{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T03:57:23Z","timestamp":1784606243630,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,8,18]],"date-time":"2021-08-18T00:00:00Z","timestamp":1629244800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,8,20]]},"DOI":"10.1145\/3468264.3473926","type":"proceedings-article","created":{"date-parts":[[2021,8,19]],"date-time":"2021-08-19T01:40:20Z","timestamp":1629337220000},"page":"1326-1336","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["Infiltrating security into development: exploring the world\u2019s largest software security study"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3051-4195","authenticated-orcid":false,"given":"Charles","family":"Weir","sequence":"first","affiliation":[{"name":"Lancaster University, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sammy","family":"Migues","sequence":"additional","affiliation":[{"name":"Synopsys, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mike","family":"Ware","sequence":"additional","affiliation":[{"name":"Synopsys, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[{"name":"North Carolina State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,8,18]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"American Psychological Association. 2019. Publication Manual of the American Psychological Association: The Oficial Guide to APA Style (seventh ed ed.). https: \/\/apastyle.apa.org\/products\/publication-manual-7th-edition  American Psychological Association. 2019. Publication Manual of the American Psychological Association: The Oficial Guide to APA Style (seventh ed ed.). https: \/\/apastyle.apa.org\/products\/publication-manual-7th-edition"},{"key":"e_1_3_2_1_2_1","volume-title":"Bartlett","author":"Barth Adam","year":"2010","unstructured":"Adam Barth , Benjamin I. P. Rubinstein , Mukund Sundararajan , John C. Mitchell , Dawn Song , and Peter L . Bartlett . 2010 . A Learning-Based Approach to Reactive Security. In Financial Cryptography and Data Security, Radu Sion (Ed.). Springer Berlin Heidelberg , Berlin, Heidelberg, 192-206. Adam Barth, Benjamin I. P. Rubinstein, Mukund Sundararajan, John C. Mitchell, Dawn Song, and Peter L. Bartlett. 2010. A Learning-Based Approach to Reactive Security. In Financial Cryptography and Data Security, Radu Sion (Ed.). Springer Berlin Heidelberg, Berlin, Heidelberg, 192-206."},{"key":"e_1_3_2_1_3_1","volume-title":"Agile Application Security: Enabling Security in a Continuous Delivery Pipeline. O'Reilly","author":"Bell Laura","unstructured":"Laura Bell , Michael Brunton-Spall , Rich Smith , and Jim Bird . 2017. Agile Application Security: Enabling Security in a Continuous Delivery Pipeline. O'Reilly , Sebastopol, CA . Laura Bell, Michael Brunton-Spall, Rich Smith, and Jim Bird. 2017. Agile Application Security: Enabling Security in a Continuous Delivery Pipeline. O'Reilly, Sebastopol, CA."},{"key":"e_1_3_2_1_4_1","unstructured":"Bristol University. [n. d.]. The CyBOK Project. ([n. d.]). https:\/\/www.cybok.org\/  Bristol University. [n. d.]. The CyBOK Project. ([n. d.]). https:\/\/www.cybok.org\/"},{"key":"e_1_3_2_1_5_1","volume-title":"CDC's Achievements. (September 23","author":"CDC.","year":"2019","unstructured":"CDC. September 23, 2019. Preventing, Detecting, and Responding to Epidemics : CDC's Achievements. (September 23 , 2019 ). https:\/\/www.cdc.gov\/globalhealth\/ security\/ghsareport\/2018\/prevent-detect-respond.html CDC. September 23, 2019. Preventing, Detecting, and Responding to Epidemics: CDC's Achievements. (September 23, 2019 ). https:\/\/www.cdc.gov\/globalhealth\/ security\/ghsareport\/2018\/prevent-detect-respond.html"},{"key":"e_1_3_2_1_6_1","unstructured":"Cisco. 2021. The 2021 Security Outcomes Study. ( 2021 ). https:\/\/www.cisco.com\/ c\/en\/us\/products\/security\/security-outcomes-study.html  Cisco. 2021. The 2021 Security Outcomes Study. ( 2021 ). https:\/\/www.cisco.com\/ c\/en\/us\/products\/security\/security-outcomes-study.html"},{"key":"e_1_3_2_1_7_1","unstructured":"CONSORT. 2010. Checklist of Information to Include When Reporting a Randomized Trial. ( 2010 ) 11-12 pages. http:\/\/www.consort-statement.org\/consort-2010 [Online; accessed 2019-09-10].  CONSORT. 2010. Checklist of Information to Include When Reporting a Randomized Trial. ( 2010 ) 11-12 pages. http:\/\/www.consort-statement.org\/consort-2010 [Online; accessed 2019-09-10]."},{"key":"e_1_3_2_1_8_1","unstructured":"DoD. 2020. Cybersecurity Maturity Model Certification (CMMC). ( 2020 ). https: \/\/www.acq.osd.mil\/cmmc\/docs\/CMMC_ModelMain_V1. 02_20200318.pdf  DoD. 2020. Cybersecurity Maturity Model Certification (CMMC). ( 2020 ). https: \/\/www.acq.osd.mil\/cmmc\/docs\/CMMC_ModelMain_V1. 02_20200318.pdf"},{"key":"e_1_3_2_1_9_1","first-page":"374","article-title":"Validity Threats in Empirical Software Engineering Research: An Initial Survey","author":"Feldt Robert","year":"2010","unstructured":"Robert Feldt and Ana Magazinius . 2010 . Validity Threats in Empirical Software Engineering Research: An Initial Survey .. In SEKE. 374 - 379 . Robert Feldt and Ana Magazinius. 2010. Validity Threats in Empirical Software Engineering Research: An Initial Survey.. In SEKE. 374-379.","journal-title":"SEKE."},{"key":"e_1_3_2_1_10_1","volume-title":"10 Cyber Security Trends You Can't Ignore","author":"Firch Jason","year":"2021","unstructured":"Jason Firch and PurpleSec. 2021. 10 Cyber Security Trends You Can't Ignore in 2021 . ( 2021 ). https:\/\/purplesec.us\/cyber-security-trends-2021\/ Jason Firch and PurpleSec. 2021. 10 Cyber Security Trends You Can't Ignore in 2021. ( 2021 ). https:\/\/purplesec.us\/cyber-security-trends-2021\/"},{"key":"e_1_3_2_1_12_1","volume-title":"The Urgency to Treat Cybersecurity as a Business Decision. ID G00466055 (12","author":"February","year":"2020","unstructured":"Gartner. 12 February 2020. The Urgency to Treat Cybersecurity as a Business Decision. ID G00466055 (12 February 2020 ). Gartner. 12 February 2020. The Urgency to Treat Cybersecurity as a Business Decision. ID G00466055 (12 February 2020 )."},{"key":"e_1_3_2_1_13_1","unstructured":"Kilem L Gwet. 2014. Handbook of Inter-Rater Reliability: The Definitive Guide to Measuring the Extent of Agreement Among Raters. Advanced Analytics LLC.  Kilem L Gwet. 2014. Handbook of Inter-Rater Reliability: The Definitive Guide to Measuring the Extent of Agreement Among Raters. Advanced Analytics LLC."},{"key":"e_1_3_2_1_14_1","volume-title":"Skills and Characteristics of Successful Cybersecurity Advocates. In Workshop on Security Information Workers-SIW. USENIX Association.","author":"Haney Julie M","year":"2017","unstructured":"Julie M Haney and Wayne G Lutters . 2017 . Skills and Characteristics of Successful Cybersecurity Advocates. In Workshop on Security Information Workers-SIW. USENIX Association. Julie M Haney and Wayne G Lutters. 2017. Skills and Characteristics of Successful Cybersecurity Advocates. In Workshop on Security Information Workers-SIW. USENIX Association."},{"key":"e_1_3_2_1_15_1","volume-title":"Using the Common Criteria for IT security evaluation","author":"Herrmann Debra S","unstructured":"Debra S Herrmann . 2002. Using the Common Criteria for IT security evaluation . CRC Press . Debra S Herrmann. 2002. Using the Common Criteria for IT security evaluation. CRC Press."