遇见数据集

S55: A Multidimensional Instrument for Assessing Organizational Capability in Secure Software Engineering

收藏
Zenodo2026-08-02 更新2026-08-13 收录
官方服务:

资源简介:

Context:Adopting secure software engineering practices does not necessarily ensure that organizations can sustain, standardize, measure, and integrate them into governance. Assessment approaches are therefore needed to examine security practices together with the organizational capabilities and institutionalization mechanisms that support their continuity. Objective: This study presents and applies S55, a multidimensional instrument designed to assess perceived organizational capability for Secure Software Engineering by integrating lifecycle security practices, supporting capabilities, and perceived organizational maturity. Method: We conducted an exploratory, cross-sectional survey with 98 Brazilian professionals. S55 comprises 55 statements organized into six analytical areas and 12 diagnostic dimensions. Forty-eight items contribute to dimension, area, and overall scores, while seven complementary global items support interpretation. Scores were normalized to a 0--100 scale. Results: The overall score was 54.5, indicating an intermediate but internally heterogeneous profile. Software security culture (63.8) and software operational security capability (62.3) achieved the highest scores, whereas training (43.3) and perceived organizational maturity (47.0) achieved the lowest. Practice-related dimensions and six of seven supporting capabilities scored above perceived maturity, suggesting a potential institutionalization gap. Software supply chain results indicated stronger perceptions of vulnerability-response responsibilities than of continuous component visibility. In AI-assisted development, human review and security checks scored above traceability of tool use. Conclusion: The findings suggest that secure software engineering capability depends not only on adopting practices but also on the conditions required to institutionalize them. S55 provides a structured basis for identifying perceived capability asymmetries and prioritizing further investigation and improvement initiatives. It complements, but does not replace, audits, certifications, or objective organizational assessments, and its measurement properties require further validation.

提供机构:
Zenodo
创建时间:
2026-08-02
二维码
社区交流群
二维码
科研交流群
商业服务