Security requirements engineering: when anti-requirements hit the fan
Security requirements engineering: when anti-requirements hit the fan
复制标题
安全需求工程:当反需求出现问题时
DOI:
10.1109/icre.2002.1048527
复制
发表时间:
2002
期刊:
影响因子:
--
通讯作者:
B. Nuseibeh
中科院分区:
文献类型:
--
作者:
Robert Crook;D. Ince;Luncheng Lin;B. Nuseibeh
Everyone agrees that security is a problem, ranging from Microsoft to the banks that have been recent victims of rogue traders. What is paradoxical is that there does not seem to be a wholehearted commitment by both academics and industry to treat this topic systematically at the top level of requirements engineering. Our vision is of a future in which we inform the security requirements engineering process by organisational theory. This would act as the bridge between the well-ordered world of the software project informed by conventional requirements and the unexpected world of anti-requirements associated with the malicious user. We frame a vision for the requirements engineering community that would involve the community solving six difficult problems.