classroom
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Graduate developers lacking security skills

New government-sponsored research finds most IT undergraduates get less than five hours security training

Phil Muncaster, IT Week 13 May 2008
ADVERTISEMENT

The latest generation of software developers have little to no experience in how to code secure applications, UK government-sponsored research has revealed.

The government-funded advisory body the Cyber Security Knowledge Transfer Network (KTN) analysed statistics from 75 UK universities which run courses to train future software developers.

It found that only 20 per cent of UK computing undergraduates get more than five hours education on software security. The other 80 per cent receive less than five hours.

"We're not expecting to turn out graduates who are experts in secure software development, but 80 per cent are hardly even being told about it," said John Harrison, chair of the Cyber Security KTN Special Interest Group in Secure Software Development. "If we can create awareness in the next generation of software developers, then when they go out into industry they can create awareness in their own organisations."

Harrison added that the issue of training IT undergraduates in security has not been resolved because "there is no clear owner of the problem".

"There is a huge body of knowledge in the security industry on what can go wrong," he argued. "We need to transfer that knowledge into software development."

Hadrian James of IT management software vendor Compuware, argued that engineering security into the development process from the start removes the need for costly redesigns.

"There is a substantial amount of contact time in a three year undergraduate course," he added. "A lot of time is spent on object design, but security should be one of those objects."

See also:

Rich Green, SunSun uses JavaOne to groom new developers  07 May 2008
SonicWall is offering a free deep packet inspection engine  01 May 2008
MS HQMicrosoft has posted reams of protocol documentation on its MSDN sites  09 Apr 2008
google logoNew application SDK released to the first 10,000 lucky developers  08 Apr 2008
the lawCompuware research shows firms are exposing customer data during application testing  08 Jan 2008

All Developer

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | S4C
  Datblygydd Delphi - Oracle - Delphi - Oracle Developer Datblygydd Delphi - Oracle Mae S4C yn gwahodd ceisiadau ar gyfer y swydd uchod a leolir o fewn y Gyfarwyddiaeth Darlledu a Dosbarthu. Dylai fod ... more >
Colindale (C1905), United Kingdom | NHS Blood and Transplant
 Operations Engineer, £28,313 - £37,326 pa plus High Cost Area Supplement, Colindale (C1905) About us The National Blood Service is an integral and vital part of the NHS. Our two million volunteer donors contribute 1.6 ... more >
United Kingdom | MI5 Security Service
Network and Systems Engineers Working for MI5 you will use your expertise to protect the UK from terrorism, espionage and other threats to national security. You'll be joining a team that provides essential technical analysis ... more >
United Kingdom | MI5 Security Service
Software Developer/SQL Specialists Working for MI5 you will use your expertise to protect the UK from terrorism, espionage and other threats to national security. You'll be joining a team that provides essential technical analysis and ... more >
More job opportunities