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pmed.0020124"},{"key":"e_1_3_2_1_17_1","unstructured":"ISO. 2011. ISO\/IEC 27034 Application Security Standard. ( 2011 ). https:\/\/www. iso27001security.com\/html\/27034.html  ISO. 2011. ISO\/IEC 27034 Application Security Standard. ( 2011 ). https:\/\/www. iso27001security.com\/html\/27034.html"},{"key":"e_1_3_2_1_18_1","unstructured":"ISO\/IEC. 2013. ISO\/IEC 27001: Information Security Management Report. ( 2013 ). https:\/\/www.iso.org\/isoiec-27001-information-security.html  ISO\/IEC. 2013. ISO\/IEC 27001: Information Security Management Report. ( 2013 ). https:\/\/www.iso.org\/isoiec-27001-information-security.html"},{"key":"e_1_3_2_1_19_1","volume-title":"Inger Anne T\u00f8ndel, and Lillian R\u00f8stad","author":"Jaatun Martin Gilje","year":"2015","unstructured":"Martin Gilje Jaatun , Daniela S. Cruzes , Karin Bernsmed , Inger Anne T\u00f8ndel, and Lillian R\u00f8stad . 2015 . Software Security Maturity in Public Organisations. In Information Security, Javier Lopez and Chris J. Mitchell (Eds.). Springer International Publishing , Cham, 120-138. Martin Gilje Jaatun, Daniela S. Cruzes, Karin Bernsmed, Inger Anne T\u00f8ndel, and Lillian R\u00f8stad. 2015. Software Security Maturity in Public Organisations. In Information Security, Javier Lopez and Chris J. Mitchell (Eds.). Springer International Publishing, Cham, 120-138."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.3233\/978-1-61499-649-1-87"},{"key":"e_1_3_2_1_21_1","volume-title":"Reactive Investment in Information Security. In Tenth Workshop on Economics of Information Security (WEIS 2011 ), Fairfax, VA, USA, June 14-15, 2011. (WEIS Workshop Proceedings).","author":"Kwon Juhee","unstructured":"Juhee Kwon and M. Eric Johnson . 2011. An Organizational Learning Perspective on Proactive vs . Reactive Investment in Information Security. In Tenth Workshop on Economics of Information Security (WEIS 2011 ), Fairfax, VA, USA, June 14-15, 2011. (WEIS Workshop Proceedings). Juhee Kwon and M. Eric Johnson. 2011. An Organizational Learning Perspective on Proactive vs. Reactive Investment in Information Security. In Tenth Workshop on Economics of Information Security (WEIS 2011 ), Fairfax, VA, USA, June 14-15, 2011. (WEIS Workshop Proceedings)."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Juhee Kwon and M. Eric Johnson. 2014. Proactive Versus Reactive Security Investments in the Healthcare Sector. MIS Quarterly 38 2 ( 2014 ) 451-A3. https: \/\/www.jstor.org\/stable\/26634934  Juhee Kwon and M. Eric Johnson. 2014. Proactive Versus Reactive Security Investments in the Healthcare Sector. MIS Quarterly 38 2 ( 2014 ) 451-A3. https: \/\/www.jstor.org\/stable\/26634934","DOI":"10.25300\/MISQ\/2014\/38.2.06"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2010.117"},{"key":"e_1_3_2_1_24_1","volume-title":"Software Security: Building Security In.","author":"McGraw Gary","year":"2006","unstructured":"Gary McGraw . 2006 . Software Security: Building Security In. Vol. 1 . AddisonWesley Professional . Gary McGraw. 2006. Software Security: Building Security In. Vol. 1. AddisonWesley Professional."},{"key":"e_1_3_2_1_25_1","volume-title":"The Building Security in Maturity Model (BSIMM)","author":"McGraw Gary","unstructured":"Gary McGraw and Brian Chess . 2009. The Building Security in Maturity Model (BSIMM) . USENIX Association , Montreal, Quebec . Gary McGraw and Brian Chess. 2009. The Building Security in Maturity Model (BSIMM). USENIX Association, Montreal, Quebec."},{"key":"e_1_3_2_1_28_1","volume-title":"Crossing the Chasm: Marketing and Selling Disruptive Products to Mainstream Customers","author":"Moore Geofrey A","unstructured":"Geofrey A Moore . 2009. Crossing the Chasm: Marketing and Selling Disruptive Products to Mainstream Customers . Harper Collins . Geofrey A Moore. 2009. Crossing the Chasm: Marketing and Selling Disruptive Products to Mainstream Customers. Harper Collins."