官术网_书友最值得收藏!

Requirements

Initially, requirements are specified for the product, frequently embedded in a variety of specification types:

  • System-level requirements are described in a System Requirements Specification (SyRS)
  • Software Requirements Specification (SRS) describes use cases for software, and associated functional and non-functional requirements
  • Interface requirements are specified in an Interface Requirements Specification (IRS)
  • Hardware requirements may be specified in a hardware functional or hardware requirements specification.

A process of requirements derivation is used to derive requirements from the system level to individual components.

Security engineers in a waterfall development program progress through the life cycle phases as time progresses. One of the first activities to complete is a security requirements analysis. Just as products have functional requirements allocated to them, those products must also have security requirements allocated.

Engineers use many sources to identify security requirements. These can include Security Technical Implementation Guides (STIGs), compliance requirements, and system threat models.

A useful tool for creating and tracking security requirements is the Security Requirements Traceability Matrix (SRTM). An SRTM maps security requirements to their implementation within components of the product, discusses the method for their verification, and tracks that verification status.

As the name suggests, the matrix can be used to track security requirements for closure as an input to a security test plan and procedures document. 

Create a baseline SRTM containing a metaset of security requirements that should be applied to system developments. Project teams can then use that SRTM as a starting point, and tailor the unique security requirements to their system design. 
主站蜘蛛池模板: 邹城市| 洛浦县| 萨迦县| 肃宁县| 庆阳市| 南川市| 同江市| 仁怀市| 隆昌县| 余姚市| 永泰县| 墨玉县| 洛宁县| 泰顺县| 绥德县| 淄博市| 台东县| 仁寿县| 汾阳市| 清丰县| 武鸣县| 永寿县| 唐河县| 都匀市| 麟游县| 伊吾县| 大同县| 醴陵市| 濮阳市| 兰溪市| 木兰县| 郓城县| 新乡县| 威海市| 垦利县| 佳木斯市| 灵丘县| 察隅县| 吉木萨尔县| 长岭县| 壶关县|