Enhancing security requirements engineering by organizational learning

被引:0
|
作者
Kurt Schneider
Eric Knauss
Siv Houmb
Shareeful Islam
Jan Jürjens
机构
[1] Leibniz Universität Hannover,Software Engineering Group
[2] Secure-NOK AS,School of Computing, IT and Engineering
[3] University of East London,Chair for Software Engineering
[4] TU Dortmund and Fraunhofer ISST,undefined
来源
Requirements Engineering | 2012年 / 17卷
关键词
Secure software engineering; Requirements analysis; Organizational learning; Requirements workflow modeling;
D O I
暂无
中图分类号
学科分类号
摘要
More and more software projects today are security-related in one way or the other. Requirements engineers without expertise in security are at risk of overlooking security requirements, which often leads to security vulnerabilities that can later be exploited in practice. Identifying security-relevant requirements is labor-intensive and error-prone. In order to facilitate the security requirements elicitation process, we present an approach supporting organizational learning on security requirements by establishing company-wide experience resources and a socio-technical network to benefit from them. The approach is based on modeling the flow of requirements and related experiences. Based on those models, we enable people to exchange experiences about security-relevant requirements while they write and discuss project requirements. At the same time, the approach enables participating stakeholders to learn while they write requirements. This can increase security awareness and facilitate learning on both individual and organizational levels. As a basis for our approach, we introduce heuristic assistant tools. They support reuse of existing experiences that are relevant for security. In particular, they include Bayesian classifiers that issue a warning automatically when new requirements seem to be security-relevant. Our results indicate that this is feasible, in particular if the classifier is trained with domain-specific data and documents from previous projects. We show how the ability to identify security-relevant requirements can be improved using this approach. We illustrate our approach by providing a step-by-step example of how we improved the security requirements engineering process at the European Telecommunications Standards Institute (ETSI) and report on experiences made in this application.
引用
收藏
页码:35 / 56
页数:21
相关论文
共 50 条
  • [31] Towards security requirements management for software product lines:: A security domain requirements engineering process
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    COMPUTER STANDARDS & INTERFACES, 2008, 30 (06) : 361 - 371
  • [32] Security requirements engineering: When anti-requirements hit the fan
    Crook, R
    Ince, D
    Lin, LC
    Nuseibeh, B
    IEEE JOINT INTERNATIONAL CONFERENCE ON REQUIREMENTS ENGINEERING, PROCEEDINGS, 2002, : 203 - 205
  • [33] Legal Requirements towards Enhancing the Security of Medical Devices
    Yeng, Prosper K.
    Wulthusen, Stephen D.
    Yang, Bian
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (11) : 666 - 675
  • [34] Application of Reinforcement Learning to Requirements Engineering: Requirements Tracing
    Sultanov, Hakim
    Hayes, Jane Huffman
    2013 21ST IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE), 2013, : 52 - 61
  • [35] THE SECURITY ENGINEERING DESIGN PROCESS, AN EVALUATION PROCEDURE FOR PHYSICAL SECURITY REQUIREMENTS
    BETTS, CP
    STRUCTURES FOR ENHANCED SAFETY AND PHYSICAL SECURITY, 1989, : 61 - 72
  • [36] Utilizing security requirements engineering methods for operational security maintenance purposes
    Abuosba, Khalil
    El-Sheikh, Asim
    Martin, Clemens
    2008 CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-4, 2008, : 1763 - 1767
  • [37] Security Engineering for Machine Learning
    McGraw, Gary
    Bonett, Richie
    Figueroa, Harold
    Shepardson, Victor
    COMPUTER, 2019, 52 (08) : 54 - 57
  • [38] E-learning: organizational requirements for successful feedback learning
    Cegarra-Navarro, Juan G.
    Sabater-Sanchez, Ramon
    JOURNAL OF WORKPLACE LEARNING, 2005, 17 (5-6) : 276 - +
  • [39] Software Prototypes: Enhancing The Quality of Requirements Engineering Process
    Suranto, Beni
    2ND INTERNATIONAL SYMPOSIUM ISTMET 2015 TECHNOLOGY MANAGEMENT & EMERGING TECHNOLOGIES, 2015,
  • [40] Asynchronous requirements engineering: Enhancing distributed software development
    Campbell, CL
    Van de Walle, B
    ITRE2003: INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: RESEARCH AND EDUCATION, 2003, : 133 - 136