A Security Practices Evaluation Framework
Subjective Practice Adherence Measurement
Text-based practice adherence data collection.
Description
SP-EF includes five subjective adherence measures that can be used in surveys and interviews:
- Usage - How often is this practice applied?
- Values: not used, daily, weekly, monthly, quarterly, annually, less than annually.
- Ease Of Use - How easy is this practice to use?
- Values: Very Low, Low, Nominal, High, Very High.
- Utility - How much does this practice assist in providing security in the software under development?
- Values: Very Low, Low, Nominal, High, Very High.
- Training - How well trained is the project staff in the practices being used?
- Values: Very Low, Low, Nominal, High, Very High.
- Effort - How much time, on average, does applying this practice take each time you apply it?
- Ordinal values: 5 minutes or less, 5-15 minutes, 15-30 minutes, 30-minutes-1 hour, 1-4 hours, 4-8 hours, 1-2 days, 3-5 days, over 5 days
- Ratio values: hours (fractional allowed)