{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T16:23:53Z","timestamp":1747153433711,"version":"3.40.5"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031613814"},{"type":"electronic","value":"9783031613821"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-61382-1_6","type":"book-chapter","created":{"date-parts":[[2024,6,1]],"date-time":"2024-06-01T01:06:11Z","timestamp":1717203971000},"page":"84-97","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Training and Security Awareness Under the Lens of Practitioners: A DevSecOps Perspective Towards Risk Management"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8060-5672","authenticated-orcid":false,"given":"Xhesika","family":"Ramaj","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5102-1122","authenticated-orcid":false,"given":"Mary","family":"S\u00e1nchez-Gord\u00f3n","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1555-9726","authenticated-orcid":false,"given":"Ricardo","family":"Colomo-Palacios","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7304-3835","authenticated-orcid":false,"given":"Vasileios","family":"Gkioulos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,6,1]]},"reference":[{"key":"6_CR1","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1109\/MS.2017.3571578","volume":"34","author":"K Carter","year":"2017","unstructured":"Carter, K.: Francois Raynaud on DevSecOps. IEEE Softw. 34, 93\u201396 (2017). https:\/\/doi.org\/10.1109\/MS.2017.3571578","journal-title":"IEEE Softw."},{"key":"6_CR2","unstructured":"Communication from the Commission to the Council and the European Parliament - Critical Infrastructure Protection in the fight against terrorism. https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex%3A52004DC0702. Accessed 28 Jan 2024"},{"key":"6_CR3","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1109\/MITP.2020.2966614","volume":"22","author":"MR Fox","year":"2020","unstructured":"Fox, M.R.: IT governance in a DevOps world. IT Prof. 22, 54\u201361 (2020). https:\/\/doi.org\/10.1109\/MITP.2020.2966614","journal-title":"IT Prof."},{"key":"6_CR4","doi-asserted-by":"publisher","unstructured":"Mohan, V., Othmane, L.B.: SecDevOps: is it a marketing buzzword? - Mapping research on security in DevOps. In: 2016 11th International Conference on Availability, Reliability and Security (ARES), pp. 542\u2013547. IEEE, Salzburg, Austria (2016). https:\/\/doi.org\/10.1109\/ARES.2016.92","DOI":"10.1109\/ARES.2016.92"},{"key":"6_CR5","doi-asserted-by":"publisher","unstructured":"Aldawood, H., Skinner, G.: Educating and raising awareness on cyber security social engineering: a literature review. In: 2018 IEEE International Conference on Teaching, Assessment, and Learning for Engineering (TALE), pp. 62\u201368 (2018). https:\/\/doi.org\/10.1109\/TALE.2018.8615162","DOI":"10.1109\/TALE.2018.8615162"},{"key":"6_CR6","doi-asserted-by":"publisher","unstructured":"Zeeshan, A.A.: Compliance and security. In: Zeeshan, A.A. (ed.) DevSecOps for .NET core: securing modern software applications, pp. 265\u2013278. Apress, Berkeley, CA (2020). https:\/\/doi.org\/10.1007\/978-1-4842-5850-7_7","DOI":"10.1007\/978-1-4842-5850-7_7"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Naidoo, R., M\u00f6ller, N.: Building software applications securely with DevSecOps: a socio- technical perspective. In: Proceedings of the 21st European Conference on Cyber Warfare and Security. Academic Conferences and Publishing Limited, UK (2022)","DOI":"10.34190\/eccws.21.1.295"},{"key":"6_CR8","unstructured":"2023 State of Platform Engineering Report | Puppet by Perforce. https:\/\/www.puppet.com\/resources\/state-of-platform-engineering. Accessed 26 Jan 2024"},{"key":"6_CR9","doi-asserted-by":"publisher","unstructured":"Smeds, J., Nybom, K., Porres, I.: DevOps: a definition and perceived adoption impediments. In: Lassenius, C., Dings\u00f8yr, T., Paasivaara, M. (eds.) Agile Processes in Software Engineering and Extreme Programming, vol. 212, pp. 166\u2013177. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-18612-2_14","DOI":"10.1007\/978-3-319-18612-2_14"},{"key":"6_CR10","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1049\/sfw2.12132","volume":"17","author":"X Zhou","year":"2023","unstructured":"Zhou, X., et al.: Revisit security in the era of DevOps: an evidence-based inquiry into DevSecOps industry. IET Softw. 17, 435\u2013454 (2023). https:\/\/doi.org\/10.1049\/sfw2.12132","journal-title":"IET Softw."