{"title":"Secure Software Development Assimilation: Effects of External Pressures and Roles of Internal Factors","authors":"Mingqiu Song, Donghao Chen, E. Mkoba","doi":"10.4018/ijsse.2014070103","DOIUrl":null,"url":null,"abstract":"Drawing upon institutional theory, this article develops an extended model to test and verify the effects of external institutional pressures on Secure Software Development (SSD) assimilation and the roles of internal critical factors. The empirical results are based on 86 survey data from respondents of related organizations in United Kingdom, Hong Kong, and Mainland China who have related project experience about SSD. Results from partial least squares (PLS) analysis suggest that both mimetic and coercive pressures have indirect effects on SSD assimilation with the distal mediation of top management. Normative pressures positively affect SSD assimilation with the full mediation of secure software champion. Results also suggest that secure software champion plays another partial mediation between top management participation and SSD assimilation. This paper highlights the important role of secure software champion for its dually mediating effects on both external and internal forces during SSD assimilation process.","PeriodicalId":89158,"journal":{"name":"International journal of secure software engineering","volume":"72 1","pages":"32-55"},"PeriodicalIF":0.0000,"publicationDate":"2014-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of secure software engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/ijsse.2014070103","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
Drawing upon institutional theory, this article develops an extended model to test and verify the effects of external institutional pressures on Secure Software Development (SSD) assimilation and the roles of internal critical factors. The empirical results are based on 86 survey data from respondents of related organizations in United Kingdom, Hong Kong, and Mainland China who have related project experience about SSD. Results from partial least squares (PLS) analysis suggest that both mimetic and coercive pressures have indirect effects on SSD assimilation with the distal mediation of top management. Normative pressures positively affect SSD assimilation with the full mediation of secure software champion. Results also suggest that secure software champion plays another partial mediation between top management participation and SSD assimilation. This paper highlights the important role of secure software champion for its dually mediating effects on both external and internal forces during SSD assimilation process.