{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T02:46:11Z","timestamp":1784342771894,"version":"3.55.0"},"reference-count":69,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2022,12,24]],"date-time":"2022-12-24T00:00:00Z","timestamp":1671840000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,12,24]],"date-time":"2022-12-24T00:00:00Z","timestamp":1671840000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/S035362\/1"],"award-info":[{"award-number":["EP\/S035362\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2023,3]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Evidence from data breach reports shows that many competent software development teams still do not implement secure, privacy-preserving software, even though techniques to do so are now well-known. A major factor causing this is simply a lack of priority and resources for security, as decided by product managers. So, how can we help developers and product managers to work together to achieve appropriate decisions on security and privacy issues? This paper explores using structured workshops to support teams of developers in engaging product managers with software security and privacy, even in the absence of security professionals. The research used the Design Based Research methodology. This paper describes and justifies our workshop design and implementation, and describes our thematic coding of both participant interviews and workshop discussions to quantify and explore the workshops\u2019 effectiveness. Based on trials in eight organizations, involving 88 developers, we found the workshops effective in helping development teams to identify, promote, and prioritize security issues with product managers. Comparisons between organizations suggested that such workshops are most effective with groups with limited security expertise, and when led by the development team leaders. We also found workshop participants needed minimal guidance to identify security threats, and a wide range of ways to promote possible security improvements. Empowering developers and product managers in this way offers a powerful grassroots approach to improve software security worldwide.<\/jats:p>","DOI":"10.1007\/s10664-022-10252-0","type":"journal-article","created":{"date-parts":[[2022,12,24]],"date-time":"2022-12-24T07:02:36Z","timestamp":1671865356000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Incorporating software security: using developer workshops to engage product managers"],"prefix":"10.1007","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3051-4195","authenticated-orcid":false,"given":"Charles","family":"Weir","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3963-4743","authenticated-orcid":false,"given":"Ingolf","family":"Becker","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7515-8908","authenticated-orcid":false,"given":"Lynne","family":"Blair","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,12,24]]},"reference":[{"key":"10252_CR1","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/s00766-016-0258-2","volume":"23","author":"T Ambreen","year":"2018","unstructured":"Ambreen T, Ikram N, Usman M, Niazi M (2018) Empirical research in requirements engineering: trends and opportunities. Requir Eng 23:63\u201395. https:\/\/doi.org\/10.1007\/s00766-016-0258-2","journal-title":"Requir Eng"},{"key":"10252_CR2","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1145\/2535813.2535823","volume":"2013","author":"D Ashenden","year":"2013","unstructured":"Ashenden D, Lawrence D (2013) Can we sell security like soap? A new approach to behaviour change. New Secur Paradigms Work 2013:87\u201394. https:\/\/doi.org\/10.1145\/2535813.2535823","journal-title":"New Secur Paradigms Work"},{"key":"10252_CR3","doi-asserted-by":"publisher","unstructured":"Assal H, Chiasson S (2019) Think secure from the beginning: a survey with software developers. In: conference on human factors in computing systems (CHI). ACM. https:\/\/doi.org\/10.1145\/3290605.3300519","DOI":"10.1145\/3290605.3300519"},{"key":"10252_CR4","doi-asserted-by":"publisher","DOI":"10.4324\/9780203701010","volume-title":"Design research in education: a practical guide for early career researchers","author":"A Bakker","year":"2018","unstructured":"Bakker A (2018) Design research in education: