...
首页> 外文期刊>Journal of Theoretical and Applied Information Technology >SECURITY REQUIREMENTS ELICITATION AND CONSISTENCY VALIDATION: A SYSTEMATIC LITERATURE REVIEW
【24h】

SECURITY REQUIREMENTS ELICITATION AND CONSISTENCY VALIDATION: A SYSTEMATIC LITERATURE REVIEW

机译:安全要求征集和一致性验证:系统的文献综述

获取原文
           

摘要

Security requirements are important in developing secure software development. Objectives: This study plans to identify properties of security requirements for developing secure software as well as to analyse the existing works for requirements validation. The gaps and limitations of each approach was discussed in this study. Method: A systematic literature review is conducted to identify and analyse related literature on elicitation of security requirements for developing secure software. Findings: There are four results: (1) the security properties highly considered for developing secure software are ?Confidentiality?, ?Integrity? ?Identification & Authentication?, and ?Availability?; (2) the approaches in validating security requirements are controlled user experiments, tools and manual checklist; (3) the security references used are the NIST, the Common Criteria and the ISO/IEC; and (4) security requirements template and consistency checking. Finally, the gaps and limitations of the existing works were also discussed. Conclusion: The primary challenge of security requirements during elicitation is to write the correct security requirements and validating the consistency of security requirements. As such, requirements engineers should consider the challenges posed by security requirements in eliciting and validating security requirements.
机译:安全要求对于开发安全的软件开发很重要。目标:本研究计划确定用于开发安全软件的安全需求的属性,并分析现有工作以进行需求验证。这项研究讨论了每种方法的差距和局限性。方法:进行了系统的文献综述,以识别和分析有关引发安全软件开发安全要求的相关文献。结果:有四个结果:(1)开发安全软件时高度重视的安全性是“机密性”,“完整性”。 “身份验证”和“可用性”; (2)验证安全要求的方法是受控的用户实验,工具和手动检查表; (3)使用的安全性参考是NIST,通用标准和ISO / IEC; (4)安全需求模板和一致性检查。最后,还讨论了现有作品的差距和局限性。结论:引发安全需求的主要挑战是编写正确的安全需求并验证安全需求的一致性。因此,需求工程师应在提出和验证安全需求时考虑安全需求带来的挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号