Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

Analysis of Security Requirements Engineering: Towards a Comprehensive Approach

Author 1: Ilham Maskani Author 2: Jaouad Boutahar Author 3: Souhaïl El Ghazi El Houssaïni
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 7, No. 11 · Published 2016 · Cited by 6

DOI: https://doi.org/10.14569/IJACSA.2016.071106

Abstract

Software’s security depends greatly on how a system was designed, so it’s very important to capture security requirements at the requirements engineering phase. Previous research proposes different approaches, but each is looking at the same problem from a different perspective such as the user, the threat, or the goal perspective. This creates huge gaps between them in terms of the used terminology and the steps followed to obtain security requirements. This research aims to define an approach as comprehensive as possible, incorporating the strengths and best practices found in existing approaches, and filling the gaps between them. To achieve that, relevant literature reviews were studied and primary approaches were compared to find their common and divergent traits. To guarantee comprehensiveness, a documented comparison process was followed. The outline of our approach was derived from this comparison. As a result, it reconciles different perspectives to security requirements engineering by including: the identification of stakeholders, assets and goals, and tracing them later to the elicited requirements, performing risk assessment in conformity with standards and performing requirements validation. It also includes the use of modeling artifacts to describe threats, risks or requirements, and defines a common terminology.

Keywords

How to Cite this Article

Maskani, I., Boutahar, J., & Houssaïni, S. E. G. E. (2016). Analysis of Security Requirements Engineering: Towards a Comprehensive Approach. International Journal of Advanced Computer Science and Applications, 7(11). https://doi.org/10.14569/IJACSA.2016.071106

Maskani, Ilham, et al.. "Analysis of Security Requirements Engineering: Towards a Comprehensive Approach." International Journal of Advanced Computer Science and Applications, vol. 7, no. 11, 2016, https://doi.org/10.14569/IJACSA.2016.071106.

@article{Maskani2016,
  title     = {Analysis of Security Requirements Engineering: Towards a Comprehensive Approach},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {7},
  number    = {11},
  year      = {2016},
  publisher = {The Science and Information Organization},
  author    = {Ilham Maskani and Jaouad Boutahar and Souhaïl El Ghazi El Houssaïni},
  doi       = {10.14569/IJACSA.2016.071106},
  url       = {https://doi.org/10.14569/IJACSA.2016.071106}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.