a practical guide for early career researchers. Routledge, Abingdon"},{"issue":"1","key":"10252_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1207\/s15327809jls1301_1","volume":"13","author":"S Barab","year":"2004","unstructured":"Barab S, Squire K (2004) Design-based research: putting a stake in the ground. J learn Sci 13(1):1\u201314. https:\/\/doi.org\/10.1207\/s15327809jls1301_1","journal-title":"J learn Sci"},{"key":"10252_CR6","doi-asserted-by":"crossref","unstructured":"Barbacci MR, Ellison R, Weinstock CB, Wood WG (2000) Quality attribute workshop participants handbook","DOI":"10.21236\/ADA455616"},{"key":"10252_CR7","unstructured":"Beck K, Fowler M (2001) Planning extreme programming. Addison-Wesley Professional"},{"key":"10252_CR8","doi-asserted-by":"publisher","unstructured":"Becker I, Parkin S, Sasse MA (2017) Finding security champions in blends of Organisational culture. In: European workshop on usable security \u2013 EuroUSEC. https:\/\/doi.org\/10.14722\/eurousec.2017.23007","DOI":"10.14722\/eurousec.2017.23007"},{"key":"10252_CR9","doi-asserted-by":"publisher","first-page":"860","DOI":"10.1016\/j.infsof.2007.09.004","volume":"50","author":"S Beecham","year":"2008","unstructured":"Beecham S, Baddoo N, Hall T (2008) Motivation in software engineering: a systematic literature review. Inf Softw Technol 50:860\u2013878. https:\/\/doi.org\/10.1016\/j.infsof.2007.09.004","journal-title":"Inf Softw Technol"},{"key":"10252_CR10","volume-title":"Agile application security: enabling security in a continuous delivery pipeline","author":"L Bell","year":"2017","unstructured":"Bell L, Brunton-Spall M, Smith R, Bird J (2017) Agile application security: enabling security in a continuous delivery pipeline. O\u2019Reilly, Sebastopol, CA"},{"key":"10252_CR11","unstructured":"Beyer M, Ahmed S, Doerlemann K, Arnell S, Parkin S, Sasse A, Passingham N (2015) Awareness is only the first step: a framework for progressive engagement of staff in cyber security. Business white paper: Hewlett Packard"},{"key":"10252_CR12","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1207\/s15327809jls0202_2","volume":"2","author":"AL Brown","year":"1992","unstructured":"Brown AL (1992) Design experiments: theoretical and methodological challenges in creating complex interventions in classroom settings. J Learn Sci 2:141\u2013178. https:\/\/doi.org\/10.1207\/s15327809jls0202_2","journal-title":"J Learn Sci"},{"key":"10252_CR13","doi-asserted-by":"publisher","first-page":"103389","DOI":"10.1016\/j.csi.2019.103389","volume":"69","author":"FA Bukhsh","year":"2020","unstructured":"Bukhsh FA, Bukhsh ZA, Daneva M (2020) A systematic literature review on requirement prioritization techniques and their empirical evaluation. Comput Stand Interfaces 69:103389. https:\/\/doi.org\/10.1016\/j.csi.2019.103389","journal-title":"Comput Stand Interfaces"},{"key":"10252_CR14","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1109\/MSP.2016.95","volume":"14","author":"DD Caputo","year":"2016","unstructured":"Caputo DD, Pfleeger SL, Sasse MA, Ammann P, Offutt J, Deng L (2016) Barriers to usable security? Three organizational case studies. IEEE Secur Priv 14:22\u201332. https:\/\/doi.org\/10.1109\/MSP.2016.95","journal-title":"IEEE Secur Priv"},{"key":"10252_CR15","unstructured":"Clarke V, Braun V, Hayfield N (2015) Thematic analysis. In: Smith JA (ed) qualitative psychology: a practical guide to research methods. SAGE publications, pp 222\u2013248"},{"key":"10252_CR16","doi-asserted-by":"crossref","unstructured":"Collins A (1992) Toward a design science of education. In: New Directions in Educational Technology. Springer, pp 15\u201322. https:\/\/files.eric.ed.gov\/fulltext\/ED326179.pdf","DOI":"10.1007\/978-3-642-77750-9_2"},{"key":"10252_CR17","doi-asserted-by":"publisher","first-page":"268","DOI":"10.1145\/503271.503246","volume":"26","author":"R Conradi","year":"2001","unstructured":"Conradi R, Dyb\u00e5 T (2001) An empirical study on the utility of formal routines to transfer knowledge and experience. ACM SIGSOFT Softw Eng Notes 26:268\u2013276. https:\/\/doi.org\/10.1145\/503271.503246","journal-title":"ACM SIGSOFT Softw Eng Notes"},{"key":"10252_CR18","doi-asserted-by":"publisher","first-page":"4497","DOI":"10.1007\/s00500-015-1760-z","volume":"20","author":"M