Security engineering methods - in-depth analysis

Shruti Jaiswal, Daya Sagar Gupta · International Journal of Information and Computer Security · 2017

Providing security to complex information system development is challenging because of complex network and ubiquitous system. Traditional mechanisms address security concerns during development or design phases that may lead to various loopholes or over-constrained system. The field of security engineering has emerged whereby security requirements are gathered along with other requirements during the initial phase of software development. However, dealing with security concerns during the initial phases of development is challenging because of design and code unavailability. The paper first represents the proposals for security requirements engineering based on different approaches such as use case approach, goal-oriented approach, and process-oriented approach. These methodologies are evaluated along various parameters such as security engineering activities covered, application domain and others. The in-depth analysis ends with a recent proposal for security engineering and list of unresolved issues that needs consideration. The outcome of the paper can be exploited to drive further research.

Read the paper · More papers on PaperTik