• skip to content
  • skip to navigation
  • skip to supporting content
Homepage
CLOK - Central Lancashire Online Knowledge
Menu
  • Home
  • About
  • Policies
  • Deposit Guide: Research eTheses
  • Copyright Guide
  • Contact
  • Links
    • Login
  • Deposit
  • Search Item
  • Search FullText
  • Browse

Towards Agile Security Risk Management in RE and Beyond

Tools
- Tools
+ Tools

Franqueira, Virginia N.L. (2011) Towards Agile Security Risk Management in RE and Beyond. In: First International Workshop on Empirical Requirements Engineering (EmpiRE), 2011. IEEE Computer Society, Trento, pp. 33-36. ISBN 978-1-4577-1075-9

Full text not available from this repository.

Official URL: http://dx.doi.org/10.1109/EmpiRE.2011.6046253

Abstract

Little attention has been given so far to the process of security risk management at the early stages of system development. Security has been addressed by isolated security assurance practices, some of which consider risks and mitigations but they do not provide an overview of the overall security state of the system being developed. This paper takes the position that (1) these isolated security assurance practices should be fully integrated and should be embedded in short iterations of risk assessment, treatment and acceptance, providing input for updating security requirements and for security risk management, and that (2) available empirical data from public catalogs and databases should be used as a source of expertise, to leverage past experiences, and therefore reduce, although not eliminate, subjectivity of human judgment. Borrowing from the agile software development and project management philosophy, we introduce the idea of a light weight, agile approach to security risk management integrated to the development life cycle.


Item Type:Book Section
Uncontrolled Keywords (separate with ;):Information Security Risk Management; Agile Software Development; Secure Engineering; Security Assurance
Subjects:Q Science > Q Science (General)
Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Schools:School of Computing Engineering & Physcial Sciences
ID Code:6078
Deposited By: Carmit Erez
Deposited On:05 Nov 2012 13:50
Last Modified:05 Nov 2012 13:50

Repository Staff Only: item control page

University of Central Lancashire

Preston,
Lancashire,
PR1 2HE

Tel: +44 (0)1772 201 201

Other Links

  • Contact UCLan
  • How to find us
  • Help

  • Facebook
  • Twitter
  • UCLan RSS
  • Contact UCLan
  • Copyright |
  • Disclaimer |
  • Data Protection Act |
  • Freedom of Information