This project aims to help organizations tailor their security efforts so developers can consistently build secure software. Version 2 introduces SECUR-E, an open framework based on COM-B and DASP research, to identify whether barriers to secure development stem from capability, opportunity, or motivation. Users can then select targeted interventions. Features include self-assessment, scoring, persona guidance, team visualizations, playbooks, and progress tracking to support better security culture. Personas reflect current conditions, not fixed identities. Results should never be used for hiring, performance, or disciplinary decisions. The framework is under expert review and community testing.
We're building the SECUR-E framework to help engineering teams understand whether security behavior is being limited by Capability, Opportunity, Motivation, or a combination of all three, then choose support that fits the real pattern.
Tools, policies and training matter, but they do not explain every daily decision developers make under delivery pressure. One developer may need foundational knowledge. Another already has the skill and motivation but lacks time, usable tools or a trusted security contact. A third may comply only while enforcement is visible.
SECUR-E turns those differences into a structured conversation about conditions—not character.
Each step has a specific output, a responsible-use check and a corresponding project resource.
Step 1: Assess: 24 items survey + 3 reflections
Step 2: Score: CAP (Capability), OPP (Opportunity), and MOT (Motivation) bands
Step 3: Classify: Pattern + confidence
Step 4: Profile: Individual or aggregate view
Step 5: Check: Risk and opportunity triggers
Step 6: Intervene: Matched tactics and cautions
Step 7: Reassess: Review after 3-6 months
I lead an engineering team
Separate individual skill needs from environmental barriers you can change, then sponsor one team-level action (Go to Manager path).
I build software
Understand what would make secure work easier for you—skills, support or motivation—without turning the result into a label (Go to Developer path).
I run AppSec or security culture
Move from generic interventions to profile-shaped tactics, contraindications and measurable review points (Go to Security Practitioner path).
I am evaluating a pilot
See the time commitment, data-handling options, success criteria and conditions for safe organizational use (Go to Pilot path).
I study behavior or software teams
Review the constructs, thresholds, open questions and staged validation roadmap (Go to Research path).
I want to improve the OWASP project
Choose a bounded review, pilot, translation, case study, tool or research contribution (Go to Contributor path).
Each persona-pattern guide combines a COM-B diagnosis, targeted tactics, evidence anchors, transition pathways and explicit contraindications. A standard intervention can help one profile while deepening another profile’s problem. Explore the six patterns in the Personas section.
The six core deliverables work as a sequence, not six unrelated downloads (Browse all project resources in the Resources section).
D1: Understand - Scales and research grounding
D2: Assess - Developer self-assessment
D3: Interpret - Scoring and classification
D4: Discuss - Profiles and team grids
D5: Track - Visualization and triggers
D6: Act - Intervention guidance
Never use results for hiring, promotion, performance review, discipline or access control. Individual results are private by default. Team reporting is aggregate, and a low Opportunity score is feedback about the environment, not a personal failure (Read the full responsible- use guidance in the Responsible Use section).
Complete the 30-minute individual path, sponsor a 90-minute workshop, or assess whether your organization is ready for a supported pilot (Check the Developer or Pilot Organization section).
Review one subscale, test one deliverable, propose a study, translate an artifact or publish an honest field note (Check the Contributor section).
Thanks to QuestionPro for providing us over 35 question types to choose from. The advanced question types help up collect deep insights.