Experimental evaluation of security requirements engineering benefits

1Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.

Abstract

Security Requirements Engineering (SRE) approaches are designed to improve information system security by thinking about security requirements at the beginning of the software development lifecycle. This paper is a quantitative evaluation of the benefits of applying such an SRE approach. The followed methodology was to develop two versions of the same web application, with and without using SRE, then comparing the level of security in each version by running different test tools. The subsequent results clearly support the benefits of the early use of SRE with a 38% security improvement in the secure version of the application. This security benefit reaches 67% for high severity vulnerabilities, leaving only non-critical and easy-to-fix vulnerabilities.

Cite

CITATION STYLE

APA

Boutahar, J., Maskani, I., & El Houssaïni, S. E. G. (2018). Experimental evaluation of security requirements engineering benefits. International Journal of Advanced Computer Science and Applications, 9(11), 411–415. https://doi.org/10.14569/ijacsa.2018.091158

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free