{"id":"https://openalex.org/W2742846213","doi":"https://doi.org/10.1145/3098954.3098996","title":"Which Security Requirements Engineering Methodology Should I Choose?","display_name":"Which Security Requirements Engineering Methodology Should I Choose?","publication_year":2017,"publication_date":"2017-08-10","ids":{"openalex":"https://openalex.org/W2742846213","doi":"https://doi.org/10.1145/3098954.3098996","mag":"2742846213"},"language":"en","primary_location":{"id":"doi:10.1145/3098954.3098996","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3098954.3098996","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5052443306","display_name":"Sravani Teja Bulusu","orcid":null},"institutions":[{"id":"https://openalex.org/I134560555","display_name":"Universit\u00e9 Toulouse III - Paul Sabatier","ror":"https://ror.org/02v6kpv12","country_code":"FR","type":"education","lineage":["https://openalex.org/I134560555"]},{"id":"https://openalex.org/I4210119061","display_name":"Institut de Recherche en Informatique de Toulouse","ror":"https://ror.org/01rx4qw44","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I205747304","https://openalex.org/I205747304","https://openalex.org/I4210119061","https://openalex.org/I4210152422","https://openalex.org/I4387153255","https://openalex.org/I4405258862","https://openalex.org/I4405259414"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Sravani Teja Bulusu","raw_affiliation_strings":["IRIT/University Paul Sabatier, Toulouse, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"IRIT/University Paul Sabatier, Toulouse, France","institution_ids":["https://openalex.org/I134560555","https://openalex.org/I4210119061"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5001626345","display_name":"Romain Laborde","orcid":"https://orcid.org/0000-0002-0943-6180"},"institutions":[{"id":"https://openalex.org/I134560555","display_name":"Universit\u00e9 Toulouse III - Paul Sabatier","ror":"https://ror.org/02v6kpv12","country_code":"FR","type":"education","lineage":["https://openalex.org/I134560555"]},{"id":"https://openalex.org/I4210119061","display_name":"Institut de Recherche en Informatique de Toulouse","ror":"https://ror.org/01rx4qw44","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I205747304","https://openalex.org/I205747304","https://openalex.org/I4210119061","https://openalex.org/I4210152422","https://openalex.org/I4387153255","https://openalex.org/I4405258862","https://openalex.org/I4405259414"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Romain Laborde","raw_affiliation_strings":["IRIT/University Paul Sabatier, Toulouse, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"IRIT/University Paul Sabatier, Toulouse, France","institution_ids":["https://openalex.org/I134560555","https://openalex.org/I4210119061"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041476109","display_name":"Ahmad Samer Wazan","orcid":"https://orcid.org/0000-0002-1611-2870"},"institutions":[{"id":"https://openalex.org/I134560555","display_name":"Universit\u00e9 Toulouse III - Paul Sabatier","ror":"https://ror.org/02v6kpv12","country_code":"FR","type":"education","lineage":["https://openalex.org/I134560555"]},{"id":"https://openalex.org/I4210119061","display_name":"Institut de Recherche en Informatique de Toulouse","ror":"https://ror.org/01rx4qw44","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I205747304","https://openalex.org/I205747304","https://openalex.org/I4210119061","https://openalex.org/I4210152422","https://openalex.org/I4387153255","https://openalex.org/I4405258862","https://openalex.org/I4405259414"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Ahmad Samer Wazan","raw_affiliation_strings":["IRIT/University Paul Sabatier, Toulouse, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"IRIT/University Paul Sabatier, Toulouse, France","institution_ids":["https://openalex.org/I134560555","https://openalex.org/I4210119061"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5073619509","display_name":"Fran\u00e7ois Barr\u00e8re","orcid":null},"institutions":[{"id":"https://openalex.org/I134560555","display_name":"Universit\u00e9 Toulouse III - Paul Sabatier","ror":"https://ror.org/02v6kpv12","country_code":"FR","type":"education","lineage":["https://openalex.org/I134560555"]},{"id":"https://openalex.org/I4210119061","display_name":"Institut de Recherche en Informatique de Toulouse","ror":"https://ror.org/01rx4qw44","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I205747304","https://openalex.org/I205747304","https://openalex.org/I4210119061","https://openalex.org/I4210152422","https://openalex.org/I4387153255","https://openalex.org/I4405258862","https://openalex.org/I4405259414"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Francois Barr\u00e8re","raw_affiliation_strings":["IRIT/University Paul Sabatier, Toulouse, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"IRIT/University Paul Sabatier, Toulouse, France","institution_ids":["https://openalex.org/I134560555","https://openalex.org/I4210119061"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5064062710","display_name":"Abdelmalek Benzekri","orcid":"https://orcid.org/0000-0001-8236-8690"},"institutions":[{"id":"https://openalex.org/I134560555","display_name":"Universit\u00e9 Toulouse III - Paul Sabatier","ror":"https://ror.org/02v6kpv12","country_code":"FR","type":"education","lineage":["https://openalex.org/I134560555"]},{"id":"https://openalex.org/I4210119061","display_name":"Institut de Recherche en Informatique de Toulouse","ror":"https://ror.org/01rx4qw44","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I205747304","https://openalex.org/I205747304","https://openalex.org/I4210119061","https://openalex.org/I4210152422","https://openalex.org/I4387153255","https://openalex.org/I4405258862","https://openalex.org/I4405259414"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Abdelmalek Benzekri","raw_affiliation_strings":["IRIT/University Paul Sabatier, Toulouse, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"IRIT/University Paul Sabatier, Toulouse, France","institution_ids":["https://openalex.org/I134560555","https://openalex.org/I4210119061"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.5192,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.87435722,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10639","display_name":"Advanced Software Engineering