• DocumentCode
    3692751
  • Title

    Instantiating a model for structuring and reusing security requirements sources

  • Author

    Christian Schmitt;Peter Liggesmeyer

  • Author_Institution
    Siemens AG, Munich, Germany
  • fYear
    2015
  • fDate
    8/25/2015 12:00:00 AM
  • Firstpage
    25
  • Lastpage
    30
  • Abstract
    This paper presents a model for structuring and reusing security requirements sources. The model serves as blueprint for the development of an organization-specific repository which provides relevant security requirements sources such as security information and knowledge sources and relevant compliance obligations in a structured and reusable form. The resulting repository is intended to be used by development teams during the elicitation and analysis of security requirements with the goal to understand the security problem space, incorporate all relevant requirements sources and to avoid unnecessary effort for identifying, understanding and correlating applicable security requirements sources on a project-wise basis. We start with an overview and categorization of important security requirements sources, followed by the description of the generic model. To demonstrate the applicability and benefits of the model, the instantiation approach and details of the resulting repository of security requirements sources are presented.
  • Keywords
    "Security","Organizations","Requirements engineering","Guidelines","Data privacy","Software"
  • Publisher
    ieee
  • Conference_Titel
    Evolving Security and Privacy Requirements Engineering (ESPRE), 2015 IEEE 2nd Workshop on
  • Type

    conf

  • DOI
    10.1109/ESPRE.2015.7330164
  • Filename
    7330164