Using FSM patterns to size security non-functional requirements with COSMIC
Erdir Ungan, Sylvie Trudel, Luc Poulin · 2017
Measuring non-functional requirements (NFR) proved to be a non-trivial problem and has been subject to many studies recently. This paper introduces application of Functional Size Measurement (FSM) Patterns to facilitate measurement of NFRs, focusing on security requirements. A Design Science Research methodology was followed to define and demonstrate the usefulness of measurement patterns applied to application security controls (ASC). Examples of how FSM Patterns can be defined for ASC are provided, along with how they are applied during or after the COSMIC measurement of Functional User Requirements (FURs). Results suggest that the magnitude of functional size introduced by a sample set of ASCs through a small case can increase significantly (e.g. over 200%). Defining and applying FSM Patterns turned out to be an effective way of reflecting functional size denoted by security NFRs. The approach also lets such NFRs to be sized before they are actually converted into FURs in the later phases of software development lifecycle, which makes the size of software to be represented more accurate in the early stages of the software development lifecycle. As such, FSM patterns should be an asset in incorporating the functional size stemming from high-level NFRs defined at the start of a project. The scope of this research was limited to security NFRs, and specifically to those security NFRs to be operationalized in the measured software (quasi NFRs). Future work could be extended to other categories of NFRs.