Building and Validating a Scale for Secure Software Development Self-Efficacy
Daniel Votipka, Desiree Abrokwa, Michelle L. Mazurek
Abstract
Security is an essential component of the software development lifecycle. Researchers and practitioners have developed educational interventions, guidelines, security analysis tools, and new APIs aimed at improving security. However, measuring any resulting improvement in secure development skill is challenging. As a proxy for skill, we propose to measure self-efficacy, which has been shown to correlate with skill in other contexts. Here, we present a validated scale measuring secure software-development self-efficacy (SSD-SES). We first reviewed popular secure-development frameworks and surveyed 22 secure-development experts to identify 58 unique tasks. Next, we asked 311 developers - over multiple rounds - to rate their skill at each task. We iteratively updated our questions to ensure they were easily understandable, showed adequate variance between participants, and demonstrated reliability. Our final 15-item scale contains two sub-scales measuring belief in ability to perform vulnerability identification and mitigation as well as security communications tasks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers20
- Recruiting Participants With Programming Skills: A Comparison of Four Crowdsourcing Platforms and a CS Student Mailing ListMohammad Tahaei, Kami VanieaCHI 2022 · 45 citations
- Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy RamificationsMohammad Tahaei, Ruba Abu-Salma, Awais RashidCHI 2023 · 36 citations
- Security Notifications in Static Analysis Tools: Developers' Attitudes, Comprehension, and Ability to Act on ThemMohammad Tahaei, Kami Vaniea, Konstantin Beznosov, Maria K. WoltersCHI 2021 · 35 citations
- Factors of Haptic Experience across Multiple Haptic ModalitiesAhmed Anwar, Tianzheng Shi, Oliver SchneiderCHI 2023 · 32 citations
- Using AI Assistants in Software Development: A Qualitative Study on Security Practices and ConcernsJan H. Klemmer, Stefan Albert Horstmann, Nikhil Patnaik, Cordelia Ludden et al.CCS 2024 · 14 citations
Related papers
- Self-Efficacy and Security Behavior: Results from a Systematic Review of Research MethodsNele Borgert, Luisa Jansen, Imke Böse, Jennifer Friedauer et al.CHI 2024 · 19 citations
- Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the MoonIta Ryan, Utz Roedig, Klaas-Jan StolICSE 2023 · 13 citations
- Home Is Where the Smart Is: Development and Validation of the Cybersecurity Self-Efficacy in Smart Homes (CySESH) ScaleNele Borgert, Oliver D. Reithmaier, Luisa Jansen, Larina Hillemann et al.CHI 2023 · 6 citations
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl et al.USENIX Security 2025
- Understanding security mistakes developers make: Qualitative analysis from Build It, Break It, Fix ItDaniel Votipka, Kelsey R. Fulton, James Parker, Matthew Hou et al.USENIX Security 2020
