Business oriented information security requirements development

Ivan Tirado · 2008

Information security works best when built into the product development process rather than added to an existing insecure product design. Secure design has become an area of primary interest for software developers, system integrators, service providers, and general businesses as they strive to reduce exposure to security vulnerabilities and their associated costs. Proper information security requirements that are well aligned with the business needs are essential for secure design that enhances product viability and return on investment. This paper proposes an information security requirements development process that aims to produce technically accurate information security requirements that take into account business needs.

Read the paper · More papers on PaperTik