2021/04/07 by Vivek B. Arora, Enrique Larios Vargas, Arora, Vivek +6 · 1 citation
Computer Science · #Advanced Malware Detection Techniques #FOS: Computer and information sciences #Information and Cyber Security #Software Engineering (cs.SE) #Software Engineering Research
paper · pdf · doi:10.48550/arxiv.2104.03476
openalex publication_date 2021/04/07 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28
Secure software engineering is a fundamental activity in modern software\ndevelopment. However, while the field of security research has been advancing\nquite fast, in practice, there is still a vast knowledge gap between the\nsecurity experts and the software development teams. After all, we cannot\nexpect developers and other software practitioners to be security experts.\nUnderstanding how software development teams incorporate security in their\nprocesses and the challenges they face is a step towards reducing this gap. In\nthis paper, we study how financial services companies ensure the security of\ntheir software systems. To that aim, we performed a qualitative study based on\nsemi-structured interviews with 16 software practitioners from 11 different\nfinancial companies in three continents. Our results shed light on the security\nconsiderations that practitioners take during the different phases of their\nsoftware development processes, the different security practices that software\nteams make use of to ensure the security of their software systems, the\nimprovements that practitioners perceive as important in existing\nstate-of-the-practice security tools, the different knowledge-sharing and\nlearning practices that developers use to learn more about software security,\nand the challenges that software practitioners currently face when it comes to\nsecure their systems.\n