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.5555\/2819009.2819218"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3055305.3055312"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1002\/widm.53"},{"key":"e_1_3_2_1_32_1","unstructured":"NIST. 2020. NIST Special Publication 800-53 Revision 5 Security and Privacy Controls forInformation Systems and Organizations. ( 2020 ). https:\/\/nvlpubs. nist.gov\/nistpubs\/SpecialPublications\/NIST.SP. 800-53r5.pdf  NIST. 2020. NIST Special Publication 800-53 Revision 5 Security and Privacy Controls forInformation Systems and Organizations. ( 2020 ). https:\/\/nvlpubs. nist.gov\/nistpubs\/SpecialPublications\/NIST.SP. 800-53r5.pdf"},{"key":"e_1_3_2_1_33_1","unstructured":"NIST. 2021. NIST Cybersecurity Framework. ( 2021 ). https:\/\/csrc.nist.gov\/ projects\/risk-management\/about-rmf  NIST. 2021. NIST Cybersecurity Framework. ( 2021 ). https:\/\/csrc.nist.gov\/ projects\/risk-management\/about-rmf"},{"key":"e_1_3_2_1_34_1","unstructured":"NIST. 2021. Statistics Results. ( 2021 ). https:\/\/nvd.nist.gov\/vuln\/search\/statistics  NIST. 2021. Statistics Results. ( 2021 ). https:\/\/nvd.nist.gov\/vuln\/search\/statistics"},{"key":"e_1_3_2_1_35_1","unstructured":"SAFECode organization. 2021. SAFECode. ( 2021 ). https:\/\/safecode.org\/  SAFECode organization. 2021. SAFECode. ( 2021 ). https:\/\/safecode.org\/"},{"key":"e_1_3_2_1_37_1","unstructured":"OWASP. 2020. OWASP Application Security Verification Standard (ASVS). ( 2020 ). https:\/\/owasp.org \/www-project-application-security-verification-standard\/  OWASP. 2020. OWASP Application Security Verification Standard (ASVS). ( 2020 ). https:\/\/owasp.org \/www-project-application-security-verification-standard\/"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.4018\/978-1-5225-6313-6.ch011"},{"key":"e_1_3_2_1_39_1","volume-title":"Statistics II for Dummies","author":"Rumsey Deborah","unstructured":"Deborah Rumsey . 2009. Statistics II for Dummies . Wiley , Indianapolis . Deborah Rumsey. 2009. Statistics II for Dummies. Wiley, Indianapolis."},{"key":"e_1_3_2_1_40_1","unstructured":"James LaPiedra SANS Institute. 2002. The Information Security Process: Prevention Detection and Response. ( 2002 ). https:\/\/www.giac.org\/paper\/gsec\/501\/ information-security-process-prevention-detection-response\/101197  James LaPiedra SANS Institute. 2002. The Information Security Process: Prevention Detection and Response. ( 2002 ). https:\/\/www.giac.org\/paper\/gsec\/501\/ information-security-process-prevention-detection-response\/101197"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.03.009"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW.2019.00021"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1093\/acref\/9780199679188.001.0001"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377812.3381393"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2019.8870153"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3339263"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00011"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.23919\/FRUCT.2017.8250205"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2018.290110854"}],"event":{"name":"ESEC\/FSE '21: 29th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering","location":"Athens Greece","acronym":"ESEC\/FSE '21","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3468264.3473926","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3468264.3473926","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:17:23Z","timestamp":1750191443000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3468264.3473926"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,18]]},"references-count":45,"alternative-id":["10.1145\/3468264.3473926","10.1145\/3468264"],"URL":"https:\/\/doi.org\/10.1145\/3468264.3473926","relation":{},"subject":[],"published":{"date-parts":[[2021,8,18]]},"assertion":[{"value":"2021-08-18","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}