Logo Lanfrica
  • Home
  • Atlas
  • Insights
  • Docs
  • Sign in

© 2026 Lanfrica. All rights reserved. All copyrights of the resources shown on the Lanfrica website belong to the original copyright holders, unless explicitly stated otherwise.

Secure software development as a social practice: investigating the dynamics of socio-technical factors in the security practices of developers in SMEs

Domain:

digital infrastructure

Record type:

paper
Creator:
Fid
Editor:
JirFle
Host:avatar

The software security industry primarily focuses on the technical aspect of the software development process, with limited studies examining the impact of human interactions, organisational contexts, and social factors on developer practices. The software application development industry is worth trillions of pounds, with a user base of billions per year. For decades, software engineering and security research disciplines have focused on end-users’ experiences with software applications and increasing security awareness. Unfortunately, there has been little work considering how the developers of these software products navigate the issues of software security within their specific context. Developers in micro, small, and medium-sized enterprises (SMEs), including start-ups and sole proprietorships, are creating a significant proportion of these software products to meet the high demand. These categories of organisations face numerous challenges, including limited resources, a lack of cash flow for exploring costly security technologies, constrained managerial capabilities, working within an informal structure, regulatory burdens, and more. While there is research evidence highlighting existing security best practices designed to cater to software developers within large and structured environments, little attention has been given to the practices adopted by developers in smaller organisations.

The research study presented in this thesis focuses on understanding the security practices of developers in SMEs and how their interactions, dialogues, and negotiations with stakeholders impact these practices during the software development process. The study employed the grounded theory methodology in three phases. The first phase involved an empirical exploration of the current socio-technical factors relevant to the security practices of developers in SMEs, conducted through 25 semi-structured interviews. Next, a conceptual framework was developed to situate this study within the existing literature. And finally, a theory was generated and evaluated to provide a more grounded explanation of the experiences and challenges faced by developers in SMEs, their perception of secure software development practices, and the factors that influence these practices.

This study investigates the experiences and practices of developers in SMEs from different sectors across ten countries and four continents (Africa, Europe, North and South America). Grounded theory methodology was used to generate a theory, and follow-up interviews and scenario-based activities were analysed for theory evaluation. The first outcome of the study is the C.A.M.S. taxonomy, a classification of socio-technical factors that influence the security practices of developers in SMEs. Then, a conceptual framework is presented that illustrates the relationship between concepts in the C.A.M.S. taxonomy and existing literature. The social theory of Security Practices of Developers in SMEs is then generated to theorise the secure software development practices of developers within their specific organisational context - SMEs.

Key findings from this study indicate that the primary concern for developers in SMEs is navigating human, social, and organisational issues that affect how security practices are operationalised into practical actions and activities. Furthermore, this concern is elevated due to the socio-technical factors such as negotiating and finalising software requirements based on the client’s specifications, user needs, access to affordable, usable, and useful security technology, a security knowledge acquisition structure, and support from thriving ‘expert’ communities. Therefore, implementing security best practices in software development requires developers in SMEs to possess better social skills to navigate communities and improved negotiation skills to communicate effectively with stakeholders, thereby avoiding the loss of financial support for software projects.

Visit

ora.ox.ac.uk

Tags

Software Security Practices in Small and Medium-sized Enterprises (SMEs). Socio-technical Aspects of Secure Software Engineering

Similar

Assessing The Practices Of Software Development Projects: The Case Of Information Network Security Agency (INSA)The Role of Technical Education in the Socio-Economic Development of NigeriaSocial capital development as innovation in human resource development: A case of Technical Universities in GhanaEvaluation of the Factors influencing the Indigenous Software Products Development in NigeriaFamily Dynamics and Social Structures as Determinants of Criminal Behavior in Nigeria: A Socio-psychological PerspectiveSocial and Economic development within the North central region of Nigeria: SMEs Innovation as an Alternative

Assessing The Practices Of Software Development Projects: The Case Of Information Network Security Agency (INSA)

The main purpose of this study is to assess the project management practices of software development

The Role of Technical Education in the Socio-Economic Development of Nigeria

The high status of socio-economic development in Nigeria can only be attained if both hands are join

Social capital development as innovation in human resource development: A case of Technical Universities in Ghana

Evaluation of the Factors influencing the Indigenous Software Products Development in Nigeria

This paper evaluate the internal and external factors influencing software development in Nigeria. T

Family Dynamics and Social Structures as Determinants of Criminal Behavior in Nigeria: A Socio-psychological Perspective

This paper examines how family dynamics and social structural factors contribute to criminal behavio

Social and Economic development within the North central region of Nigeria: SMEs Innovation as an Alternative

This pragmatic study critically examines the role of Small and Medium Enterprises (SMEs) as a strate