Many security requirements elicitation techniques implicitly assume that assets are identified on beforehand, but few actually describe how this should be done. In this paper we suggest one specific method that can be used to identify and prioritize assets in any software engineering project.
Index Terms:
Assets, security requirements
Citation:
Martin Gilje Jaatun, Inger Anne T?ndel, "Covering Your Assets in Software Engineering," ares, pp.1172-1179, 2008 Third International Conference on Availability, Reliability and Security, 2008