In a year-long study, we observed an agile software development team to understand how it establishes security practices following a security consultancy. This included in-situ observation at a security workshop and interviews with developers and management. In our long paper for CSCW 2017 we found that the consultancy helped build understanding, but was not sufficient to shift organizational routines.
Continue reading