Engineering Security Requirements.

Donald G. Firesmith · The Journal of Object Technology · 2003

Most requirements engineers are poorly trained to elicit, analyze, and specify security requirements, often confusing them with the architectural security mechanisms that are traditionally used to fulfill them.They thus end up specifying architecture and design constraints rather than true security requirements.This article defines the different types of security requirements and provides associated examples and guildlines with the intent of enabling requirements engineers to adequately specify security requirements without unnecessarily constraining the security and architecture teams from using the most appropriate security mechanisms for the job. SECURITY REQUIREMENTSThe engineering of the requirements for a business, system or software application, component, or (contact, data, or reuse) center involves far more than merely engineering its functional requirements.One must also engineer its quality, data, and interface requirements as well as its architectural, design, implementation, and testing constraints.Whereas some requirements engineers might remember to elicit, analyze, specify, and manage such quality requirements as interoperability, operational availability, performance, portability, reliability, and usability, many are at a loss when it comes to security requirements.Most requirements engineers are not trained at all in security, and the few that have been trained have only been given an overview of security architectural mechanisms such as passwords and encryption rather than in actual security requirements.Thus, the most common problem with security requirements, when they are specified at all, is that they tend to be accidentally replaced with security-specific architectural constraints that may unnecessarily constrain the security team from using the most appropriate security mechanisms for meeting the true underlying security requirements.This article will help you distinquish between security requirements and the mechanisms for achieving them, and will provide you with good examples of each type of security requirement.In today's world of daily virus alerts, malicious crackers, and the threats of cyberterrorism, it would be well to remember the following objectives of security requirements

Read the paper · More papers on PaperTik