Supporting Security Requirements Engineering through the Development of The Secure Development Ontology

Jessica Steinmann, Omar Ochoa · 2022

Security: the forgotten requirement. With the coming of the digital age comes new challenges to protect assets. Security of systems has become the top priority for many nations and companies due to the devastating results of software attacks. Often, much of security engineering is left up to the imaginations of engineers which is limited to experience; therefore, development of secure systems often requires security experts to analyze security risks, suggest security requirements, propose mitigations, and implement security requirements. Another challenge of security is the constantly shifting landscape. For example, once secure hash algorithms no longer being secure with the cheap availability of resources. This paper presents the development of the Secure Development Ontology (SDO), which has the purpose of assisting with the elicitation of security requirements and design decisions. The ontology defines 183 core entities and 32 object properties. The SDO is implemented in Web Ontology Language 2 through the Protege 5.5.0 tool. While ontologies have been used to map the security domain many have focused on subsets of the security domain or on security for after implementation of a system. Experience has shown that adding features to a development project is cheapest at the earliest stages of the development life cycle therefore this ontology focuses on security requirements, design, and implementation considerations.

Read the paper · More papers on PaperTik