How To Compare the Security Quality Requirements Engineering (SQUARE) Method with Other Methods

The Security Quality Requirements Engineering (SQUARE) method, developed at the Carnegie Mellon Software Engineering Institute, provides a systematic way to identify security requirements in a software development project. This report describes SQUARE and then describes other methods used for identifying security requirements, such as the Comprehensive, Lightweight Application Security Process, the Security Requirements Engineering Process, and Tropos, and compares them with SQUARE. The report concludes with some guidelines for selecting a method and a look at some related trends in requirements engineering.

View Complete Report

Author

Nancy R. Mead

This report is related to the following area(s) of work:

Security and Survivability

Technical Note
CMU/SEI-2007-TN-021
August 2007

For more information

Contact Us

info@sei.cmu.edu

412-268-5800