Enhancing Use Cases with Subjective Risk Assessment
Oluwasefunmi 'Tale Arogundade, Z. Jin, Xiaoguang Yang · 2011
The aim of this article is to advance the discussion of use-misuse cases as a tool for information system security risk assessment during system development. We closely examined the limitations and came up with some basic pointers that needed to be addressed in order to overcome the limitations. We proposed some solutions to these lacks and present a framework and modeling process to achieve the solutions. We illustrate the use of the proposed model on popular e-shop system as a case study. The proposed model is able to allow managers and system developers to share a commonly understand view concerning the potential impact of various information system related threats that make sense to them within their limited resources.