Skip to main content

Security Scenarios in Analysis and Design

This article addresses the issue of designing security into systems rather than trying to add it to systems after development. It is found by surveying teaching materials that security is only given brief acknowledgement as a concern in software development and that security is not well integrated into development life cycles used in schools. It is proposed that initial security requirements be addressed at the end of the requirements analysis phase and that update and refinement of security requirements continue through the design phase. This would be achieved by making the security administrator a major stakeholder in each and every system being developed. This would be implemented through a library of security scenarios that would be applied to each use case where appropriate. The management of the scenario library is discussed and the resource requirements are addressed.

29 (PDF, 1.98MB)

16 Sep 2002
ByDwight Haworth
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.

Security Scenarios in Analysis and Design