This project aims to help organizations tailor their security efforts so developers can consistently build secure software. Version 2 introduces SECUR-E, an open framework based on COM-B and DASP research, to identify whether barriers to secure development stem from capability, opportunity, or motivation. Users can then select targeted interventions. Features include self-assessment, scoring, persona guidance, team visualizations, playbooks, and progress tracking to support better security culture. Personas reflect current conditions, not fixed identities. Results should never be used for hiring, performance, or disciplinary decisions. The framework is under expert review and community testing.
SECUR-E is a structured self-assessment and intervention framework built around the COM-B model and DASP’s empirical drivers of secure-practice adoption.
The assessment creates a three-dimensional profile of Capability, Opportunity and Motivation. Transparent rules compare that profile with six behavioral patterns and attach a confidence level. The result is a hypothesis about what support may be useful under current conditions.
Change the conditions and the profile can change. That is the point.
CAP - Capability
Security knowledge, technical and non-technical skills, self-efficacy and awareness of one’s own learning needs.
Question:
Can people recognize and carry out the security work?
OPP - Opportunity
Team norms, leadership support, security expertise, time, usable tools, workflow fit and organizational resources.
Question:
Does the environment make secure work realistically possible?
MOT - Motivation
Beliefs about value and risk, habits, identity, autonomy, intrinsic responsibility and responses to security requirements.
Question:
Is security personally valued, habitual, externally driven or actively resisted?
A developer answers 24 rated items and 3 open reflections about current security skills, environment and mindset.
Output: Completed responses and three qualitative reflections.
Who: Respondent privately; a facilitator only under an agreed model.
Safety check: State the confidentiality model first. Section A is optional; pseudonyms are supported.
Common mistake: Answering how things should be rather than how they are.
Reverse-score nine items, sum each eight-item subscale, optionally normalize to 0–100 and assign bands.
Output: Capability, Opportunity and Motivation raw scores, normalized scores and bands.
Who: Respondent or trained facilitator.
Safety check: Check every score remains within 8–40. Keep the three dimensions visible.
Common mistake: Using a single composite as the basis for classification.
Apply six priority-ordered rules, then the borderline rules and mandatory confidence rating.
Output: Primary pattern, possible secondary pattern and High/Moderate/Low confidence.
Who: Self-user or trained facilitator.
Safety check: Do not force a single result when the framework recommends a mixed profile.
Common mistake: Treating the persona as a fixed identity or hiding uncertainty.
Record the individual profile or aggregate team bands and persona-pattern counts.
Output: An individual sheet or an aggregate team view for sense-making.
Who: Individual for private use; facilitator for team use.
Safety check: No persona counts for groups of four or fewer; individual sharing stays opt-in.
Common mistake: Presenting individual-level results to managers or the team.
Evaluate five conditional patterns that can override or sharpen the standard intervention approach.
Output: Risk or opportunity flags such as Enthusiast burnout, systemic low Opportunity or a Compliant transition opportunity.
Who: Facilitator or practitioner.
Safety check: Record “not applicable” when a trigger is checked but does not apply.
Common mistake: Treating a trigger as a diagnosis or using it to spotlight a person.
Read the relevant COM-B diagnosis, contraindications, tactics and team-level notes.
Output: One contextualized action with an owner, resources and review date.
Who: Team and sponsor, facilitated by a practitioner.
Safety check: Contraindications come first. Fix systemic Opportunity before blaming individual motivation.
Common mistake: Launching several generic activities without a clear mechanism.
Repeat the assessment after the review period and inspect shape changes, band shifts and persona transitions.
Output: A longitudinal comparison, retrospective and decision to sustain, adapt or stop.
Who: Individual or pilot team under the original confidentiality model.
Safety check: Review around 3 months for urgent profiles and 6 months for most others.
Common mistake: Claiming causality from a score change without supporting evidence.
A composite score can be useful for tracking the same profile over time, but it cannot explain what is producing the behavior. SECUR-E always keeps the three dimensions visible.
High CAP · Low OPP · High MOT: Enthusiast-like pattern: organizational support is the urgent lever.
Moderate CAP · High OPP · Low MOT: Compliant-like pattern: behavior may depend heavily on enforcement.
Low CAP · Low OPP · Low MOT: Foundational and systemic support are needed before motivational tactics.
Self-report captures perception, and perception shapes behavior—but experienced developers can overestimate capability, items may be interpreted differently across contexts, and current thresholds still require empirical validation.
The three-dimensional profile
The persona-pattern confidence level
Any mixed or borderline result
The current-context qualifier
The non-evaluation restriction
A review or expiry date