Dabbagh","year":"2016","unstructured":"Dabbagh M, Lee SP, Parizi RM (2016) Functional and non-functional requirements prioritization: empirical evaluation of IPA, AHP-based, and HAM-based approaches. Soft Comput 20:4497\u20134520. https:\/\/doi.org\/10.1007\/s00500-015-1760-z","journal-title":"Soft Comput"},{"key":"10252_CR19","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1111\/j.1365-2575.2004.00162.x","volume":"14","author":"RM Davison","year":"2004","unstructured":"Davison RM, Martinsons MG, Kock N (2004) Principles of canonical action research. Inf Syst J 14:65\u201386. https:\/\/doi.org\/10.1111\/j.1365-2575.2004.00162.x","journal-title":"Inf Syst J"},{"key":"10252_CR20","doi-asserted-by":"publisher","first-page":"1152","DOI":"10.1016\/j.infsof.2008.01.010","volume":"51","author":"B De Win","year":"2009","unstructured":"De Win B, Scandariato R, Buyens K, Gr\u00e9goire J, Joosen W (2009) On the secure software development process: CLASP, SDL and touchpoints compared. Inf Softw Technol 51:1152\u20131171. https:\/\/doi.org\/10.1016\/j.infsof.2008.01.010","journal-title":"Inf Softw Technol"},{"key":"10252_CR21","unstructured":"Denzin N, Lincoln Y (2011) The Sage handbook of qualitative research"},{"issue":"1","key":"10252_CR22","doi-asserted-by":"publisher","first-page":"5","DOI":"10.3102\/0013189X032001005","volume":"32","author":"Design-Based Research Collective","year":"2003","unstructured":"Design-Based Research Collective (2003) Design-based research: an emerging paradigm for educational inquiry. Educ Res 32(1):5\u20138. https:\/\/doi.org\/10.3102\/0013189X032001005","journal-title":"Educ Res"},{"key":"10252_CR23","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1109\/TSE.2005.53","volume":"31","author":"T Dyb\u00e5","year":"2005","unstructured":"Dyb\u00e5 T (2005) An empirical investigation of the key factors for success in software process improvement. IEEE Trans Softw Eng 31:410\u2013424. https:\/\/doi.org\/10.1109\/TSE.2005.53","journal-title":"IEEE Trans Softw Eng"},{"key":"10252_CR24","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1007\/978-1-84800-044-5_11","volume-title":"Guide to advanced empirical software engineering","author":"S Easterbrook","year":"2008","unstructured":"Easterbrook S, Singer J, Storey M-A, Damian D (2008) Selecting empirical methods for software engineering research. In: Guide to advanced empirical software engineering. Springer, London, pp 285\u2013311. https:\/\/doi.org\/10.1007\/978-1-84800-044-5_11"},{"key":"10252_CR25","unstructured":"Ejersbo LR, Engelhardt R, Fr\u00f8lunde L, Hangh\u00f8j T, Magnussen R, Misfeldt M (2008) Balancing product design and theoretical insights. In: The Handbook of Design Research Methods in Education. Routledge, pp. 149\u2013164"},{"key":"10252_CR26","unstructured":"Fisher R, Ury WL, Patton B (2011) Getting to yes: negotiating agreement without giving in. Penguin"},{"key":"10252_CR27","doi-asserted-by":"publisher","unstructured":"Fogg BJ (2009) A behavior model for Persuasive design. In: international conference on Persuasive technology - Persuasive. ACM, pp 40:1\u20137. https:\/\/doi.org\/10.1145\/1541948.1541999","DOI":"10.1145\/1541948.1541999"},{"key":"10252_CR28","doi-asserted-by":"publisher","unstructured":"Franqueira VNL, Tunnicliffe P (2015) To Flip or not to Flip: a critical interpretive synthesis of flipped teaching. In: Smart Education and Smart e-Learning. Springer, pp. 57\u201367. https:\/\/doi.org\/10.1007\/978-3-319-19875-0_6","DOI":"10.1007\/978-3-319-19875-0_6"},{"issue":"5","key":"10252_CR29","doi-asserted-by":"publisher","first-page":"521","DOI":"10.1109\/TSE.2017.2782813","volume":"45","author":"S Frey","year":"2017","unstructured":"Frey S, Rashid A, Anthonysamy P, Pinto-Albuquerque M, Naqvi SA (2017) The good, the bad and the ugly: a study of security decisions in a cyber-physical systems game. IEEE Trans Softw Eng 45(5):521\u2013536. https:\/\/doi.org\/10.1109\/TSE.2017.2782813","journal-title":"IEEE Trans Softw Eng"},{"key":"10252_CR30","unstructured":"Gwet KL (2014) Handbook of inter-rater reliability: the definitive guide to measuring the extent of agreement among raters.