A novel method: Ontology-based security requirements engineering framework
P. Salini, Selvadurai Kanmani · 2016
Software systems security is often exploited by threats through vulnerabilities of the systems. This reveals the necessity of eliciting and analyzing security requirements in the requirements engineering phase. Though some security requirements engineering methods are proposed by researchers for eliciting security requirements, the time and cost needed to use and implement the method are more than to elicit business requirements of the software systems. Moreover, requirements engineers are not trained in eliciting security requirements and they need to depend on security experts to identify security requirements. In order to solve these problems, we facilitate the security requirements elicitation process by security requirements reusability. This paper proposes an ontology-based security requirements engineering framework a novel method for developing secure software systems. Our method allows analysts to reuse existing security requirements ontologies when eliciting security requirements in security requirements engineering phase. We expect that the proposed method would be very helpful for requirements engineers to elicit and manage security requirements.