An Integrated Cost-Effective Security Requirement Engineering Process in SDLC Using FRAM
Swe Zin Hlaing, Koichiro Ochimizu · 2018
Software engineers should be aware of the security threats and should implement proper degree of security mechanisms that meet the security requirements. Everyone knows, however, that building secure system is expensive. We need to have security engineering processes that help us to develop secure systems in cost-effective way. Cost-effective way means that we should pay attention on how much cost spent on the security failures and what level of security mechanisms we must ascertain in advance. This paper proposed the integration framework of two processes: security engineering process and risk-driven process to implement cost-effective secure system in each phase of SDLC. Functional Resonance Analysis Method (FRAM) has used as a tool for integration. By using this integrated framework, we can find out the impact of risk included in each phase and it is very useful for maintaining and evolution of the process. Then, we adopted the integrated process in the case of UIT's Information System Environment. Finally, the integrated system captures the cost-effective security requirements to demonstrate the misuse case by performing quantitative risk analysis.