{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T05:26:31Z","timestamp":1787030791503,"version":"3.56.0"},"reference-count":27,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,1,1]]},"abstract":"<p>In this paper, the author aim to present a threat and risk-driven methodology to security requirements engineering. The chosen approach has a strong focus on gathering, modeling, and analyzing the environment in which a secure ICT-system to be built is located. The knowledge about the environment comprises threat and risk models. As presented in the paper, this security-relevant knowledge is used to assess the adequacy of security mechanisms, which are then selected to establish security requirements.<\/p>","DOI":"10.4018\/jmcmc.2011010103","type":"journal-article","created":{"date-parts":[[2011,10,19]],"date-time":"2011-10-19T12:40:05Z","timestamp":1319028005000},"page":"35-50","source":"Crossref","is-referenced-by-count":1,"title":["Threat and Risk-Driven Security Requirements Engineering"],"prefix":"10.4018","volume":"3","author":[{"given":"Holger","family":"Schmidt","sequence":"first","affiliation":[{"name":"Technical University of Dortmund, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jmcmc.2011010103-0","doi-asserted-by":"crossref","unstructured":"Asnar, Y., Giorgini, P., Massacci, F., & Zannone, N. (2007). From trust to dependability through risk analysis. In Proceedings of the international conference on availability, reliability and security (AReS) (pp. 19-26). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/ARES.2007.93"},{"key":"jmcmc.2011010103-1","unstructured":"Asnar, Y., Giorgini, P., & Mylopoulos, J. (2006). Risk modelling and reasoning in goal models (Tech. Rep. No. DIT-06-008). University of Trento, Trento, Italy."},{"key":"jmcmc.2011010103-2","doi-asserted-by":"publisher","DOI":"10.1007\/s10550-007-0013-9"},{"key":"jmcmc.2011010103-3","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-009-0092-x"},{"key":"jmcmc.2011010103-4","unstructured":"Fernandez, E. B., la Red, M. D. L., Forneron, J., Uribe, V. E., & Rodriguez, G. G. (2007). A secure analysis pattern for handling legal cases. In Proceedings of the Latin America conference on pattern languages of programming (SugarLoafPLoP). Retrieved August 9, 2009, from http:\/\/sugarloafplop.dsc.upe.br\/wwD.zip"},{"key":"jmcmc.2011010103-5","article-title":"Secure Tropos: dealing effectively with security requirements in the development of multiagent systems","author":"P.Giorgini","year":"2006","journal-title":"Safety and security in multi-agent systems \u2013 selected papers"},{"key":"jmcmc.2011010103-6","doi-asserted-by":"publisher","DOI":"10.1142\/S0218194007003240"},{"key":"jmcmc.2011010103-7","unstructured":"G\u00fcrses, S., Jahnke, J. H., Obry, C., Onabajo, A., Santen, T., & Price, M. (2005). Eliciting confidentiality requirements in practice. In Proceedings of the conference of the centre for advanced studies on collaborative research (CASCON) (pp. 101-116). IBM Press."},{"key":"jmcmc.2011010103-8","unstructured":"Hatebur, D., Heisel, M., & Schmidt, H. (2007). A security engineering process based on patterns. In Proceedings of the international workshop on secure systems methodologies using patterns (spatterns) (pp. 734-738). Washington, DC: IEEE Computer Society."},{"key":"jmcmc.2011010103-9","doi-asserted-by":"crossref","unstructured":"Hatebur, D., Heisel, M., & Schmidt, H. (2008). Analysis and component-based realization of security requirements. In Proceedings of the international conference on availability, reliability and security (AReS) (pp. 195-203). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/ARES.2008.27"},{"key":"jmcmc.2011010103-10","unstructured":"Hernan, S., Lambert, S., Ostwald, T., & Shostack, A. (2006, November). Uncover security design flaws using the STRIDE approach. Retrieved from http:\/\/msdn.microsoft.com\/de-de\/magazine\/cc163519.aspx"},{"key":"jmcmc.2011010103-11","unstructured":"Houmb, S. H., Georg, G., France, R., Bieman, J., & J\u00fcrjens, J. (2005). Cost-benefit trade-off analysis using BBN for aspect-oriented risk-driven development. In Proceedings of the IEEE international conference on engineering of complex computer systems (iceccs). Washington, DC: IEEE Computer Society."