Elicitation of SME Requirements for Cybersecurity Solutions by Studying Adherence to Recommendations
نویسندگان
چکیده
[Context and motivation] Small and medium-sized enterprises (SME) have become the weak spot of our economy for cyber attacks. These companies are large in number and often do not have the controls in place to prevent successful attacks, respectively are not prepared to systematically manage their cybersecurity capabilities. [Question/problem] One of the reasons for why many SME do not adopt cybersecurity is that developers of cybersecurity solutions understand little the SME context and the requirements for successful use of these solutions. [Principal ideas/results] We elicit requirements by studying how cybersecurity experts provide advice to SME. The experts’ recommendations offer insights into what important capabilities of the solution are and how these capabilities ought to be used for mitigating cybersecurity threats. The adoption of a recommendation hints at a correct match of the solution, hence successful consideration of requirements. Abandoned recommendations point to a misalignment that can be used as a source to inquire missed requirements. Re-occurrence of adoption or abandonment decisions corroborate the presence of requirements. [Contributions] This poster describes the challenges of SME regarding cybersecurity and introduces our proposed approach to elicit requirements for cybersecurity solutions. The poster describes CYSEC, our tool used to capture cybersecurity advice and help to scale cybersecurity requirements elicitation to a large number of participating SME. We conclude by outlining the planned research to develop and validate CYSEC.
منابع مشابه
Elicitation Strategies for Web Application Using Activity Theory
Requirements engineering (RE) is often seen as an essential facet in software development. It is a vital process before each project starts. In the context of systems engineering, an understanding and application of systems theory and practice is also relevant to RE. The contexts in which RE takes place habitually involve human activities. Therefore, RE needs to be sensitive to how people perce...
متن کاملElicitation Strategies for Web Application Using Activity Theory
Requirements engineering (RE) is often seen as an essential facet in software development. It is a vital process before each project starts. In the context of systems engineering, an understanding and application of systems theory and practice is also relevant to RE. The contexts in which RE takes place habitually involve human activities. Therefore, RE needs to be sensitive to how people perce...
متن کاملS3C: Using Service Discovery to Support Requirements Elicitation in the ERP Domain
[Context and motivation] Requirements Elicitation and Fit Gap analysis are amongst the most time and effort-consuming steps in an ERP project. There is a potentially high rate of reuse in ERP projects as solutions are mainly based on standard software components and services. [Question/problem] The increasing number of standard software services limits the consultants’ ability to identify relev...
متن کاملEmbedded R&D for Cybersecurity in an Operational Environment
This paper describes a paradigm shift from how cybersecurity research and development (R&D) is traditionally applied in an operational environment. The methodology is referred to as embedded R&D (eR&D); cybersecurity researchers are tightly coupled with the operational stakeholders. This tight-knit relationship allows the researchers to elicit R&D requirements from the stakeholders seamlessly o...
متن کاملCybersecurity Information Sharing: a Framework for Sustainable Information Security Management in UK SME Supply Chains
UK small to medium sized enterprises (SMEs) are suffering increasing levels of cybersecurity breaches and are a major point of vulnerability in the supply chain networks in which they participate. A key factor for achieving optimal security levels within supply chains is the management and sharing of cybersecurity information associated with specific metrics. Such information sharing schemes am...
متن کامل