{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:59:01Z","timestamp":1750309141504,"version":"3.41.0"},"reference-count":17,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,2,28]],"date-time":"2024-02-28T00:00:00Z","timestamp":1709078400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2024,2,28]]},"abstract":"<jats:p>How to design and implement information systems so that they are safe and secure is a complex topic. Both high-level design principles and implementation guidance for software safety and security are well established and broadly accepted. For example, Jerome Saltzer and Michael Schroeder's seminal overview of principles of secure design was published almost 50 years ago, and various community and governmental bodies have published comprehensive best practices about how to avoid common software weaknesses. This article argues, based on experience at Google, that focusing on developer ecosystems is both practical and effective, and can achieve a drastic reduction in the rate of common classes of defects across hundreds of applications being developed by thousands of developers.<\/jats:p>","DOI":"10.1145\/3648601","type":"journal-article","created":{"date-parts":[[2024,2,29]],"date-time":"2024-02-29T23:14:50Z","timestamp":1709248490000},"page":"73-99","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Developer Ecosystems for Software Safety"],"prefix":"10.1145","volume":"22","author":[{"given":"Christoph","family":"Kern","sequence":"first","affiliation":[{"name":"Google"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,2,29]]},"reference":[{"volume-title":"Building Secure and Reliable Systems: Best Practices for Designing, Implementing, and Maintaining Systems","author":"Adkins H.","unstructured":"Adkins, H., Beyer, B., Blankinship, P., Lewandowski, P., Oprea, A., Stubblefield, A. 2020. Building Secure and Reliable Systems: Best Practices for Designing, Implementing, and Maintaining Systems. O'Reilly Media; https:\/\/sre.google\/books\/building-secure-reliable-systems\/.","key":"e_1_2_1_1_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_2_1","DOI":"10.1145\/2491245"},{"volume-title":"Stubborn weaknesses in the CWE top 25","year":"2023","unstructured":"CWE. 2023. Stubborn weaknesses in the CWE top 25; https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_stubborn_weaknesses.html.","key":"e_1_2_1_3_1"},{"volume-title":"Top 25 most dangerous software weaknesses","year":"2023","unstructured":"CWE. 2023. Top 25 most dangerous software weaknesses; https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_top25_list.html.","key":"e_1_2_1_4_1"},{"unstructured":"Czapi?ski M. Wolafka R. 2019. Zero Touch Prod: Towards safer and more secure production environments. Usenix; https:\/\/www.usenix.org\/conference\/srecon19emea\/presentation\/czapinski.","key":"e_1_2_1_5_1"},{"doi-asserted-by":"crossref","unstructured":"Kern C. 2014. Securing the tangled web. Communications of the ACM 57(9) 38?47; https:\/\/dl.acm.org\/doi\/10.1145\/2643134.","key":"e_1_2_1_6_1","DOI":"10.1145\/2643134"},{"unstructured":"Kotowicz K. 2024. Trusted Types; https:\/\/w3c.github.io\/trusted-types\/dist\/spec\/.","key":"e_1_2_1_7_1"},{"unstructured":"Leveson N. 2019. A systems approach to safety and cybersecurity. Usenix; https:\/\/www.usenix.org\/conference\/srecon19emea\/presentation\/leveson.","key":"e_1_2_1_8_1"},{"doi-asserted-by":"crossref","unstructured":"Nokleberg C. Hawkes B. 2021. Application frameworks. Communications of the ACM 64(7) 42?49; https:\/\/dl.acm.org\/doi\/10.1145\/3446796.","key":"e_1_2_1_9_1","DOI":"10.1145\/3446796"},{"unstructured":"OWASP. OWASP Top Ten; https:\/\/owasp.org\/www-project-top-ten\/.","key":"e_1_2_1_10_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_11_1","DOI":"10.1109\/PROC.1975.9939"},{"volume-title":"The CERT C Coding Standard: 98 Rules for Developing Safe, Reliable, and Secure Systems","author":"Seacord R. C.","unstructured":"Seacord, R. C. 2014. The CERT C Coding Standard: 98 Rules for Developing Safe, Reliable, and Secure Systems, second edition. Addison-Wesley Professional.","key":"e_1_2_1_12_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_13_1","DOI":"10.1145\/2741948.2741964"},{"doi-asserted-by":"publisher","key":"e_1_2_1_14_1","DOI":"10.1109\/ICSE43902.2021.00123"},{"key":"e_1_2_1_15_1","volume-title":"IEEE European Symposium on Security and Privacy Workshops, 60?73; https:\/\/research.google\/pubs\/pub50513\/.","author":"Wang P.","year":"2021","unstructured":"Wang, P., Gumundsson, B. A., Kotowicz, K. 2021. Adopting Trusted Types in production web frameworks to prevent DOM-based cross-site scripting: a case study. In IEEE European Symposium on Security and Privacy Workshops, 60?73; https:\/\/research.google\/pubs\/pub50513\/."},{"key":"e_1_2_1_16_1","volume-title":"Software Engineering at Google: Lessons Learned from Programming over Time","author":"Winters T.","year":"2082","unstructured":"Winters, T., Manshreck, T., Wright., H. 2020. Software Engineering at Google: Lessons Learned from Programming over Time. O'Reilly Media; https:\/\/www.oreilly.com\/library\/view\/software-engineering-at\/9781492082781\/."},{"doi-asserted-by":"crossref","unstructured":"Young W. Leveson N. G. 2014. An integrated approach to safety and security based on systems theory. Communications of the ACM 57(2) 31?35; https:\/\/dl.acm.org\/doi\/10.1145\/2556938.","key":"e_1_2_1_17_1","DOI":"10.1145\/2556938"}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3648601","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3648601","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:50:20Z","timestamp":1750287020000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3648601"}},"subtitle":["Continuous assurance at scale"],"short-title":[],"issued":{"date-parts":[[2024,2,28]]},"references-count":17,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,2,28]]}},"alternative-id":["10.1145\/3648601"],"URL":"https:\/\/doi.org\/10.1145\/3648601","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"type":"print","value":"1542-7730"},{"type":"electronic","value":"1542-7749"}],"subject":[],"published":{"date-parts":[[2024,2,28]]},"assertion":[{"value":"2024-02-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}