Talk With an Expert

Using a Capability Maturity Model to Derive Security Requirements

Using a Capability Maturity Model to Derive Security Requirements (PDF, 1.81MB)Published: 08 May, 2003
Created by
Mike Phillips

A security engineer is often assigned to a project that already has defined security objectives. But on occasion, the security engineer may be tasked with the initial definition of the objectives. While this assignment may be exciting because of the important role the security engineer is to play, it may also be somewhat daunting due to the large solution space. In order to guide one's efforts in this task, the security engineer could turn to the Systems Security Engineering Capability Maturity Model (SSE-CMM). This model provides industry best practice guidance without being specific as to how security solutions are implemented. The SSE-CMM provides a broad list of 'base practices' from which the security engineer can benefit when defining the objectives of the security implementation. This paper will discuss the use of these base practices in the formation of security requirements.