\u00a0Advanced Analytics LLC"},{"key":"10252_CR31","volume-title":"The product Manager\u2019s desk reference, Second ed","author":"S Haines","year":"2014","unstructured":"Haines S (2014) The product Manager\u2019s desk reference, Second ed. McGraw-Hill, New York"},{"key":"10252_CR32","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1109\/MS.2008.105","volume":"25","author":"T Hall","year":"2008","unstructured":"Hall T, Sharp H, Beecham S, Baddoo N, Robinson H (2008) What do we know about developer motivation? IEEE Softw 25:92\u201394. https:\/\/doi.org\/10.1109\/MS.2008.105","journal-title":"IEEE Softw"},{"key":"10252_CR33","doi-asserted-by":"crossref","unstructured":"Herzberg F (2017) Motivation to work. Routledge","DOI":"10.4324\/9781315124827"},{"key":"10252_CR34","doi-asserted-by":"crossref","unstructured":"Hubbard DW, Seiersen R (2016) How to measure anything in cybersecurity risk. John Wiley & Sons","DOI":"10.1002\/9781119162315"},{"key":"10252_CR35","unstructured":"ISO\/IEC (2008) 21827:2008 - Systems Security Engineering - Capability Maturity Model"},{"key":"10252_CR36","unstructured":"Kelly AE, Lesh RA, Baek JY (2008) Handbook of design research methods in education: innovations in science, technology, engineering, and mathematics learning and teaching. Routledge"},{"key":"10252_CR37","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1007\/978-3-642-41320-9_5","volume-title":"Financial cryptography and data security","author":"I Kirlappos","year":"2013","unstructured":"Kirlappos I, Beautement A, Sasse MA (2013) \u201cComply or die\u201d is dead: long live security-aware principal agents. In: Financial cryptography and data security. Springer, Berlin, Heidelberg, pp 70\u201382. https:\/\/doi.org\/10.1007\/978-3-642-41320-9_5"},{"key":"10252_CR38","first-page":"87","volume-title":"Positioning and power in academic publishing: players","author":"T Kluyver","year":"2016","unstructured":"Kluyver T, Ragan-kelley B, P\u00e9rez F et al (2016) Jupyter notebooks: a publishing format for reproducible computational workflows. In: Positioning and power in academic publishing: players. IOS Press, Agents and Agendas, pp 87\u201390"},{"key":"10252_CR39","doi-asserted-by":"publisher","unstructured":"Lopez T, Sharp H, Tun T, Bandara A, Levine M, Nuseibeh B (2019a) Hopefully we are mostly secure: views on secure code in professional practice. In: Workshop on Cooperative and Human Aspects of Software Engineering - CHASE. IEEE, pp. 61\u201368 https:\/\/doi.org\/10.1109\/CHASE.2019.00023","DOI":"10.1109\/CHASE.2019.00023"},{"key":"10252_CR40","doi-asserted-by":"publisher","DOI":"10.1109\/CESSER-IP.2019.00014","volume-title":"Talking about security with professional developers. In: Workshop on Conducting Empirical Studies in Industry - CESSER-IP","author":"T Lopez","year":"2019","unstructured":"Lopez T, Sharp H, Tun T et al (2019b) Talking about security with professional developers. In: Workshop on Conducting Empirical Studies in Industry - CESSER-IP. IEEE Computer Society, Montreal, QC, Canada"},{"key":"10252_CR41","doi-asserted-by":"publisher","unstructured":"McSweeney B (1999) Security, identity, and interests: a sociology of international relations. Cambridge University Press https:\/\/doi.org\/10.1109\/CESSER-IP.2019.00014","DOI":"10.1109\/CESSER-IP.2019.00014"},{"key":"10252_CR42","doi-asserted-by":"publisher","unstructured":"Mead NR, Stehney T (2005) Security quality requirements engineering (SQUARE) methodology. In: SESS 2005 - proceedings of the 2005 workshop on software engineering for secure systems - building trustworthy applications. Pp 1\u20137. https:\/\/doi.org\/10.1145\/1082983.1083214","DOI":"10.1145\/1082983.1083214"},{"key":"10252_CR43","doi-asserted-by":"publisher","unstructured":"Mellado D, Fern\u00e1ndez-Medina E, Piattini M (2006) Applying a security requirements engineering process. In: lecture notes in computer science (including subseries lecture notes in artificial intelligence and lecture notes in bioinformatics). Pp 192\u2013206 https:\/\/doi.org\/10.1007\/11863908_13","DOI":"10.1007\/11863908_13"},{"key":"10252_CR44","unstructured":"Microsoft (2018) Microsoft security intelligence report, Volume 23. https:\/\/info.microsoft.com\/rs\/157-gqe-382\/images\/en-us_cntnt-ebook-sir-volume-23_march2018.pdf. Accessed 6 Mar 2019"},{"key":"10252_CR45","doi-asserted-by":"publisher","unstructured":"Nhlabatsi A, Nuseibeh B, Yu Y (2012) Security requirements engineering for