Publicação em atas de evento científico
Raising awareness in the industry on secure code review practices
Andrei-Cristian Iosif (Iosif, A.-C.); Tiago Espinha Gasiba (Gasiba, T. E.); Ulrike Lechner (Lechner, U.); Maria Pinto-Albuquerque (Pinto-Albuquerque, M.);
CYBER 2023: The Eighth International Conference on Cyber-Technologies and Cyber-Systems
Ano (publicação definitiva)
2023
Língua
Inglês
País
--
Mais Informação
Web of Science®

Esta publicação não está indexada na Web of Science®

Scopus

Esta publicação não está indexada na Scopus

Google Scholar

N.º de citações: 0

(Última verificação: 2024-04-26 10:50)

Ver o registo no Google Scholar

Abstract/Resumo
As products and services become increasingly digital and software increasingly complex, all aspects of an industrial software development lifecycle must contribute to quality. Code review serves as a means to address software quality and fosters knowledge exchange across teams. Nonetheless, code review practices require resources and often require more resources than planned, while the benefit of a code review to code quality is less tangible. In our work, we address the effectiveness and efficiency of code review practices and develop an understanding of what is a good and valuable code review practice as part of a software development lifecycle. Our focus is code reviews meant to identify and address security weaknesses in an industrial context. This work presents a design study on how to design a workshop on code review. We conducted and evaluated three workshops with 37 industrial software developers. The findings of our work reveal that presenting constructive code review practices can contribute to raising awareness of secure coding and software lifecycle practices among software development professionals. This contributes to the quality and, in particular, security of software.
Agradecimentos/Acknowledgements
Maria Pinto-Albuquerque thanks the Instituto Universitário de Lisboa and ISTAR, for their support. The authors would like to thank Anton Bartl for the useful discussions and provision of the original starting idea for the vulnerable code snippet used...
Palavras-chave
Code review,Cybersecurity,Compliance,Development lifecycle,Quality,Standards
Prémios
Prémio de Melhor Artigo
Registos de financiamentos
Referência de financiamento Entidade Financiadora
UIDB/04466/2020 Fundação para a Ciência e a Tecnologia
13N16585 German Federal Ministry of Education and Research
13N16581 German Federal Ministry of Education and Research
UIDP/04466/2020 Fundação para a Ciência e a Tecnologia
Projetos Relacionados

Esta publicação é um output do(s) seguinte(s) projeto(s):