Methodologies","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10430","display_name":"Software Engineering Techniques and Practices","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/requirements-engineering","display_name":"Requirements engineering","score":0.7818950414657593},{"id":"https://openalex.org/keywords/security-engineering","display_name":"Security engineering","score":0.709752082824707},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6903138756752014},{"id":"https://openalex.org/keywords/requirements-elicitation","display_name":"Requirements elicitation","score":0.5999184846878052},{"id":"https://openalex.org/keywords/requirement","display_name":"Requirement","score":0.5613089799880981},{"id":"https://openalex.org/keywords/requirements-analysis","display_name":"Requirements analysis","score":0.4728783965110779},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.4568633735179901},{"id":"https://openalex.org/keywords/non-functional-requirement","display_name":"Non-functional requirement","score":0.43476617336273193},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.4206163287162781},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.4109693467617035},{"id":"https://openalex.org/keywords/risk-analysis","display_name":"Risk analysis (engineering)","score":0.38602137565612793},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.28294849395751953},{"id":"https://openalex.org/keywords/software-security-assurance","display_name":"Software security assurance","score":0.2815493047237396},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.23441675305366516},{"id":"https://openalex.org/keywords/security-service","display_name":"Security service","score":0.17354559898376465},{"id":"https://openalex.org/keywords/software-development","display_name":"Software development","score":0.09489193558692932},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.09037145972251892},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.06301727890968323}],"concepts":[{"id":"https://openalex.org/C6604083","wikidata":"https://www.wikidata.org/wiki/Q376937","display_name":"Requirements engineering","level":3,"score":0.7818950414657593},{"id":"https://openalex.org/C13159133","wikidata":"https://www.wikidata.org/wiki/Q365674","display_name":"Security engineering","level":5,"score":0.709752082824707},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6903138756752014},{"id":"https://openalex.org/C45384764","wikidata":"https://www.wikidata.org/wiki/Q838667","display_name":"Requirements elicitation","level":4,"score":0.5999184846878052},{"id":"https://openalex.org/C135475081","wikidata":"https://www.wikidata.org/wiki/Q774228","display_name":"Requirement","level":4,"score":0.5613089799880981},{"id":"https://openalex.org/C59488412","wikidata":"https://www.wikidata.org/wiki/Q187147","display_name":"Requirements analysis","level":3,"score":0.4728783965110779},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.4568633735179901},{"id":"https://openalex.org/C199747065","wikidata":"https://www.wikidata.org/wiki/Q3254666","display_name":"Non-functional requirement","level":5,"score":0.43476617336273193},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.4206163287162781},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.4109693467617035},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.38602137565612793},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.28294849395751953},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.2815493047237396},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.23441675305366516},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.17354559898376465},{"id":"https://openalex.org/C529173508","wikidata":"https://www.wikidata.org/wiki/Q638608","display_name":"Software development","level":3,"score":0.09489193558692932},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.09037145972251892},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.06301727890968323},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C186846655","wikidata":"https://www.wikidata.org/wiki/Q3398377","display_name":"Software construction","level":4,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3098954.3098996","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3098954.3098996","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":18,"referenced_works":["https://openalex.org/W185673473","https://openalex.org/W818892910","https://openalex.org/W1987826190","https://openalex.org/W2002530109","https://openalex.org/W2006034650","https://openalex.org/W2097154968","https://openalex.org/W2109265070","https://openalex.org/W2109477976","https://openalex.org/W2111695375","https://openalex.org/W2129289644","https://openalex.org/W2145561519","https://openalex.org/W2146863076","https://openalex.org/W2271655342","https://openalex.org/W2289651665","https://openalex.org/W2593740729","https://openalex.org/W4233171448","https://openalex.org/W4247077770","https://openalex.org/W6996265188"],"related_works":["https://openalex.org/W2472769502","https://openalex.org/W2242308721","https://openalex.org/W4254568495","https://openalex.org/W142054160","https://openalex.org/W2608001814","https://openalex.org/W4235167339","https://openalex.org/W1617997706","https://openalex.org/W2901540557","https://openalex.org/W34814695","https://openalex.org/W3153864189"],"abstract_inverted_index":{"Since":[0],"many":[1],"decades,":[2],"requirements":[3,25,41],"engineering":[4,26,42],"domain":[5],"has":[6],"seen":[7],"significant":[8],"enhancements":[9],"towards":[10],"adapting":[11],"the":[12,34,73],"security":[13,24,35,40],"and":[14,31],"risk":[15],"analysis":[16],"concepts.":[17],"In":[18,60],"this":[19,61],"regard,":[20],"there":[21],"exist":[22],"numerous":[23],"methodologies":[27],"that":[28,69],"support":[29],"elicitation":[30],"evaluation":[32,67],"of":[33,49,56,75],"requirements.":[36],"However,":[37],"selecting":[38],"a":[39,46,54,65,76],"methodology":[43,68],"(SRE)":[44],"for":[45],"given":[47],"context":[48],"use":[50],"often":[51],"depends":[52],"on":[53],"set":[55],"ad":[57],"hoc":[58],"criteria.":[59],"paper,":[62],"we":[63],"propose":[64],"methodological":[66],"helps":[70],"in":[71],"identifying":[72],"characteristics":[74],"good":[77],"SRE":[78],"methodology.":[79]},"counts_by_year":[{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":3},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
