The importance of incorporating security requirements within system architecture rather than incorporating retro fitting controls to an insecure design

Stephen Wing · Computer Fraud & Security · 2006

Security is one of a number of ‘Non-Functional’ Requirements any system and solution needs to cater for; others include Performance and Usability. Ignoring any of them during the design phases of a project is likely to cause problems later on in the project or after the system has gone live. In this article I want to lay out the advantages of including the security requirements within the Security Architecture, and give brief examples of the impacts and pitfalls of trying to retrofit security into a design.

Read the paper · More papers on PaperTik