Requirement Centric Security Evaluation of Software Intensive Systems
Information security demands are increasing in nowadays complex and networked information technology environment. Systematic development of the information security requirements of practical software-intensive systems is typically ignored, at an inadequate level or relies heavily on the experience of the security professionals. However, it is obvious that security requirements should be the paid attention in all phases of security engineering. We introduce a preliminary framework for security evaluation based on security requirement definition, behavior modeling and evidence collection.