SwePub
Sök i LIBRIS databas

  Extended search

(WFRF:(Gustafsson Mats)) srt2:(2020-2024)
 

Search: (WFRF:(Gustafsson Mats)) srt2:(2020-2024) > A Case Study of Int...

A Case Study of Introducing Security Risk Assessment in Requirements Engineering in a Large Organization

Ardi, Shanai (author)
Ericsson AB, Linköping, Sweden
Sandahl, Kristian, Professor, 1959- (author)
Linköpings universitet,Programvara och system,Tekniska fakulteten,PELAB
Gustafsson, Mats (author)
Ericsson AB, Linköping, Sweden
 (creator_code:org_t)
Springer, 2023
2023
English.
In: SN Computer Science. - : Springer. - 2661-8907. ; 4:5
  • Journal article (peer-reviewed)
Abstract Subject headings
Close  
  • Software products are increasingly used in critical infrastructures, and verifying the security of these products has become a necessary part of every software development project. Effective and practical methods and processes are needed by software vendors and infrastructure operators to meet the existing extensive demand for security. This article describes a lightweight security risk assessment method that flags security issues as early as possible in the software project, namely during requirements analysis. The method requires minimal training effort, adds low overhead, and makes it possible to show immediate results to affected stakeholders. We present a longitudinal case study of how a large enterprise developing complex telecom products adopted this method all the way from pilot studies to full-scale regular use. Lessons learned from the case study provide knowledge about the impact that upskilling and training of requirements engineers have on reducing the risk of malfunctions or security vulnerabilities in situations where it is not possible to have security experts go through all requirements. The case study highlights the challenges of process changes in large organizations as well as the pros and cons of having centralized, distributed, or semi-distributed workforce for security assurance in requirements engineering.

Subject headings

NATURVETENSKAP  -- Data- och informationsvetenskap -- Programvaruteknik (hsv//swe)
NATURAL SCIENCES  -- Computer and Information Sciences -- Software Engineering (hsv//eng)

Keyword

Security risk assessment
Software Engineering
Requirements Engineering

Publication and Content Type

ref (subject category)
art (subject category)

Find in a library

To the university's database

Find more in SwePub

By the author/editor
Ardi, Shanai
Sandahl, Kristia ...
Gustafsson, Mats
About the subject
NATURAL SCIENCES
NATURAL SCIENCES
and Computer and Inf ...
and Software Enginee ...
Articles in the publication
SN Computer Scie ...
By the university
Linköping University

Search outside SwePub

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Close

Copy and save the link in order to return to this view