scieee AI-readable full text Open interactive document viewer

Characterizing the Security Culture of the Research Software Engineering Community

Armstrong, Matthew; Carver, Jeffrey; Milewicz, Reed

Abstract

The growing importance of research software heightens concerns about research software security, which will only intensify if not proactively addressed. Before any specific measures or interventions can be suggested, it is essential to understand the RSE community’s security behaviors, competencies, and values, collectively referred to as their ‘security culture’ [1]. While studying the climate and culture within a group of people is not a new concept or research topic, to our knowledge, no security culture research has taken place within the RSE community. In this study, we aim to characterize the security culture of the RSE community by replicating a prior work performed in the open-source software space [3]. To broaden our sample, we distributed this survey to RSE community members in both the US and Germany. By replicating an existing survey, we can compare the RSE community’s responses with those of the open-source community, which shares some characteristics with RSE [4-5]. In addition to the original survey, we added a series of vignettes to gauge the RSE community’s knowledge and perception of threat modeling, a standard “shift-left” approach to security. By doing so, we gauge RSE interest in participating in security efforts and motivate future security research in the research software domain. Ultimately, we surveyed 104 members of the RSE community, including both those in the US and Germany. To characterize RSE security culture, we ask the following research questions: RQ1: What is the security culture of the RSE community? RQ2: How does the RSE community’s security culture compare with the Open-Source Community’s security culture? RQ3: What is the perception among RSE community members on adopting threat modeling during development? The primary contributions of this study are: 1) A novel characterization of the RSE community’s security culture, 2) an empirical comparison of the security culture of RSEs and OSS developers, and 3) recommendations for internal and external stakeholders to improve RSE security culture. This study is a first step toward tailoring “shift-left” security principles to address the unique challenges that RSEs face.

Full text

Characterizing the Security Culture of the RSE Community Matthew Armstrong1, Jeffrey Carver1, Reed Milewicz2 1University of Alabama, 2Sandia National Laboratory RSE Results Ideas for Improvement •Adopt a community-responsibility mindset, similar to OSS •Behaviors •Policies •Procedures •Identify and Promote Interactions between stakeholders •Security Researchers •Software Engineering Researchers •Research Funders •Research Software Engineers •Domain Experts and PIs •Ongoing: •Promote RSE security awareness, leading to security champions •Security Workshops for RSEs •Promote RSE cause with external researchers •Publish findings in wider SE / security venues •Have thoughts that could explain our findings? •What do you think the RSE community should be doing to improve? •What could external stakeholders do to help? •Have an idea for our next step that would best help you? Any writing or attached feedback to this poster will be used in on-going research, as approved by the University of Alabama IRB. By writing or attaching feedback, you consent to our use of the feedback in our study. If you have any questions, please contact Matthew Armstrong (maarms[email protected]) for more information. Value Responsibility* Positivity* Acts* Compliance Risk-Taking Knowledge Skills Effectiveness Trust* Supportiveness Expectation Expertise Policies Implementation Infrastructure Codification Personalization Mean Values RSE OSS Leave us a note! RSE vs Open-Source Security Culture HELP WANTED RSE dimension results in ascending order, indicating: •A lack of institutional support and communication methods for security •Positive behaviors despite mixed skills/expertise •Positive attitudes despite neutral community expectations and support *Indicates an insignificant difference under analysis Despite similar attitudes towards security, OS is more positive in almost all other dimensions; perhaps techniques could be translated from OS to RS? Interviews also available Contact maarmstr[email protected] for more info