},{"key":"6_CR11","doi-asserted-by":"publisher","unstructured":"S\u00e1nchez-Gord\u00f3n, M., Colomo-Palacios, R.: Security as culture: a systematic literature review of DevSecOps. In: Proceedings of the IEEE\/ACM 42nd International Conference on Software Engineering Workshops, pp. 266\u2013269. Association for Computing Machinery, New York, NY, USA (2020). https:\/\/doi.org\/10.1145\/3387940.3392233","DOI":"10.1145\/3387940.3392233"},{"key":"6_CR12","doi-asserted-by":"publisher","unstructured":"Morales, J.A., Yasar, H.: Experiences with secure pipelines in highly regulated environments. In: Proceedings of the 18th International Conference on Availability, Reliability and Security, pp. 1\u20139. Association for Computing Machinery, New York, NY, USA (2023). https:\/\/doi.org\/10.1145\/3600160.3605466","DOI":"10.1145\/3600160.3605466"},{"key":"6_CR13","unstructured":"The 2021 State of DevOps Report | Puppet by Perforce. https:\/\/www.puppet.com\/resources\/state-of-devops-report. Accessed 27 Oct 2023"},{"key":"6_CR14","doi-asserted-by":"publisher","first-page":"590","DOI":"10.1007\/978-3-319-49094-6_44","volume-title":"Product-Focused Software Process Improvement","author":"L Riungu-Kalliosaari","year":"2016","unstructured":"Riungu-Kalliosaari, L., M\u00e4kinen, S., Lwakatare, L.E., Tiihonen, J., M\u00e4nnist\u00f6, T.: DevOps adoption benefits and challenges in practice: a case study. In: Abrahamsson, P., Jedlitschka, A., Nguyen Duc, A., Felderer, M., Amasaki, S., Mikkonen, T. (eds.) Product-Focused Software Process Improvement. LNCS, vol. 10027, pp. 590\u2013597. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-49094-6_44"},{"key":"6_CR15","doi-asserted-by":"publisher","unstructured":"Mohan, V., ben Othmane, L., Kres, A.: BP: security concerns and best practices for automation of software deployment processes: an industrial case study. In: 2018 IEEE Cybersecurity Development (SecDev), pp. 21\u201328 (2018). https:\/\/doi.org\/10.1109\/SecDev.2018.00011","DOI":"10.1109\/SecDev.2018.00011"},{"key":"6_CR16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101967","volume":"97","author":"R Kumar","year":"2020","unstructured":"Kumar, R., Goyal, R.: Modeling continuous security: a conceptual model for automated DevSecOps using open-source software over cloud (ADOC). Comput. Secur. 97, 101967 (2020). https:\/\/doi.org\/10.1016\/j.cose.2020.101967","journal-title":"Comput. Secur."},{"key":"6_CR17","volume-title":"Overcoming DevSecOps Challenges: A Practical Guide for All Stakeholders","author":"H Yasar","year":"2020","unstructured":"Yasar, H.: Overcoming DevSecOps Challenges: A Practical Guide for All Stakeholders. Carnegie Mellon University, Pittsburgh, PA, USA (2020)"},{"key":"6_CR18","doi-asserted-by":"crossref","unstructured":"Ramaj, X., S\u00e1nchez-Gord\u00f3n, M., Chockalingam, S., Colomo-Palacios, R.: Unveiling the safety aspects of DevSecOps: evolution, gaps and trends. Recent Adv. Comput. Sci. Commun. 16, 61\u201369 (2023)","DOI":"10.2174\/2666255816666220804143918"},{"key":"6_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.accinf.2022.100560","volume":"45","author":"OH Plant","year":"2022","unstructured":"Plant, O.H., van Hillegersberg, J., Aldea, A.: Rethinking IT governance: designing a framework for mitigating risk and fostering internal control in a DevOps environment. Int. J. Account. Inf. Syst. 45, 100560 (2022). https:\/\/doi.org\/10.1016\/j.accinf.2022.100560","journal-title":"Int. J. Account. Inf. Syst."},{"key":"6_CR20","doi-asserted-by":"publisher","unstructured":"Yasar, H.: Implementing secure DevOps assessment for highly regulated environments. In: Proceedings of the 12th International Conference on Availability, Reliability and Security, pp. 1\u20133. Association for Computing Machinery, New York, NY, USA (2017). https:\/\/doi.org\/10.1145\/3098954.3105819","DOI":"10.1145\/3098954.3105819"},{"key":"6_CR21","doi-asserted-by":"publisher","unstructured":"Ramaj, X., Colomo-Palacios, R., S\u00e1nchez-Gord\u00f3n, M., Gkioulos, V.: Towards a DevSecOps-enabled framework for risk management of critical infrastructures. In: Yilmaz, M., Clarke, P., Riel, A., Messnarz, R. (eds.) EuroSPI 2023. CCIS, vol. 1890, pp. 47\u201358. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-42307-9_4","DOI":"10.1007\/978-3-031-42307-9_4"},{"key":"6_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106700","volume":"141","author":"RN Rajapakse","year":"2022","unstructured":"Rajapakse, R.N., Zahedi, M., Babar, M.A., Shen, H.: Challenges and solutions when adopting DevSecOps: a systematic review. Inf. Softw. Technol. 141, 106700 (2022). https:\/\/doi.org\/10.1016\/j.infsof.2021.106700","journal-title":"Inf. Softw. Technol."},{"key":"6_CR23","doi-asserted-by":"publisher","first-page":"393","DOI":"10.1002\/job.1897","volume":"35","author":"SY Sung","year":"2014","unstructured":"Sung, S.Y., Choi, J.N.: Do organizations spend wisely on employees? Effects of training and development investments on learning and innovation in organizations. J. Organ. Behav. 