"It's not my responsibility to write them": An Empirical Study of Software Product Managers and Security Requirements

Houda Naji, Felix Reichmann, Tobias Bruns, and M. Angela Sasse, Ruhr University Bochum; Alena Naiakshina, University of Cologne

Product managers play a key role in defining and prior- itizing requirements overall, yet little is known about how they approach security requirements (SRs). To address this gap, we conducted a study with 50 participants in product management roles. Our 60-minute online study consisted of a requirement-writing task, followed by a questionnaire. Our analysis shows that, while security is not the top priority for our participants, only 10% did not include any SRs, and only 4% did not identify any security risks in their tasks. Most par- ticipants viewed SRs as a shared responsibility that should be discharged in collaboration with other roles - security experts, architects, and development teams - but without a clear as- signment or process. There is an assumption that security will be taken care of, somehow, in the process, with 54% believ- ing that security will be addressed, even when not explicitly stated in the requirements. To mitigate the concern of "diffu- sion of responsibility" for security, we identified a number of recommendations to involve stakeholders to address security throughout the development process.

Category: 
Short Presentation

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {309822,
author = {Houda Naji and Felix Reichmann and Tobias Bruns and M. Angela Sasse and Alena Naiakshina},
title = {"It{\textquoteright}s not my responsibility to write them": An Empirical Study of Software Product Managers and Security Requirements},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
isbn = {978-1-939133-52-6},
address = {Seattle, WA},
pages = {2245--2264},
url = {https://www.usenix.org/conference/usenixsecurity25/presentation/naji},
publisher = {USENIX Association},
month = aug
}