How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview Study

被引:0
|
作者
Gutfleisch, Marco [1 ]
Klemmer, Jan H. [2 ]
Busch, Niklas [2 ]
Acar, Yasemin [3 ]
Sasse, M. Angela [1 ]
Fahl, Sascha [2 ,4 ]
机构
[1] Ruhr Univ Bochum, Bochum, Germany
[2] Leibniz Univ Hannover, Hannover, Germany
[3] Max Planck Inst Secur & Privacy, Bochum, Germany
[4] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
来源
43RD IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2022) | 2022年
关键词
USABILITY; DEVELOPERS; NEED;
D O I
10.1109/SP46214.2022.00011
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
For software to be secure in practice, users need to be willing and able to appropriately use security features. These features are usually implemented by software professionals during the software development process (SDP), who may be unable to consider the usability of these mechanisms. While research has made progress in supporting developers in creating secure software products, very little attention has been paid to whether and how these security features are made usable. In a semi-structured interview study with 25 software professionals (software developers, designers, architects), we explored how they and other decision-makers encounter and deal with security and usability during the software development process in their companies. Based on 37 hours of interview recordings, we qualitatively analyzed and investigated 23 distinct development contexts in detail. In addition to individual awareness and factors that directly influence the implementation phase, we identify a high impact of contextual factors, such as stakeholder pressure, presence of expertise, and collaboration culture, and the specific implementation of the SDP on usable security in software products. We conclude our work by highlighting important gaps, such as studying and improving contextual factors that contribute to usable security and discussing potential improvements of the status quo.
引用
收藏
页码:893 / 910
页数:18
相关论文
共 50 条
  • [41] HOW DOES FEELING INFORMED RELATE TO BEING INFORMED? RESULTS FROM THE DECISIONS STUDY
    Sepucha, Karen R.
    Fagerlin, Angela
    Couper, Mick P.
    Levin, Carrie A.
    Singer, Eleanor
    Zikmund-Fisher, Brian J.
    ANNALS OF BEHAVIORAL MEDICINE, 2011, 41 : S151 - S151
  • [42] How can end of life care excellence be normalized in hospitals? Lessons from a qualitative framework study
    Christy Noble
    Laurie Grealish
    Andrew Teodorczuk
    Brenton Shanahan
    Balaji Hiremagular
    Jodie Morris
    Sarah Yardley
    BMC Palliative Care, 17
  • [43] How can end of life care excellence be normalized in hospitals? Lessons from a qualitative framework study
    Noble, Christy
    Grealish, Laurie
    Teodorczuk, Andrew
    Shanahan, Brenton
    Hiremagular, Balaji
    Morris, Jodie
    Yardley, Sarah
    BMC PALLIATIVE CARE, 2018, 17
  • [44] How Good are Code Smells for Evaluating Software Maintainability? - Results from a Comparative Case Study
    Yamashita, Aiko
    2013 29TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE (ICSM), 2013, : 566 - 571
  • [45] Communication with relatives in the context of postmortem organ donation from the perspective of physicians and nurses: results of a qualitative interview study from Austria
    Posch, Christiane
    Flatscher-Thoeni, Magdalena
    ETHIK IN DER MEDIZIN, 2024, 36 (02) : 133 - 150
  • [46] What prevention potential does the general practitioner setting offer for family caregivers?-findings from a qualitative interview study
    Wangler, Julian
    Jansky, Michael
    WIENER MEDIZINISCHE WOCHENSCHRIFT, 2024, 174 (3-4) : 35 - 43
  • [47] How do Mothers and Fathers Suffering from Schizophrenia Experience their Parenthood? Results from an In-Depth Interview Study
    Jungbauer, Johannes
    Stelling, Kirsten
    Kuhn, Juliane
    Lenz, Albert
    PSYCHIATRISCHE PRAXIS, 2010, 37 (05) : 233 - 239
  • [48] How Does Functional Neurodiagnostics Inform Surrogate Decision-Making for Patients with Disorders of Consciousness? A Qualitative Interview Study with Patients' Next of Kin
    Schembs, Leah
    Ruhfass, Maria
    Racine, Eric
    Jox, Ralf J.
    Bender, Andreas
    Rosenfelder, Martin
    Kuehlmeyer, Katja
    NEUROETHICS, 2021, 14 (03) : 327 - 346
  • [49] How does the COVID-19 pandemic affect the personal lives and care realities of people with a schizophrenia spectrum disorder? A qualitative interview study
    Kaltenboeck, Alexander
    Millinger, Filipe Portela
    Stadtmann, Sarah
    Schmid, Christine
    Amering, Michaela
    Vogl, Susanne
    Fellinger, Matthaeus
    INTERNATIONAL JOURNAL OF SOCIAL PSYCHIATRY, 2023, 69 (05) : 1239 - 1249
  • [50] How Does Functional Neurodiagnostics Inform Surrogate Decision-Making for Patients with Disorders of Consciousness? A Qualitative Interview Study with Patients’ Next of Kin
    Leah Schembs
    Maria Ruhfass
    Eric Racine
    Ralf J. Jox
    Andreas Bender
    Martin Rosenfelder
    Katja Kuehlmeyer
    Neuroethics, 2021, 14 : 327 - 346