This project aims to help organizations tailor their security efforts so developers can consistently build secure software. Version 2 introduces SECUR-E, an open framework based on COM-B and DASP research, to identify whether barriers to secure development stem from capability, opportunity, or motivation. Users can then select targeted interventions. Features include self-assessment, scoring, persona guidance, team visualizations, playbooks, and progress tracking to support better security culture. Personas reflect current conditions, not fixed identities. Results should never be used for hiring, performance, or disciplinary decisions. The framework is under expert review and community testing.
D1–D6 are the core system. The implementation, pilot, research and governance packages turn those deliverables into adoption and contribution paths.
Complete the assessment, interpret the profile and read the closest intervention pathway.
Start with D2.
Use the facilitation safeguards before preparing any aggregate team view.
Get the kit.
Review constructs and classification assumptions before proposing a study.
Open research package.
Construct definitions, item-to-COM-B mappings and research rationales for the 24 assessment items.
Best for: Researchers, reviewers, practitioners defending or challenging the model.
Status: Core · evidence-informed · validation pending
The 15–20 minute developer self-assessment: 24 rated items, optional context and three open reflections.
Best for: Developers, champions, facilitators and pilot participants.
Status: Core · practitioner-ready · item validation pending
Reverse scoring, normalization, bands, six priority rules, borderline cases, confidence ratings and worked examples.
Best for: Self-users, facilitators, psychometric and methods reviewers.
Status: Core · transparent rules · thresholds unvalidated
Individual profile template, worked example, aggregate team persona grid and dimension heatmap.
Best for: Facilitators, security practitioners and engineering sponsors.
Status: Core · reporting template · aggregation safeguards apply
Profile bars, team composition, longitudinal tracking and five conditional risk/opportunity triggers.
Best for: Facilitators, pilot teams, data visualization and tooling contributors.
Status: Core · trigger rules provisional
COM-B diagnoses, tactics, contraindications, transition pathways and team-level guidance for six patterns.
Best for: AppSec, security culture, managers, coaches and intervention reviewers.
Status: Core · evidence-anchored · effectiveness testing pending
Individual, team, four-week and organizational implementation paths, facilitation scripts and confidentiality guidance.
Download
Pilot requirements, roles, timelines, success criteria, data-handling options and FAQs.
Download
Open questions, validation roadmap, study designs, research roles and ethical data guidance.
Download
Role-specific starting questions, 30-minute, one-week and one-month paths for all major audiences.
Download
Review tracks, maintainer responsibilities, item-change rules, translation requirements and ethical escalation.
Download
Adoption, contribution, validation, practitioner impact and safety metrics with action triggers.
Download
Failure-friendly case-study structure with required anonymization checklist.
Download