How do practitioners reason about security requirements? An interview study
In the development of modern software-intensive systems, security aspects are increasingly emphasized, with new laws and regulations putting more demands on manufacturers. Requirements elicitation must therefore carefully consider security aspects. The literature contains various frameworks that have been proposed to aid in the elicitation of these types of requirements. We are interested to understand how, in industrial practice, persons responsible for cybersecurity reason about so-called ``security requirements''. To find out, we perform eight semi-structured interviews with experts having leading roles in cybersecurity in large companies. We identify the concepts that they leverage when reasoning about security requirements, what other aspects they look at when identifying security requirements, how they differ between security requirements and other requirements, and what their definition of a security requirement is. In this paper, we report on this interview study and our analysis of it. We highlight the commonalities and crucial differences between experts’ reasoning, and a surprising spread of conclusions regarding the identification of example requirements as being security requirements or not. Our analysis opens a new perspective on how to deal with security requirements, we hypothesize the benefits of using multiple approaches for elicitation and a single approach for requirements specification.
Wed 26 JunDisplayed time zone: (UTC) Coordinated Universal Time change
15:45 - 17:45 | Responsible RequirementsRE@Next! Papers / Research Papers at V201 Chair(s): Jacek Dąbrowski Lero - the Science Foundation Ireland Research Centre for Software | ||
15:45 30mPaper | A Vision to Enhance Trust Requirements for Peer Support Systems by Revisiting Trust Theories RE@Next! Papers File Attached | ||
16:15 30mPaper | Uncovering Patterns of Users' Ethical Concerns about Software RE@Next! Papers Özge Karaçam Vrije Universiteit Amsterdam, Tom Humbert Vrije Universiteit Amsterdam, Emitzá Guzmán Vrije Universiteit Amsterdam Pre-print | ||
16:45 30mPaper | How do practitioners reason about security requirements? An interview study Research Papers Pre-print |