A comparison of security requirements engineering methods

Springer Science and Business Media LLC - Tập 15 - Trang 7-40 - 2009
Benjamin Fabian1, Seda Gürses2, Maritta Heisel3, Thomas Santen4, Holger Schmidt3
1Institute of Information Systems, Humboldt-Universität zu Berlin, Berlin, Germany
2ESAT/COSIC, K.U. Leuven, Leuven-Heverlee, Belgium
3Software Engineering, University of Duisburg-Essen, Duisburg, Germany
4European Microsoft Innovation Center, Aachen, Germany

Tóm tắt

This paper presents a conceptual framework for security engineering, with a strong focus on security requirements elicitation and analysis. This conceptual framework establishes a clear-cut vocabulary and makes explicit the interrelations between the different concepts and notions used in security engineering. Further, we apply our conceptual framework to compare and evaluate current security requirements engineering approaches, such as the Common Criteria, Secure Tropos, SREP, MSRA, as well as methods based on UML and problem frames. We review these methods and assess them according to different criteria, such as the general approach and scope of the method, its validation, and quality assurance capabilities. Finally, we discuss how these methods are related to the conceptual framework and to one another.

Tài liệu tham khảo