No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
Raha Asadi, Bodil Biering, Vincent van Dijk, Oksana Kulyk, Elda Paja
摘要
Software developing small and medium enterprises (SMEs) play a crucial role as suppliers to larger corporations and public administration.It is therefore necessary for them to be able to demonstrate that their products meet certain security criteria, both to gain trust of their customers and to comply to standards that demand such a demonstration.In this study we have investigated ways for SMEs to demonstrate their security when operating in a business-tobusiness model, conducting semi-structured interviews (𝑁 = 16) with practitioners from different SMEs in Denmark and validating our findings in a follow-up workshop (𝑁 = 6).Our findings indicate five distinctive security demonstration approaches, namely: Certifications, Reports, Questionnaires, Interactive Sessions and Social Proof.We discuss the challenges, benefits, and recommendations related to these approaches, concluding that none of them is a one-size-fits all solution and that more research into relative advantages of these approaches and their combinations is needed. CCS Concepts• Security and privacy → Social aspects of security and privacy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper3
- Is a Trustmark and QR Code Enough? The Effect of IoT Security and Privacy Label Information Complexity on Consumer Comprehension and BehaviorClaire C. Chen, Dillon Shu, Hamsini Ravishankar, Xinran Li 等CHI 2024 · 被引用 27 次
- Comparing the Use and Usefulness of Four IoT Security LabelsPeter J. Caven, Zitao Zhang, Jacob Abbott, Xinyao Ma 等CHI 2024 · 被引用 15 次
- Not as easy as just update: Survey of System Administrators and Patching BehavioursAdam D. G. Jenkins, Linsen Liu, Maria K. Wolters, Kami VanieaCHI 2024 · 被引用 10 次
相关 Paper
- The Mundane Art of Cybersecurity: Living with Insecure IT in Danish Small- and Medium-Sized EnterprisesLaura Kocksch, Torben Elgaard JensenCSCW 2024 · 被引用 5 次
- 'It's Confusing, Insecure, and Messy' - Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence SectorJudith Kankam-Boateng, Marco Peressotti, Jan Stentoft, Kent Adsbøll Wickstrøm 等CHI 2026 · 被引用 2 次
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke 等USENIX Security 2021 · 被引用 30 次
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky 等S&P 2024 · 被引用 21 次
- "My Privacy for their Security": Employees' Privacy Perspectives and Expectations when using Enterprise Security SoftwareJonah Stegman, Patrick J. Trottier, Caroline Hillier, Hassan Khan 等USENIX Security 2023
