A Security Practices Evaluation Framework

Subjective Practice Adherence Measurement

Text-based practice adherence data collection.

Description

SP-EF includes five subjective adherence measures that can be used in surveys and interviews:

  • Usage - How often is this practice applied?
    • Values: not used, daily, weekly, monthly, quarterly, annually, less than annually.
  • Ease Of Use - How easy is this practice to use?
    • Values: Very Low, Low, Nominal, High, Very High.
  • Utility - How much does this practice assist in providing security in the software under development?
    • Values: Very Low, Low, Nominal, High, Very High.
  • Training - How well trained is the project staff in the practices being used?
    • Values: Very Low, Low, Nominal, High, Very High.
  • Effort - How much time, on average, does applying this practice take each time you apply it?
    • Ordinal values: 5 minutes or less, 5-15 minutes, 15-30 minutes, 30-minutes-1 hour, 1-4 hours, 4-8 hours, 1-2 days, 3-5 days, over 5 days
    • Ratio values: hours (fractional allowed)