Massachusetts Institute of Technology
A threat-rigidity analysis of the Apache Software Foundation's response to reported server security issues
Abstract
dc:description.abstractThere exists a broad body of literature documenting organizational responses to competitive threats, including those responses which fit into the threat-rigidity hypothesis. The purpose of this thesis is to investigate how a novel organizational form, the open-source software development community known as the Apache Software Foundation, responds to a specific type of threat: security issues reported to exist in its software products. An analysis of publicly available data from the Apache Software Foundation is conducted, the security issue handling process is described in detail, and an analysis on security issue origin, severity, and resolution is provided. Special attention is given to communication along the issue resolution process, as the threat-rigidity hypothesis predicts a reduction in the flow of information across the organization.
Degree
thesis:*- Department dc:contributor.department
- System Design and Management Program.
- Grantor dc:publisher
- Massachusetts Institute of Technology
- Year dc:date.issued
- 2006
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Shapira, Yoav
- Advisor dc:contributor.advisor
-
- Eric A. von Hippel.
Subjects
dc:subject × 1Rights
dc:rights- Statement dc:rights
-
- M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission.
- Licence dc:rights.uri
- Language dc:language.iso
- eng
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- http://hdl.handle.net/1721.1/35093
- OAI identifier oai:identifier
- oai:dspace.mit.edu:1721.1/35093