},{"key":"jmcmc.2011010103-12","author":"M.Howard","year":"2006","journal-title":"The security development lifecycle"},{"key":"jmcmc.2011010103-13","unstructured":"International Organization for Standardization (ISO) and International Electrotechnical Commission. (IEC). (2000). Functional safety of electrical\/electronic\/programmable electronic safty-relevant systems (ISO\/IEC 61508). Retrieved August 9, 2009, from http:\/\/www.iec.ch\/61508\/"},{"key":"jmcmc.2011010103-14","author":"M.Jackson","year":"2001","journal-title":"Problem frames. Analyzing and structuring software development problems"},{"key":"jmcmc.2011010103-15","unstructured":"Lin, L., Nuseibeh, B., Ince, D., & Jackson, M. (2004). Using abuse frames to bound the scope of security problems. In Proceedings of the IEEE international requirements engineering conference (RE) (pp. 354-355). Washington, DC: IEEE Computer Society."},{"key":"jmcmc.2011010103-16","unstructured":"Mayer, N. (2009). Model-based management of information system security risk. Unpublished doctoral dissertation, University of Namur. Retrieved August 9, 2009, from http:\/\/nmayer .eu\/publis\/Thesis Mayer 2.0.pdf"},{"key":"jmcmc.2011010103-17","doi-asserted-by":"crossref","unstructured":"Mead, N. R., Hough, E. D., & Stehney, T. R., II. (2005). Security quality requirements engineering (SQUARE) methodology (Tech. Rep. No. CMU\/SEI-2005-TR-009). Pittsburgh, PA: Carnegie Mellon Software Engineering Institute.","DOI":"10.21236\/ADA443493"},{"key":"jmcmc.2011010103-18","unstructured":"R\u00f8stad, L., T\u00f8ndel, I. A., Line, M. B., & Nordland, O. (2006). Safety vs. security. In M. G. Stamatelatos & H. S. Blackman (Eds.), Proceedings of the international conference on probabilistic safety assessment and management (PSAM). New York: ASME Press."},{"key":"jmcmc.2011010103-19","doi-asserted-by":"crossref","unstructured":"Schmidt, H. (2010). A pattern-and component-based method to develop secure software. Berlin: Deutscher Wissenschafts-Verlag (DWV).","DOI":"10.4018\/978-1-61520-837-1.ch003"},{"key":"jmcmc.2011010103-20","unstructured":"Schneier, B. (1999). Attack trees. Dr. Dobb\u2019s Journal. Retrieved August 9, 2009, from http:\/\/www.schneier.com\/paper-attacktrees-ddj-ft"},{"key":"jmcmc.2011010103-21","doi-asserted-by":"crossref","unstructured":"Sindre, G. (2007). Mal-activity diagrams for capturing attacks on business processes. In P. Sawyer, B. Paech, & P. Heymans (Eds.), Proceedings of the international working conference on requirements engineering: Foundation for software quality (REFSQ) (LNCS 4542, pp. 355-366). New York: Springer.","DOI":"10.1007\/978-3-540-73031-6_27"},{"key":"jmcmc.2011010103-22","unstructured":"Sindre, G., & Opdahl, A. L. (2001). Capturing security requirements through misuse cases. In Proceedings of the Norwegian informatics conference (NIK)."},{"key":"jmcmc.2011010103-23","unstructured":"UML Revision Task Force. (2009, February). OMG unified modeling language: Superstructure. Retrieved August 9, 2009, from http:\/\/www.omg.org\/spec\/UML\/2.2\/"},{"key":"jmcmc.2011010103-24","first-page":"148","author":"A.van Lamsweerde","year":"2004","journal-title":"Elaborating security requirements by construction of intentional anti-models"},{"key":"jmcmc.2011010103-25","first-page":"196","article-title":"Engineering requirements for system reliability and security","volume":"Vol. 9","author":"A.van Lamsweerde","year":"2007","journal-title":"Software system reliability and security"},{"key":"jmcmc.2011010103-26","doi-asserted-by":"publisher","DOI":"10.1145\/237432.237434"}],"container-title":["International Journal of Mobile Computing and Multimedia Communications"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=51660","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T17:39:30Z","timestamp":1654105170000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jmcmc.2011010103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2011,1,1]]},"references-count":27,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2011,1]]}},"URL":"https:\/\/doi.org\/10.4018\/jmcmc.2011010103","relation":{},"ISSN":["1937-9412","1937-9404"],"issn-type":[{"value":"1937-9412","type":"print"},{"value":"1937-9404","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,1,1]]}}}