<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-19T10:13:27Z</responseDate><request verb="GetRecord" identifier="oai:dspace.mit.edu:1721.1/35093" metadataPrefix="dim">https://dspace.mit.edu/server/oai/request</request><GetRecord><record><header><identifier>oai:dspace.mit.edu:1721.1/35093</identifier><datestamp>2022-01-13T07:55:19Z</datestamp><setSpec>com_1721.1_7582</setSpec><setSpec>com_1721.1_7581</setSpec><setSpec>col_1721.1_131023</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="advisor" lang="en_US">Eric A. von Hippel.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author" lang="en_US">Shapira, Yoav</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="other" lang="en_US">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department" lang="en_US">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2006-12-18T20:39:47Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2006-12-18T20:39:47Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="copyright" lang="en_US">2006</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued" lang="en_US">2006</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">http://hdl.handle.net/1721.1/35093</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="oclc" lang="en_US">71333049</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Thesis (S.M.)--Massachusetts Institute of Technology, System Design and Management Program, 2006.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Page 141 blank.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Includes bibliographical references (p. 84-87).</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">There exists a broad body of literature documenting organizational responses to competitive threats, including those responses which fit into the threat-rigidity hypothesis. The purpose of this thesis is to investigate how a novel organizational form, the open-source software development community known as the Apache Software Foundation, responds to a specific type of threat: security issues reported to exist in its software products. An analysis of publicly available data from the Apache Software Foundation is conducted, the security issue handling process is described in detail, and an analysis on security issue origin, severity, and resolution is provided. Special attention is given to communication along the issue resolution process, as the threat-rigidity hypothesis predicts a reduction in the flow of information across the organization.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">(cont.) The results show that this organization defies some central predictions of the hypothesis: there is little reduction in information flow, little or no centralization in decision-making, and no loss of group-level focus. The research results are framed within the literature of user-led innovation and organizational behavior. The implications for traditional software development organizations are discussed, and recommendations for further research are provided.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="statementofresponsibility" lang="en_US">by Yoav Shapira.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="degree" lang="en_US">S.M.</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="extent" lang="en_US">141 p.</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="extent">8159896 bytes</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="extent">8167337 bytes</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="dc" element="language" qualifier="iso" lang="en_US">eng</dim:field>
   <dim:field mdschema="dc" element="publisher" lang="en_US">Massachusetts Institute of Technology</dim:field>
   <dim:field mdschema="dc" element="rights" lang="en_US">M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission.</dim:field>
   <dim:field mdschema="dc" element="rights" qualifier="uri">http://dspace.mit.edu/handle/1721.1/7582</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="title" lang="en_US">A threat-rigidity analysis of the Apache Software Foundation's response to reported server security issues</dim:field>
   <dim:field mdschema="dc" element="type" lang="en_US">Thesis</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="dspace" element="authorsordered">false</dim:field>
   <dim:field mdschema="dspace" element="entity" qualifier="type">Publication</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="cerif" element="openaire" authority="" confidence="-1">&lt;Publication xmlns="https://www.openaire.eu/cerif-profile/1.1/" id="2dd086a6-1473-41f7-b71f-2d75a1e53e01">
	&lt;Type xmlns="https://www.openaire.eu/cerif-profile/vocab/COAR_Publication_Types">http://purl.org/coar/resource_type/c_1843&lt;/Type>
	&lt;Language>eng&lt;/Language>
   	&lt;Title>A threat-rigidity analysis of the Apache Software Foundation&amp;apos;s response to reported server security issues&lt;/Title>
   	&lt;PublishedIn>
    	&lt;Publication>
      	&lt;/Publication>
   	&lt;/PublishedIn>
   	&lt;PublicationDate>2006&lt;/PublicationDate>
   	&lt;Authors>
      	&lt;Author>
        	&lt;DisplayName>Shapira, Yoav&lt;/DisplayName>
         	&lt;Affiliation>
         		&lt;OrgUnit>
         		&lt;/OrgUnit>
         	&lt;/Affiliation>
      	&lt;/Author>
	&lt;/Authors>
   	&lt;Editors>
	&lt;/Editors>
    &lt;Publishers>
        &lt;Publisher>
            &lt;DisplayName>Massachusetts Institute of Technology&lt;/DisplayName>
            &lt;OrgUnit />
        &lt;/Publisher>
    &lt;/Publishers>
    &lt;License>http://dspace.mit.edu/handle/1721.1/7582&lt;/License>
    &lt;Keyword>System Design and Management Program.&lt;/Keyword>
   	&lt;Abstract>There exists a broad body of literature documenting organizational responses to competitive threats, including those responses which fit into the threat-rigidity hypothesis. The purpose of this thesis is to investigate how a novel organizational form, the open-source software development community known as the Apache Software Foundation, responds to a specific type of threat: security issues reported to exist in its software products. An analysis of publicly available data from the Apache Software Foundation is conducted, the security issue handling process is described in detail, and an analysis on security issue origin, severity, and resolution is provided. Special attention is given to communication along the issue resolution process, as the threat-rigidity hypothesis predicts a reduction in the flow of information across the organization.&lt;/Abstract>
   	&lt;Abstract>(cont.) The results show that this organization defies some central predictions of the hypothesis: there is little reduction in information flow, little or no centralization in decision-making, and no loss of group-level focus. The research results are framed within the literature of user-led innovation and organizational behavior. The implications for traditional software development organizations are discussed, and recommendations for further research are provided.&lt;/Abstract>
	&lt;Access xmlns="http://purl.org/coar/access_right" 
    >
    &lt;/Access>
&lt;/Publication>
</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>