Publication:
RiskSRP: Prioritizing security requirements based on total risk avoidance

No Thumbnail Available

Date

2017

Journal Title

Journal ISSN

Volume Title

Publisher

American Scientific Publishers

Research Projects

Organizational Units

Journal Issue

Abstract

Once a set of security requirements are elicited, they need to be prioritized. Due to constraints such as development risk, cost, time to market, and security risk avoidance, it can be difficult to implement all security requirements that have been elicited for a system. Also, security requirements are often implemented in stages, and prioritization can help to determine which ones should be implemented first. Usually requirements are prioritized based on stockholders� preference with regards to the importance and easiest to implement. However, these approaches cannot be used with efficiency when dealing with security requirements because there are additional elements that are unique with security requirements. This paper proposes a Risk-based Security Requirements Prioritization (RiskSRP), a process that allows the prioritization of security requirements according to the Total Risk Impact (TI) of security threat(s). � 2017 American Scientific Publishers All rights reserved.

Description

Keywords

Assets valuation, Prioritization, Risk, Security requirements, Threats

Citation

Collections