evolving software systems: a survey. In: Security-Aware Systems Applications and Software Development Methods. IGI Global, pp. 108\u2013128. https:\/\/doi.org\/10.4018\/978-1-4666-1580-9.ch007","DOI":"10.4018\/978-1-4666-1580-9.ch007"},{"key":"10252_CR46","unstructured":"Oxford Languages (2011) Concise Oxford English Dictionary"},{"key":"10252_CR47","doi-asserted-by":"publisher","first-page":"489","DOI":"10.1515\/jhsem-2014-0035","volume":"11","author":"SL Pfleeger","year":"2014","unstructured":"Pfleeger SL, Sasse MA, Furnham A (2014) From weakest link to security Hero: transforming staff security behavior. J Homel Secur Emerg Manag 11:489\u2013510. https:\/\/doi.org\/10.1515\/jhsem-2014-0035","journal-title":"J Homel Secur Emerg Manag"},{"key":"10252_CR48","doi-asserted-by":"publisher","first-page":"2489","DOI":"10.1145\/2998181.2998191","volume-title":"Conference on computer supported cooperative work - CSCW","author":"A Poller","year":"2017","unstructured":"Poller A, Kocksch L, T\u00fcrpe S, Epp FA, Kinder-Kurlanda K (2017) Can security become a routine? A study of organizational change in an agile software development group. In: Conference on computer supported cooperative work - CSCW. ACM, Portland Oregon USA, pp 2489\u20132503. https:\/\/doi.org\/10.1145\/2998181.2998191"},{"key":"10252_CR49","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3471930","volume":"31","author":"I Rauf","year":"2022","unstructured":"Rauf I, Petre M, Tun T et al (2022) The case for adaptive security interventions. ACM Trans Softw Eng Methodol 31:1\u201352. https:\/\/doi.org\/10.1145\/3471930","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"10252_CR50","unstructured":"RiskBased Security (2020) 2020 Mid Year Data Breach Report"},{"key":"10252_CR51","unstructured":"Shostack A (2014) Threat modeling: designing for security. John Wiley & Sons"},{"key":"10252_CR52","doi-asserted-by":"publisher","unstructured":"Shreeve B, Hallett J, Edwards M, et al (2020) The best laid plans or lack Thereof: Security Decision-Making of Different Stakeholder Groups. IEEE Trans Softw Eng. https:\/\/doi.org\/10.1109\/TSE.2020.3023735","DOI":"10.1109\/TSE.2020.3023735"},{"key":"10252_CR53","doi-asserted-by":"crossref","unstructured":"Springer O, Miler J (2018) The role of a software product manager in various business environments. In: proceedings of the 2018 federated conference on computer science and information systems, FedCSIS 2018. Polish information processing society, pp 985\u2013994","DOI":"10.15439\/2018F100"},{"key":"10252_CR54","unstructured":"Stack Overflow (2016) Annual Developer Survey. https:\/\/insights.stackoverflow.com\/survey\/2016. Accessed 17 Jun 2020"},{"key":"10252_CR55","doi-asserted-by":"publisher","first-page":"596","DOI":"10.1111\/TCT.13242","volume":"17","author":"T Stenfors","year":"2020","unstructured":"Stenfors T, Kajamaa A, Bennett D (2020) How to \u2026 assess the quality of qualitative research. Clin Teach 17:596\u2013599. https:\/\/doi.org\/10.1111\/TCT.13242","journal-title":"Clin Teach"},{"key":"10252_CR56","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1016\/j.cose.2016.03.009","volume":"60","author":"JM Such","year":"2016","unstructured":"Such JM, Gouglidis A, Knowles W et al (2016) Information assurance techniques: perceived cost effectiveness. Comput Secur 60:117\u2013133. https:\/\/doi.org\/10.1016\/j.cose.2016.03.009","journal-title":"Comput Secur"},{"key":"10252_CR57","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1108\/00251749810211027","volume":"36","author":"MA Tietjen","year":"1998","unstructured":"Tietjen MA, Myers RM (1998) Motivation and job satisfaction. Manag Decis 36:226\u2013231. https:\/\/doi.org\/10.1108\/00251749810211027","journal-title":"Manag Decis"},{"key":"10252_CR58","unstructured":"T\u00fcrpe S, Kocksch L, Poller A (2016) Penetration tests a turning point in security practices? Organizational challenges and implications in a software development team. In: Workshop on Security Information Workers - SIW. USENIX Association"},{"key":"10252_CR59","doi-asserted-by":"crossref","unstructured":"van der Linden D, Anthonysamy P, Nuseibeh B, et al (2020) Schr\u00f6dinger\u2019s security: opening the box on app developers\u2019 security rationale. In: International Conference on Software Engineering - ICSE. IEEE","DOI":"10.1145\/3377811.3380394"},{"key":"10252_CR60","unstructured":"Veracode (2018) State of Software Security Report Volume 9. https:\/\/info.veracode.com\/report-state-of-software-security-volume-9.html. Accessed 6 Feb 2019"},{"issue":"5","key":"10252_CR61","first-page":"360","volume":"37","author":"AJ Viera","year":"2005","unstructured":"Viera AJ, Garrett JM (2005) Understanding Interobserver agreement: the kappa statistic. Fam Med 37(5):360\u2013363","journal-title":"Fam Med"},{"key":"10252_CR62","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1007\/BF02504682","volume":"53","author":"F Wang","year":"2005","unstructured":"Wang F, Hannafin MJ (2005) Design-based research and technology-enhanced learning environments. Educ Technol Res Dev 53:5\u201323. https:\/\/doi.org\/10.1007\/BF02504682","journal-title":"Educ Technol Res Dev"},{"key":"10252_CR63","doi-asserted-by":"publisher","unstructured":"Weir C, Becker I, Blair L (2021a) A passion for security: intervening to help software developers. In: 2021 IEEE\/ACM 43rd international conference on software engineering: software engineering in practice (ICSE-SEIP). IEEE, pp 21\u201330. : https:\/\/doi.org\/10.1109\/ICSE-SEIP52600.2021.00011","DOI":"10.1109\/ICSE-SEIP52600.2021.00011"},{"key":"10252_CR64","doi-asserted-by":"publisher","unstructured":"Weir C, Becker I, Noble J, et al (2019) Interventions for long-term software security: creating a lightweight program of assurance techniques for developers. Softw - Pract Exp 275\u2013298. : https:\/\/doi.org\/10.1002\/spe.2774","DOI":"10.1002\/spe.2774"},{"key":"10252_CR65","unstructured":"Weir C, Hermann B, Fahl S (2020a) From needs to actions to secure apps? The effect of requirements and developer practices on app security. In: 29th USENIX security symposium (USENIX security 20)"},{"key":"10252_CR66","unstructured":"Weir C, Knight J, Ford N (2021b) Developer Security Essentials. https:\/\/www.securedevelopment.org\/workshops\/. Accessed 9 Jun 2021"},{"key":"10252_CR67","doi-asserted-by":"publisher","unstructured":"Weir C, Noble J, Rashid A (2020b) Challenging software developers: dialectic as a Foundation for Security Assurance Techniques. J Cybersecurity 30. https:\/\/doi.org\/10.1093\/cybsec\/tyaa007","DOI":"10.1093\/cybsec\/tyaa007"},{"key":"10252_CR68","doi-asserted-by":"publisher","unstructured":"Xie J, Lipford HR, Chu B (2011) Why do programmers make security errors? In: IEEE symposium on visual languages and human centric computing. Pittsburg, PA, USA, pp. 161\u2013164. : https:\/\/doi.org\/10.1109\/VLHCC.2011.6070393","DOI":"10.1109\/VLHCC.2011.6070393"},{"key":"10252_CR69","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1109\/ICSE.2015.49","volume-title":"International conference on software engineering - ICSE","author":"K Yskout","year":"2015","unstructured":"Yskout K, Scandariato R, Joosen W (2015) Do security patterns really help designers? In: International conference on software engineering - ICSE. IEEE, Firenze, Italy, pp 292\u2013302. https:\/\/doi.org\/10.1109\/ICSE.2015.49"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10252-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-022-10252-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10252-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,3]],"date-time":"2023-04-03T06:49:26Z","timestamp":1680504566000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-022-10252-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,24]]},"references-count":69,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2023,3]]}},"alternative-id":["10252"],"URL":"https:\/\/doi.org\/10.1007\/s10664-022-10252-0","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,24]]},"assertion":[{"value":"20 October 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 December 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"None.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of interest\/competing interests"}},{"value":"The project was approved by the Lancaster University Faculty of Science and Technology Research Ethics committee.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}},{"value":"N\/A","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate"}},{"value":"N\/A","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}}],"article-number":"21"}}