A Readiness Model for Security Requirements Engineering

被引:27
|
作者
Mufti, Yusuf [1 ]
Niazi, Mahmood [1 ]
Alshayeb, Mohammad [1 ]
Mahmood, Sajjad [1 ]
机构
[1] King Fahd Univ Petr & Minerals, Dept Informat & Comp Sci, Dhahran 31261, Saudi Arabia
来源
IEEE ACCESS | 2018年 / 6卷
关键词
Readiness model; secure requirements engineering; SOFTWARE PROCESS IMPROVEMENT; FRAMEWORK;
D O I
10.1109/ACCESS.2018.2840322
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The focus on secure software development has been growing steadily in all phases of the software development life cycle. Security awareness in the requirements engineering stage of software development is important in building secure software. One of the major issues faced by the software industry is that many organizations undertake secure software development initiatives without knowing whether they are ready to undertake them. Currently, there is no model to measure the readiness of security requirements engineering in an organization. The objective of this paper is to develop a security requirements engineering readiness model (SRERM) to enable organizations to assess their security requirements engineering (SRE) readiness levels. In order to achieve this goal, a systematic mapping study was conducted to identify the relevant studies in the SRE domain. A total of 104 primary studies were identified, and available evidence was synthesized into 12 security requirements categories and 76 best practices to build a SRERM. Initially, two case studies were conducted in order to evaluate the SRERM in a real-world environment. Based on the outcomes of the two case studies, some modifications were proposed to further improve the SRERM. After modifying the SRERM, two more case studies were conducted in order to evaluate the modifications made to the SRERM. The case study results indicate that the SRERM has the ability to identify the readiness levels of SRE in the software industry.
引用
收藏
页码:28611 / 28631
页数:21
相关论文
共 50 条
  • [1] Security & Safety by Model-based Requirements Engineering
    Japs, Sergej
    [J]. 2020 28TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE'20), 2020, : 422 - 427
  • [2] Model driven security engineering for the realization of dynamic security requirements in collaborative systems
    Alam, Muhammad
    [J]. MODELS IN SOFTWARE ENGINEERING, 2007, 4364 : 278 - 287
  • [3] Security and trust requirements engineering
    Giorgini, P
    Massacci, F
    Zannone, N
    [J]. FOUNDATIONS OF SECURITY ANALYSIS AND DESIGN III, 2005, 3655 : 237 - 272
  • [4] Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid
    Stojkov, Milan
    Dalcekovic, Nikola
    Markoski, Branko
    Milosavljevic, Branko
    Sladic, Goran
    [J]. ENERGIES, 2021, 14 (21)
  • [5] Towards the Model-Driven Engineering of Security Requirements for Embedded Systems
    Roudier, Yves
    Idrees, Muhammad Sabir
    Apvrille, Ludovic
    [J]. 2013 3RD INTERNATIONAL WORKSHOP ON MODEL-DRIVEN REQUIREMENTS ENGINEERING (MODRE), 2013, : 55 - 64
  • [6] Model Oriented Security Requirements Engineering (MOSRE) Framework for Web Applications
    Salini, P.
    Kanmani, S.
    [J]. ADVANCES IN COMPUTING AND INFORMATION TECHNOLOGY, VOL 2, 2013, 177 : 341 - +
  • [7] Applying a security requirements engineering process
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    [J]. COMPUTER SECURITY - ESORICS 2006, PROCEEDINGS, 2006, 4189 : 192 - 206
  • [8] A comparison of security requirements engineering methods
    Fabian, Benjamin
    Guerses, Seda
    Heisel, Maritta
    Santen, Thomas
    Schmidt, Holger
    [J]. REQUIREMENTS ENGINEERING, 2010, 15 (01) : 7 - 40
  • [9] Survey and analysis on Security Requirements Engineering
    Salini, P.
    Kanmani, S.
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2012, 38 (06) : 1785 - 1797
  • [10] Position on Metrics for Security in Requirements Engineering
    Kundi, Mahwish
    Chitchyan, Ruzanna
    [J]. 2014 IEEE 1ST INTERNATIONAL WORKSHOP ON REQUIREMENTS ENGINEERING AND TESTING (RET), 2014, : 29 - 31