{"id":"https://openalex.org/W4408438767","doi":"https://doi.org/10.1093/cybsec/tyaf005","title":"Software security in practice: knowledge and motivation","display_name":"Software security in practice: knowledge and motivation","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4408438767","doi":"https://doi.org/10.1093/cybsec/tyaf005"},"language":"en","primary_location":{"id":"doi:10.1093/cybsec/tyaf005","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyaf005","pdf_url":null,"source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1093/cybsec/tyaf005","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5086691875","display_name":"Hala Assal","orcid":"https://orcid.org/0000-0002-3306-0558"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Hala Assal","raw_affiliation_strings":["Department of Systems and Computer Engineering , 1125 Colonel By Drive, Ottawa, ON, K1S 5B6 ,"],"affiliations":[{"raw_affiliation_string":"Department of Systems and Computer Engineering , 1125 Colonel By Drive, Ottawa, ON, K1S 5B6 ,","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017469251","display_name":"Srivathsan G. Morkonda","orcid":"https://orcid.org/0009-0005-2218-1935"},"institutions":[{"id":"https://openalex.org/I67031392","display_name":"Carleton University","ror":"https://ror.org/02qtvee93","country_code":"CA","type":"education","lineage":["https://openalex.org/I67031392"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Srivathsan G Morkonda","raw_affiliation_strings":["School of Computer Science, Carleton University , 1125 Colonel By Drive, Ottawa, ON, K1S 5B6 ,"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Carleton University , 1125 Colonel By Drive, Ottawa, ON, K1S 5B6 ,","institution_ids":["https://openalex.org/I67031392"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039182320","display_name":"Muhammad Arif","orcid":"https://orcid.org/0000-0002-9996-9844"},"institutions":[{"id":"https://openalex.org/I67031392","display_name":"Carleton University","ror":"https://ror.org/02qtvee93","country_code":"CA","type":"education","lineage":["https://openalex.org/I67031392"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Muhammad Zaid Arif","raw_affiliation_strings":["School of Computer Science, Carleton University , 1125 Colonel By Drive, Ottawa, ON, K1S 5B6 ,"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Carleton University , 1125 Colonel By Drive, Ottawa, ON, K1S 5B6 ,","institution_ids":["https://openalex.org/I67031392"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5048641215","display_name":"Sonia Chiasson","orcid":"https://orcid.org/0000-0001-7314-2198"},"institutions":[{"id":"https://openalex.org/I67031392","display_name":"Carleton University","ror":"https://ror.org/02qtvee93","country_code":"CA","type":"education","lineage":["https://openalex.org/I67031392"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Sonia Chiasson","raw_affiliation_strings":["School of Computer Science, Carleton University , 1125 Colonel By Drive, Ottawa, ON, K1S 5B6 ,"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Carleton University , 1125 Colonel By Drive, Ottawa, ON, K1S 5B6 ,","institution_ids":["https://openalex.org/I67031392"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5086691875"],"corresponding_institution_ids":[],"apc_list":{"value":1864,"currency":"USD","value_usd":1864},"apc_paid":{"value":1864,"currency":"USD","value_usd":1864},"fwci":3.3527,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.89806674,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":"11","issue":"1","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10430","display_name":"Software Engineering Techniques and Practices","score":0.994700014591217,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11675","display_name":"Open Source Software Innovations","score":0.9797000288963318,"subfield":{"id":"https://openalex.org/subfields/1706","display_name":"Computer Science Applications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.5126868486404419},{"id":"https://openalex.org/keywords/knowledge-management","display_name":"Knowledge management","score":0.4188680052757263},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.3910241425037384},{"id":"https://openalex.org/keywords/applied-psychology","display_name":"Applied psychology","score":0.3272954821586609}],"concepts":[{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.5126868486404419},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.4188680052757263},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.3910241425037384},{"id":"https://openalex.org/C75630572","wikidata":"https://www.wikidata.org/wiki/Q538904","display_name":"Applied psychology","level":1,"score":0.3272954821586609}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1093/cybsec/tyaf005","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyaf005","pdf_url":null,"source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1093/cybsec/tyaf005","is_oa":true,"landing_page_url":"https://doi.org/10.1093/cybsec/tyaf005","pdf_url":null,"source":{"id":"https://openalex.org/S2735156331","display_name":"Journal of Cybersecurity","issn_l":"2057-2085","issn":["2057-2085","2057-2093"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310311648","host_organization_name":"Oxford University Press","host_organization_lineage":["https://openalex.org/P4310311648","https://openalex.org/P4310311647"],"host_organization_lineage_names":["Oxford University Press","University of Oxford"],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Cybersecurity","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G3110883528","display_name":null,"funder_award_id":"SMFSA-566403-2022","funder_id":"https://openalex.org/F4320334593","funder_display_name":"Natural Sciences and Engineering Research Council of Canada"},{"id":"https://openalex.org/G419407966","display_name":null,"funder_award_id":"RGPIN-2021-03808","funder_id":"https://openalex.org/F4320334593","funder_display_name":"Natural