How to select a security requirements method? A comparative study with students and practitioners

19Citations
Citations of this article
36Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Most Secure Development Software Life Cycles (SSDLCs) start from security requirements. Security Management standards do likewise. There are several methods from industry and academia to elicit and analyze security requirements, but there are few empirical evaluations to investigate whether these methods are effective in identifying security requirements. Most of the papers published in the requirements engineering community report on methods'evaluations that are conducted by the same researchers who have designed the methods. The goal of this paper is to investigate how successfull academic security requirements methods are when applied by someone different than the method designer. The paper reports on a medium scale qualitative study where master students in computer science and professionals have applied academic security requirements engineering methods to analyze the security risks of a specific application scenario. The study has allowed the identification of methods' strenghts and limitations. © 2012 Springer-Verlag.

Cite

CITATION STYLE

APA

Massacci, F., & Paci, F. (2012). How to select a security requirements method? A comparative study with students and practitioners. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 7617 LNCS, pp. 89–104). https://doi.org/10.1007/978-3-642-34210-3_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free