Security quality requirements engineering (SQUARE) methodology 论文

2005ACM SIGSOFT Software Engineering Notes引用 320
Information and Cyber SecuritySoftware Engineering Techniques and PracticesSoftware Engineering Research

摘要

Requirements engineering, a vital component in successful project development, often neglects sufficient attention to security concerns. Further, industry lacks a useful model for incorporating security requirements into project development. Studies show that upfront attention to security saves the economy billions of dollars. Industry is thus in need of a model to examine security and quality requirements in the development stages of the production lifecycle.In this paper, we examine a methodology for both eliciting and prioritizing security requirements on a development project within an organization. We present a model developed by the Software Engineering Institute's Networked Systems Survivability (NSS) Program, and then examine two case studies where the model was applied to a client system. The NSS Program continues to develop this useful model, which has proven effective in helping an organization understand its security posture.

相关技术

暂无数据

相关事件

暂无数据

相关文章

暂无数据