Click here to Skip to main content
15,884,298 members

Survey Results

Who is responsible for a software system's security?

Survey period: 24 Oct 2016 to 31 Oct 2016

A hardcoded password, a SQL injection, a system with a known issue, or not changing the default password. There can be lots of fingerprints on that knife.

OptionVotes% 
The user using the system51214.74
The person who recommended the use of the system1975.67
The person who installs the system45713.15
The developer who built the system80223.09
The person who decided on the default settings of the system50914.65
None of the above2,51572.39
Respondents were allowed to choose more than one answer; totals may not add up to 100%



 
GeneralRe: Most of all the developer. Pin
den2k8824-Oct-16 2:54
professionalden2k8824-Oct-16 2:54 
GeneralRe: Most of all the developer. Pin
Philippe Mori24-Oct-16 4:48
Philippe Mori24-Oct-16 4:48 
GeneralRe: Most of all the developer. Pin
Philippe Mori24-Oct-16 6:55
Philippe Mori24-Oct-16 6:55 
GeneralEveryone is. Pin
Afzaal Ahmad Zeeshan23-Oct-16 22:19
professionalAfzaal Ahmad Zeeshan23-Oct-16 22:19 
GeneralSalma Hayek... PinPopular
Sander Rossel23-Oct-16 21:21
professionalSander Rossel23-Oct-16 21:21 
GeneralRe: Salma Hayek... Pin
Jörgen Andersson24-Oct-16 0:46
professionalJörgen Andersson24-Oct-16 0:46 
GeneralRe: Salma Hayek... Pin
OriginalGriff24-Oct-16 5:19
mveOriginalGriff24-Oct-16 5:19 
GeneralMany Pin
den2k8823-Oct-16 20:58
professionalden2k8823-Oct-16 20:58 
* The developer who wrote the software: he's responsible of the absence of security bugs and backdoors, and of writing the documentation. Also he has to implement correct security practices (avoid the possibility of using clear text outside of debug environment, avoid then usage of weakly encryption methods...).

* The person who installs the software: he's resposible of reading the documentation and applying the proper policies. If developers use the best and safest technologies and the installer trumps them with shared accounts and unshielded servers there's nothing to be done.

* The user: please avoid post its with passwords, installation of wareZ on the clien machines, looking at "The newest new funny videos with cats!!" on the workstation.

The person who recommended the use of the system isn't responsible of the bad installation and usage of such. The person who decided on the default settings of the system may have a little responsibility but it's not his fault if the installer is incompetent. He may have had its reasons to put up those defaults.
DURA LEX, SED LEX
GCS d--- s-/++ a- C++++ U+++ P- L- E-- W++ N++ o+ K- w+++ O? M-- V? PS+ PE- Y+ PGP t++ 5? X R++ tv-- b+ DI+++ D++ G e++>+++ h--- ++>+++ y+++*      Weapons extension: ma- k++ F+2 X

If you think 'goto' is evil, try writing an Assembly program without JMP. -- TNCaver

When I was six, there were no ones and zeroes - only zeroes. And not all of them worked. -- Ravi Bhavnani

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.