Cristin-resultat-ID: 1718911
Sist endret: 2. desember 2019, 13:14
NVI-rapporteringsår: 2019
Resultat
Vitenskapelig artikkel
2019

Risk-Based Elicitation of Security Requirements According to the ISO 27005 Standard

Bidragsytere:
  • Roman Wirtz
  • Maritta Heisel
  • Angela Borchert
  • Rene Meis
  • Aida Omerovic og
  • Ketil Stølen

Tidsskrift

Communications in Computer and Information Science (CCIS)
ISSN 1865-0929
e-ISSN 1865-0937
NVI-nivå 1

Om resultatet

Vitenskapelig artikkel
Publiseringsår: 2019
Volum: 1023
Sider: 71 - 97

Importkilder

Scopus-ID: 2-s2.0-85069208393

Beskrivelse Beskrivelse

Tittel

Risk-Based Elicitation of Security Requirements According to the ISO 27005 Standard

Sammendrag

Security is of great importance for software intensive systems. Security incidents become more and more frequent in the last few years. Such incidents can lead to substantial damage, not only financially, but also in term of reputation loss. The security of a software system can be compromised by threats, which may harm assets with a certain likelihood, thus constituting a risk. All such risks should be identified, and unacceptable risks should be reduced. The task of dealing with risks is called risk management and should be performed right from the beginning of the software development process. Security requirements can be used to address security aspects during requirements engineering. We propose a risk-based method to elicit security requirements based on functional requirements. Our method complies to the ISO 27005 standard for security risk management. We provide guidance for all steps of that process, and the results are collected in a model. We also define validation conditions to support the identification of errors when carrying out the process as early as possible.

Bidragsytere

Roman Wirtz

  • Tilknyttet:
    Forfatter
    ved Universität Duisburg-Essen

Maritta Heisel

  • Tilknyttet:
    Forfatter
    ved Universität Duisburg-Essen

Angela Borchert

  • Tilknyttet:
    Forfatter
    ved Universität Duisburg-Essen

Rene Meis

  • Tilknyttet:
    Forfatter
    ved Universität Duisburg-Essen

Aida Omerovic

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS
1 - 5 av 6 | Neste | Siste »