 17th Symposium on Usable Privacy and Security (SOUPS\u201921). 617\u2013632."},{"key":"e_1_3_4_68_2","article-title":"The impact of surface features on choice of (in)secure answers by Stackoverflow readers","author":"Linden Dirk van der","year":"2020","unstructured":"Dirk van der Linden, Emma Williams, Joseph Hallett, and Awais Rashid. 2020. The impact of surface features on choice of (in)secure answers by Stackoverflow readers. IEEE Trans. Softw. Eng. 48, 2 (2020).","journal-title":"IEEE Trans. Softw. Eng."},{"key":"e_1_3_4_69_2","unstructured":"Andrew van der Stock Brian Glas Neil Smithline and Torsten Gigler. 2017. OWASP Top 10-2017 the Ten Most Critical Web Application Security Risks. Technical Report. The Open Web Application Security Project (OWASP) Foundation. Retrieved from https:\/\/owasp.org\/www-project-top-ten\/2017\/."},{"key":"e_1_3_4_70_2","doi-asserted-by":"crossref","DOI":"10.7208\/chicago\/9780226849638.001.0001","volume-title":"Tales of the Field: On Writing Ethnography","author":"Maanen John Van","year":"2011","unstructured":"John Van Maanen. 2011. Tales of the Field: On Writing Ethnography. University of Chicago Press."},{"key":"e_1_3_4_71_2","first-page":"21","volume-title":"Proceedings of the IEEE\/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice","author":"Weir Charles","year":"2021","unstructured":"Charles Weir, Ingolf Becker, and James Blair, Lynne. 2021. A passion for security: Intervening to help software developers. In Proceedings of the IEEE\/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice. IEEE, 21\u201330."},{"key":"e_1_3_4_72_2","volume-title":"Proceedings of the 12th Symposium on Usable Privacy and Security (SOUPS\u201916)","author":"Weir Charles","year":"2016","unstructured":"Charles Weir, Awais Rashid, and James Noble. 2016. How to improve the security skills of mobile app developers? Comparing and contrasting expert views. In Proceedings of the 12th Symposium on Usable Privacy and Security (SOUPS\u201916)."},{"key":"e_1_3_4_73_2","unstructured":"Etienne Wenger Beverly Traynor and Maarten de Laat. 2011. Promoting and assessing value creation in communities and networks: A conceptual framework. Number 18. Ruud de Moor Centrum Open University of the Netherlands 1\u201356. https:\/\/scholar.google.com\/scholar?start=10&hl=en&as_sdt=0 5&cluster=2965781421348501944."},{"key":"e_1_3_4_74_2","doi-asserted-by":"publisher","DOI":"10.1145\/2663887.2663898"},{"key":"e_1_3_4_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/2531602.2531722"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3563211","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3563211","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:38:10Z","timestamp":1750178290000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3563211"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,26]]},"references-count":74,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,7,31]]}},"alternative-id":["10.1145\/3563211"],"URL":"https:\/\/doi.org\/10.1145\/3563211","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4,26]]},"assertion":[{"value":"2021-05-19","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-08-24","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-04-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}