35, 393\u2013412 (2014). https:\/\/doi.org\/10.1002\/job.1897","journal-title":"J. Organ. Behav."},{"key":"6_CR24","doi-asserted-by":"publisher","first-page":"697","DOI":"10.1108\/ICS-07-2020-0121","volume":"29","author":"N Chowdhury","year":"2021","unstructured":"Chowdhury, N., Gkioulos, V.: Key competencies for critical infrastructure cyber-security: a systematic literature review. Inf. Comput. Secur. 29, 697\u2013723 (2021). https:\/\/doi.org\/10.1108\/ICS-07-2020-0121","journal-title":"Inf. Comput. Secur."},{"key":"6_CR25","doi-asserted-by":"publisher","unstructured":"Nurse, J.R.C.: Cybersecurity awareness. In: Jajodia, S., Samarati, P., Yung, M. (eds.) Encyclopedia of Cryptography, Security and Privacy, pp. 1\u20134. Springer, Heidelberg (2019). https:\/\/doi.org\/10.1007\/978-3-642-27739-9_1596-1","DOI":"10.1007\/978-3-642-27739-9_1596-1"},{"key":"6_CR26","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-50","author":"M Wilson","year":"2003","unstructured":"Wilson, M., Hash, J.: Building an information technology security awareness and training program. Nat. Inst. Stand. Technol. (2003). https:\/\/doi.org\/10.6028\/NIST.SP.800-50","journal-title":"Nat. Inst. Stand. Technol."},{"key":"6_CR27","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1145\/505532.505535","volume":"26","author":"SL Pfleeger","year":"2001","unstructured":"Pfleeger, S.L., Kitchenham, B.A.: Principles of survey research: Part 1: turning lemons into lemonade. SIGSOFT Softw. Eng. Notes. 26, 16\u201318 (2001). https:\/\/doi.org\/10.1145\/505532.505535","journal-title":"SIGSOFT Softw. Eng. Notes."},{"key":"6_CR28","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1145\/566493.566495","volume":"27","author":"BA Kitchenham","year":"2002","unstructured":"Kitchenham, B.A., Pfleeger, S.L.: Principles of survey research Part 2: designing a survey. SIGSOFT Softw. Eng. Notes. 27, 18\u201320 (2002). https:\/\/doi.org\/10.1145\/566493.566495","journal-title":"SIGSOFT Softw. Eng. Notes."},{"key":"6_CR29","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1145\/511152.511155","volume":"27","author":"BA Kitchenham","year":"2002","unstructured":"Kitchenham, B.A., Pfleeger, S.L.: Principles of survey research: Part 3: constructing a survey instrument. SIGSOFT Softw. Eng. Notes. 27, 20\u201324 (2002). https:\/\/doi.org\/10.1145\/511152.511155","journal-title":"SIGSOFT Softw. Eng. Notes."},{"key":"6_CR30","unstructured":"Ramaj, X., S\u00e1nchez-Gord\u00f3n, M., Colomo-Palacios, R., Vasileios, G.: Training and security awareness under the lens of practitioners: a DevSecOps perspective towards risk management - online appendix. https:\/\/figshare.com\/s\/d9c8a3a70684b0288c10. Accessed 3 Feb 2024"},{"key":"6_CR31","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1145\/638574.638580","volume":"27","author":"B Kitchenham","year":"2002","unstructured":"Kitchenham, B., Pfleeger, S.L.: Principles of survey research Part 4: questionnaire evaluation. SIGSOFT Softw. Eng. Notes. 27, 20\u201323 (2002). https:\/\/doi.org\/10.1145\/638574.638580","journal-title":"SIGSOFT Softw. Eng. Notes."},{"key":"6_CR32","doi-asserted-by":"publisher","unstructured":"Kitchenham, B., Pfleeger, S.: Principles of survey research: Part 5: populations and samples. ACM SIGSOFT Softw. Eng. Notes. 27 (2002). https:\/\/doi.org\/10.1145\/571681.571686","DOI":"10.1145\/571681.571686"},{"key":"6_CR33","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1145\/638750.638758","volume":"28","author":"B Kitchenham","year":"2003","unstructured":"Kitchenham, B., Pfleeger, S.L.: Principles of survey research Part 6: data analysis. SIGSOFT Softw. Eng. Notes. 28, 24\u201327 (2003). https:\/\/doi.org\/10.1145\/638750.638758","journal-title":"SIGSOFT Softw. Eng. Notes."}],"container-title":["Lecture Notes in Computer Science","HCI for Cybersecurity, Privacy and Trust"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-61382-1_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,1]],"date-time":"2024-06-01T01:53:08Z","timestamp":1717206788000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-61382-1_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031613814","9783031613821"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-61382-1_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"1 June 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"HCII","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Human-Computer Interaction","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Washington DC","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 June 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 July 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"hcii2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2024.hci.international\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}