Reusable security requirements repository implementation based on application/system components
Author(s)
Sonmez, Fatma Ferda
Günel Kılıç, Banu
Type
Journal Article
Abstract
Forming high quality requirements has a direct impact on project success. Gathering security requirements could be challenging, since it demands a multidisciplinary approach and security expertise. Security requirements repository enables an effective alternative for addressing this challenge. The main objective of this paper is to present the design of a practical repository model for reusable security requirements, which is easy to use and understand for even non-security experts. The paper also portrays an approach and a software tool for using this model to determine subtle security requirements for improved coverage. Proposed repository consists of attributes determined by examining common security problems covered in state-of-the-art publications. A test repository was prepared using specification files and Common Criteria documents. The outcomes of applying the proposed model were compared with the sample requirement sets included in the state-of-the-art publications. The results reveal that in the absence of a security requirements repository, key security points can be missed. Repository improves the completeness of the security terms with reasonable effort.
Date Issued
2021-12-06
Date Acceptance
2021-12-01
Citation
IEEE Access, 2021, 9, pp.165966-165988
ISSN
2169-3536
Publisher
Institute of Electrical and Electronics Engineers
Start Page
165966
End Page
165988
Journal / Book Title
IEEE Access
Volume
9
Copyright Statement
© 2021 The Author(s). This work is licensed under a Creative Commons Attribution 4.0 License. For more information, see https://creativecommons.org/licenses/by/4.0/
License URL
Identifier
https://ieeexplore.ieee.org/abstract/document/9638498
Subjects
08 Information and Computing Sciences
09 Engineering
10 Technology
Publication Status
Published
Date Publish Online
2021-12-06