Planning for Secure Software Requirements and Design with UML
摘要
It is not possible to build an excellent software product quickly without understanding the requirements. It is known in the security world (and required by GDPR) that “Building Security In” is the best approach to secure software, and is the name of a maturity model: Building Security In Maturity Model (BSIMM). By Building Security In, the code is written properly the first time, saving time in the long run. Proper ‘building security in’ starts during requirements, with software risk analysis and potentially a misuse case design or threat tree, and proceeds through architectural analysis, demonstrated here using UML enhanced for security. Finally, we briefly review PCI's secure software standard related to Requirements.