Sciences and Engineering Research Council of Canada"},{"id":"https://openalex.org/G5486240051","display_name":null,"funder_award_id":"RGPIN-2023-04653","funder_id":"https://openalex.org/F4320334593","funder_display_name":"Natural Sciences and Engineering Research Council of Canada"}],"funders":[{"id":"https://openalex.org/F4320334593","display_name":"Natural Sciences and Engineering Research Council of Canada","ror":"https://ror.org/01h531d29"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":92,"referenced_works":["https://openalex.org/W641490396","https://openalex.org/W1499005519","https://openalex.org/W1604658196","https://openalex.org/W1658908529","https://openalex.org/W1677321822","https://openalex.org/W1758876287","https://openalex.org/W1968335087","https://openalex.org/W1973239702","https://openalex.org/W1994287528","https://openalex.org/W2011698232","https://openalex.org/W2033019352","https://openalex.org/W2038889476","https://openalex.org/W2041085983","https://openalex.org/W2052729098","https://openalex.org/W2059507980","https://openalex.org/W2084389751","https://openalex.org/W2093071171","https://openalex.org/W2106371080","https://openalex.org/W2130758759","https://openalex.org/W2139894798","https://openalex.org/W2146691185","https://openalex.org/W2158297335","https://openalex.org/W2160858448","https://openalex.org/W2350778671","https://openalex.org/W2511044583","https://openalex.org/W2541261609","https://openalex.org/W2549510823","https://openalex.org/W2563098966","https://openalex.org/W2585818648","https://openalex.org/W2596082134","https://openalex.org/W2698406033","https://openalex.org/W2718813204","https://openalex.org/W2732351623","https://openalex.org/W2792247140","https://openalex.org/W2805916231","https://openalex.org/W2892368422","https://openalex.org/W2902999784","https://openalex.org/W2909889155","https://openalex.org/W2914630606","https://openalex.org/W2936292087","https://openalex.org/W2964144088","https://openalex.org/W2966008409","https://openalex.org/W2972780856","https://openalex.org/W2978452220","https://openalex.org/W3007797095","https://openalex.org/W3128132191","https://openalex.org/W3133930529","https://openalex.org/W3160144036","https://openalex.org/W3182351169","https://openalex.org/W3212201636","https://openalex.org/W4200341685","https://openalex.org/W4225086772","https://openalex.org/W4236561953","https://openalex.org/W4237307340","https://openalex.org/W4239249613","https://openalex.org/W4239371203","https://openalex.org/W4242883546","https://openalex.org/W4288057765","https://openalex.org/W4308643158","https://openalex.org/W4309700043","https://openalex.org/W4319430371","https://openalex.org/W4362554685","https://openalex.org/W4366562575","https://openalex.org/W4390112232","https://openalex.org/W4391307510","https://openalex.org/W4391432468","https://openalex.org/W4391904135","https://openalex.org/W4396868147","https://openalex.org/W4396882206","https://openalex.org/W4405181105","https://openalex.org/W6620729607","https://openalex.org/W6628996700","https://openalex.org/W6636900549","https://openalex.org/W6646893606","https://openalex.org/W6656087605","https://openalex.org/W6681517862","https://openalex.org/W6742430978","https://openalex.org/W6746690242","https://openalex.org/W6754369729","https://openalex.org/W6758396222","https://openalex.org/W6775681617","https://openalex.org/W6778324729","https://openalex.org/W6781832789","https://openalex.org/W6800002011","https://openalex.org/W6800577800","https://openalex.org/W6800603138","https://openalex.org/W6804493738","https://openalex.org/W6810573964","https://openalex.org/W6845374404","https://openalex.org/W6847025045","https://openalex.org/W6849640913","https://openalex.org/W6892170452"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"Abstract":[0],"Developing":[1],"secure":[2,16],"software":[3,22,47,67],"remains":[4],"a":[5,94],"challenge":[6],"for":[7,86,104],"developers":[8,48,52,64,101,129,167],"despite":[9],"the":[10,25,30,120],"availability":[11],"of":[12,96,119,146],"security":[13,23,27,56,68,75,88,106,124,151,170,174],"resources":[14],"and":[15,29,58,77,102,171],"development":[17,34,90],"tools.":[18],"Common":[19],"factors":[20,60],"affecting":[21],"include":[24],"developer\u2019s":[26],"awareness":[28],"rationales":[31],"behind":[32],"their":[33,154,173],"decisions":[35],"with":[36,46,143],"respect":[37],"to":[38,49,150,165,168],"security.":[39],"In":[40],"this":[41,141],"work,":[42],"we":[43,160],"conducted":[44],"interviews":[45],"examine":[50],"how":[51,164],"in":[53,89],"organizations":[54],"acquire":[55],"knowledge,":[57],"what":[59],"motivate":[61,166],"or":[62],"prevent":[63],"from":[65],"adopting":[66],"practices.":[69,175],"Our":[70],"analysis":[71],"reveals":[72],"that":[73,82],"developers\u2019":[74],"knowledge":[76],"motivations":[78],"are":[79,83,126,130],"intertwined":[80],"aspects":[81],"both":[84],"important":[85],"promoting":[87],"teams.":[91,155],"We":[92],"identified":[93],"variety":[95],"learning":[97,110],"opportunities":[98],"used":[99],"by":[100,113,138],"employers":[103],"increasing":[105],"awareness,":[107],"including":[108],"in-context":[109],"activities":[111],"preferred":[112],"developers.":[114],"Based":[115,156],"on":[116,157,163],"our":[117,144,158],"application":[118],"self-determination":[121],"theory,":[122],"better":[123],"outcomes":[125,152],"expected":[127],"when":[128],"internally":[131],"driven":[132],"toward":[133],"security,":[134],"rather":[135],"than":[136],"motivated":[137],"external":[139],"factors;":[140],"aligns":[142],"interpretation":[145],"participants\u2019":[147],"descriptions":[148],"relating":[149],"within":[153],"analysis,":[159],"provide":[161],"ideas":[162],"internalize":[169],"improve":[172]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-03-24T08:02:53.985720","created_date":"2025-10-10T00:00:00"}
