Later stages support for security requirements

  • Authors:
  • Jose Romero-Mariona;Hadar Ziv;Debra J. Richardson

  • Affiliations:
  • University of California, Irvine;University of California, Irvine;University of California, Irvine

  • Venue:
  • The Fifth Richard Tapia Celebration of Diversity in Computing Conference: Intellect, Initiatives, Insight, and Innovations
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Software security concerns are frequent, widespread, and with potentially harmful consequences. We believe that security concerns should not only be specified as part of software requirements, but should also be supported during later stages of development (architecture, design, implementation, testing, and maintenance). This paper focuses on security requirements and the support available for them past their creation. As part of ongoing research we surveyed 12 approaches to security requirements engineering and identified the level of support each approach provides on a variety of areas related to later stages support. We show that support for security requirements after they are specified is lacking at best, creating opportunities for significant improvement and further research in this area.