- 0
- 0
- 约2.22万字
- 约 15页
- 2026-02-10 发布于浙江
- 举报
GartnerResearch
HowtoMakeApplicationSecurityDeveloper-Friendly
BestinSamuel,NehaAgarwal,MaryJoy
26April2024
HowtoMakeApplicationSecurityDeveloper-Friendly
26April2024-ID-8minread
ByAnalyst(s):BestinSamuel,NehaAgarwal,MaryJoy
Initiatives:SoftwareEngineeringPractices;BuildaWorld-ClassSoftwareEngineering
Organization;SecurityofApplicationsandData;SoftwareEngineeringTechnologies
Softwareengineeringleadersholdtheirteamsresponsibleandaccountableforsecurityactivities,butteamsexperiencefrictionthatimpedessecuresoftwaredelivery.Thisresearchhighlightstwocompaniesusingdeveloper-centricapproachestoaddressdeveloperpainpointsinapplicationsecurity.
OverviewKeyFindings
■ Morethanhalfofsoftwareengineeringteamsareresponsibleforsecurityactivitiessuchasremediatingvulnerabilities,securingAPIsandembeddingsecuritycontrolsinsoftware.Butsoftwareengineeringteamsexperiencefrictionthatmakesitdif?cultforthemtoaccomplishsecuritygoals.
■ Securityguidelinescanbedif?cultfordeveloperstointerpretandapplytotheirspeci?ccontext—only42%ofsoftwareengineeringprofessionalsbelievethatsecurityrequirementsareeasyforthemtounderstand.
■ Developersoftenlackaccesstosecurityexpertiseandguidance—nearlyhalfofsoftwareengineeringprofessionalsreportthattheystruggletoaccesssecurityexpertisewhenneeded.
Gartner,Inc.|Page1of11
Recommendations
■ Easetheburdenondevelopersbyidentifyingandaddressingtheirtoppainpointsincompletingsecurityactivities,inclosecollaborationwiththesecurityteam.
■ Makesecurityguidanceconsumableandactionablebyhelpingdeveloperseasilyinterpretresultsfromtools,suchasthroughacompositevulnerabilitydashboard,andbycommunicatingsecurityguidanceindeveloper-friendlylanguage.
■ Ensureaccesstosecurityexpertisebyidentifyingandtraining“securitychampions
您可能关注的文档
- 2024评估云信任的技术和法律标准研究报告 英文版 .docx
- 2024企业AI战略的制定与部署三步指南 英文版 .docx
- 2024全球AI应用趋势年度报告 .docx
- 2024全球IPv6支持度白皮书 .docx
- 2024全球人工智能挑战框架公约:加快国际合作以确保AI有益安全包容发展 英文版 .docx
- 2024软件供应链安全风险现状报告组织的应对措施调查 英文版 .docx
- 2024软件供应链管理中的威胁研究报告软件构建与维护组织所面临的主要风险 英文版 .docx
- 2024生成式AI成功路线图:如何采取多维方法助力整个组织升级技能报告 .docx
- 2024实战实录:企业级应用安全机密治理态势白皮书 英文版 conv.docx
- 2024数据流实施流程和最佳实践报告:数据监控管理与可观测性 英文版 .docx
- 2026-2030中国硬胶囊填充机行业市场发展趋势与前景展望战略研究报告.docx
- 2025至2030中国高铁零部件行业市场占有率及投资前景评估规划报告.docx
- 2025至2030中国麻醉药品行业市场深度调研及发展潜力与投资报告.docx
- 2025至2030中国飞机高度计行业细分市场及应用领域与趋势展望研究报告.docx
- 2025至2030中国环境监测仪器行业市场发展分析及投资战略咨询报告.docx
- 2026-2030中国离岸风能行业市场发展趋势与前景展望战略分析研究报告.docx
- 2025至2030中国交流电机制造行业行情走势预测及发展机遇分析报告.docx
- 2025至2030中国影音线材行业市场占有率及投资前景评估规划报告.docx
- 2026-2030中国益生菌片行业销售规模及营销发展趋势预判研究报告.docx
- 2025至2030咖啡豆产业政府现状供需分析及市场深度研究发展前景及规划可行性分析报告.docx
原创力文档

文档评论(0)