Systematically Developing Prevention, Detection, and Response Patterns for Security Requirements
Maria Riaz, Sarah Elder, Laurie A. Williams · 2016
The security community has established a number of knowledge sources, including security catalogues and controls, that capture security expertise and can support elicitation of security requirements. Providing additional guidance on how and when to leverage the security information available in the existing knowledge sources in the context of the given system can support security requirements engineering efforts. The objective of this research is to support analysts in identifying and specifying security requirements by developing and utilizing a systematic process for identifying security requirements patterns from existing knowledge sources. We document our process for systematically analyzing and synthesizing existing knowledge sources to identify a set of security requirements patterns that support a diverse set of security goals. We demonstrate the feasibility of our process by applying it to NIST Special Publication 800-53 to identify 35 security requirements patterns related to preventing, detecting and responding to security breaches. Our patterns can generate a broad set of technical security requirements by instantiating 131 different security requirements templates that are grouped in the 35 patterns. Our patterns capture the security context in which each pattern is applicable and the security-specific problem that is addressed, providing conceptual scaffolding around the knowledge abstracted in the security requirements patterns.