Security requirements engineering: when anti-requirements hit the fan

Security requirements engineering: when anti-requirements hit the fan
复制标题

安全需求工程:当反需求出现问题时

DOI:
10.1109/icre.2002.1048527
复制
发表时间:
2002
期刊:
Proceedings IEEE Joint International Conference on Requirements Engineering
影响因子:
--
通讯作者:
B. Nuseibeh
B. Nuseibeh
中科院分区:
--
文献类型:
--
作者:
Robert Crook;D. Ince;Luncheng Lin;B. Nuseibeh

文献摘要

被引文献

相似文献

每个人都同意安全是一个问题,从微软到最近成为流氓交易员受害者的银行。自相矛盾的是,学术界和工业界似乎都没有明确承诺在需求工程的最高级别系统地处理这个主题。我们的愿景是一个未来,我们通过组织理论告知安全需求工程过程。这将充当由常规需求告知的软件项目的良好有序世界与与恶意用户相关联的反需求的意外世界之间的桥梁。我们为需求工程社区制定了一个愿景,该愿景将涉及社区解决六个难题。
Everyone agrees that security is a problem, ranging from Microsoft to the banks that have been recent victims of rogue traders. What is paradoxical is that there does not seem to be a wholehearted commitment by both academics and industry to treat this topic systematically at the top level of requirements engineering. Our vision is of a future in which we inform the security requirements engineering process by organisational theory. This would act as the bridge between the well-ordered world of the software project informed by conventional requirements and the unexpected world of anti-requirements associated with the malicious user. We frame a vision for the requirements engineering community that would involve the community solving six difficult problems.