DocumentCode :
968860
Title :
A Security Requirements Engineering Process in Practice
Author :
Mellado, Daniel ; Fernández-Medina, Eduardo ; Piattini, Mario
Volume :
5
Issue :
4
fYear :
2007
fDate :
7/1/2007 12:00:00 AM
Firstpage :
211
Lastpage :
217
Abstract :
Security requirements for the IT-systems are being more and more complicated due to the scale-spreading, diversification and connectivity of them, therefore it is very difficult to make an Information System secure. Without a systematic process or methodology security requirements are often retrofitted late in the development process or pursed separately from functional design. A real case study is shown in this paper demonstrating how security requirements can be obtained in a guided, intuitive and systematic way together with the other requirements and since the early stages of the software development process by applying our proposed security requirements engineering process, called SREP, which is based on providing a security resources repository and on integrating the Common Criteria into the software development lifecycle.
Keywords :
Plasmas; Security; Silicon compounds; Software requirements and specifications; information security; security; software engineering; software quality; software safety;
fLanguage :
English
Journal_Title :
Latin America Transactions, IEEE (Revista IEEE America Latina)
Publisher :
ieee
ISSN :
1548-0992
Type :
jour
DOI :
10.1109/TLA.2007.4378508
Filename :
4378508
Link To Document :
بازگشت