Security Requirement Engineering Using Structured Object-Oriented Formal Language for M-Banking Applications
Busalire Onesmus Emeka, Shaoying Liu · 2017
In the recent times, software security has gained a great deal of attention in the Software Development Life Cycle due to increased cases of reported cyber threats and incidents. A considerable number of cyber-attacks targeting financial systems has made security be the most critical feature in banking systems. However, establishing security requirements for these applications can be a challenging task because the activities and measures demanded by their requirements calls for a clear understanding and implementation without any degree of ambiguity. In order to address this, we propose a new framework; Security Requirement Engineering with Structured Object Oriented Formal Language (SRESOFL), while giving special focus on financial applications. The framework seeks to offer a weaving approach where security requirements and the functional system requirements are fused together during the system`s requirement specification phase. We will illustrate the applicability of the SRESOFL framework with a case study on the development of a mobile banking application.