Title
An Educational Intervention For Teaching Secure Coding Practices
Abstract
Cybersecurity vulnerabilities are typically addressed through the implementation of various cybersecurity controls. These controls can be operational, technical or physical in nature. The focus of this paper is on technical controls with a specific focus on securing web applications. The secure coding practices used in this research are based on OWASP. An initial investigation found that there was a general lack of adherence to these secure coding practices by third year software development students doing their capstone project at a South African University. This research therefore focused on addressing this problem by developing an educational intervention to teach secure coding practices, specifically focusing on the data access layer of web applications developed in the .NET environment. Pre-tests and post-tests were conducted in order to determine the effectiveness of the intervention. Results indicated an increase in both knowledge and behaviour regarding the identified secure coding practices after exposure to the intervention.
Year
DOI
Venue
2019
10.1007/978-3-030-23451-5_1
INFORMATION SECURITY EDUCATION: EDUCATION IN PROACTIVE INFORMATION SECURITY, WISE 12
Keywords
DocType
Volume
Educational intervention, Secure coding practices, OWASP, Web application security
Conference
557
ISSN
Citations 
PageRank 
1868-4238
0
0.34
References 
Authors
0
3
Name
Order
Citations
PageRank
Vuyolwethu Sizoli Mdunyelwa100.34
Lynn Futcher23510.66
Johan Van Niekerk315218.80