skip to main content
10.1145/1940941.1940946acmotherconferencesArticle/Chapter ViewAbstractPublication PagesinfoseccdConference Proceedingsconference-collections
research-article

Is teaching with security in mind working?

Published:01 October 2010Publication History

ABSTRACT

Security topics have been taught for some time at universities. The most common approach has been to teach a required topic, and then introduce a security module later in the course. We have been promoting the notion of teaching security at the same time as main course's material. We found that this helps students to accept the idea of writing secure code at an early stage and encourages them to focus on the security issues before they start coding. We proposed teaching secure practices as the default model presented to the students, facilitating the adoption of those practices. Over a period of one year we promoted the concept among our colleagues both in our school and at teaching conferences. This paper is a report that shows where we are one year after of implementation of Teaching with Security in Mind.

References

  1. Carrier-Sensitive Routing User Guide http://www.cisco.com/en/US/products/sw/voicesw/ps4371/products_user_guide_book09186a00801e88f0.htmlGoogle ScholarGoogle Scholar
  2. Cenzic: Web Application Security Trends Report, Q1-Q2, 2009 http://www.cenzic.com/downloads/Cenzic_AppSecTrends_Q1-Q2-2009.pdfGoogle ScholarGoogle Scholar
  3. Bandhakavi, S., Bisht, P., Madhusudan, P., Venkatakrishnan, V. "CANDID: Preventing SQL Injection Attacks Using Dynamic Candidate Evaluations," In Proceedings of ACM Conference on Computer and Communications Security 2007. pp 12--24 Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. Walden, J. "Integrating Web Application Security into the IT Curriculum," In Proceedings of the 9th ACM SIGITE conference on Information technology education. pp 187--192 Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. Guimaraes, M., Murray, M. "Using animation courseware in the teaching of database security," In proceedings of SIGITE 2007. pp 253--258 Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. Google Code Search http://www.google.com/codesearchGoogle ScholarGoogle Scholar
  7. Boyarsky, J. Batching Select Statements in JDBC http://www.javaranch.com/journal/200510/Journal200510.jsp#a2Google ScholarGoogle Scholar

Index Terms

  1. Is teaching with security in mind working?

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Other conferences
            InfoSecCD '10: 2010 Information Security Curriculum Development Conference
            October 2010
            187 pages
            ISBN:9781450302029
            DOI:10.1145/1940941

            Copyright © 2010 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 1 October 2010

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • research-article

            Acceptance Rates

            Overall Acceptance Rate18of23submissions,78%

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader