Threat and Risk-Driven Security Requirements Engineering

  • Authors:
  • Holger Schmidt

  • Affiliations:
  • Technical University of Dortmund, Germany

  • Venue:
  • International Journal of Mobile Computing and Multimedia Communications
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, the author aim to present a threat and risk-driven methodology to security requirements engineering. The chosen approach has a strong focus on gathering, modeling, and analyzing the environment in which a secure ICT-system to be built is located. The knowledge about the environment comprises threat and risk models. As presented in the paper, this security-relevant knowledge is used to assess the adequacy of security mechanisms, which are then selected to establish security requirements.