[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-239581-105":53,"doc-detail-239581-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","security-requirements-template-based-approach-to-improve-the-writing-of-complete-security-requirements","SECURITY REQUIREMENTS TEMPLATE-BASED APPROACH TO IMPROVE THE WRITING OF COMPLETE SECURITY REQUIREMENTS","","Writing quality security requirements drives the success of secure software development. Delaying security requirements until after system definition increases the likelihood of security vulnerabilities, while producing complete requirements remains a tedious, complex task for requirements engineers. The work identifies challenges from natural-language ambiguity and misunderstandings of security terms that lead to incompleteness. It presents a prototype tool, SecureMEReq, using pattern libraries to extract, validate, and check syntax and structure, and to support completeness prioritization with comparative evaluation.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/security-requirements-template-based-approach-to-improve-the-writing-of-complete-security-requirements/239581/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/security-requirements-template-based-approach-to-improve-the-writing-of-complete-security-requirements/239581.png","ImageObject",442,249,{"name":88,"@type":89},"Mason","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-21","2026-09-11",true,{"@type":98,"interactionType":99,"userInteractionCount":9},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"Why does writing complete security requirements matter in secure software development?","Question",{"text":108,"@type":109},"Incomplete security requirements can cause costly development failure and may produce incorrect non-functional security requirements.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What makes eliciting and writing complete security requirements difficult?",{"text":113,"@type":109},"The process relies heavily on natural-language discussions, where ambiguity and misunderstanding of security terms lead to incompleteness.",{"name":115,"@type":106,"acceptedAnswer":116},"How does SecureMEReq support requirements engineers in writing complete security requirements?",{"text":117,"@type":109},"SecureMEReq provides features to extract security requirement components, validate density and syntax, check requirements and key-structure components, and validate completeness prioritization using pattern libraries.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},239581,1790000559,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":73,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":15,"language":135,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":136,"faqs":137,"seo_title":138,"seo_description":61,"update_tm":139,"read_time":79},5909887256941,"https://ap-avatar.wpscdn.com/davatar_9964176cb1d06d4a9deccf72a44ae3dc","Journal of Theoretical and Applied Information Technology  \n15th January 2021. Vol.99. No 1  \n© 2005 – ongoing JATIT & LLS  \nISSN: 1992-8645 [www.jatit.org](www.jatit.org) E-ISSN: 1817-3195  \nSECURITY REQUIREMENTS TEMPLATE-BASED APPROACH TO IMPROVE THE WRITING OF COMPLETE SECURITY REQUIREMENTS  \n1 NURIDAWATI MUSTAFA, 2 MASSILA KAMALRUDIN, 3 SAFIAH SIDEK  \n1Senior Lecturer, Department of Software Engineering, Faculty of Information and Communication Technology, Universiti Teknikal Malaysia Melaka, Malaysia 2Professor, Innovative Software System and Service Group (IS3), Universiti Teknikal Malaysia Melaka,  \nMalaysia  \n3Associate Professor, Innovative Software System and Service Group (IS3), Universiti Teknikal Malaysia  \nMelaka, Malaysia  \n[E-mail:](E-mail: 1nuridawati@utem.edu.my)[ 1](E-mail: 1nuridawati@utem.edu.my)[nuridawati@utem.edu.my](E-mail: 1nuridawati@utem.edu.my), [2](2massila@utem.edu.my)[massila@utem.edu.my](2massila@utem.edu.my), [3](3safiahsidek@utem.edu.my)[safiahsidek@utem.edu.my](3safiahsidek@utem.edu.my)  \nABSTRACT  \nWriting quality security requirements contributes to the success of secure software development. It has been a common practice to include security requirements in a software system after the system is defined. Thus, incorporating security requirements at a later stage of software development will increase the risks of security vulnerabilities in software development. However, the process of writing security requirements is tedious and complex. Although significant work can be found in the field of requirements elicitation, less attention has been given for writing complete security requirements. It is still a challenge and tedious process for requirements engineers (REs) to elicit and write complete security requirements that are derived from natural language. This is due to their tendency to misunderstand the real needs and the security terms used by inexperienced REs leading to incomplete security requirements. Motivated from these problems, we have developed a prototype tool, called SecureMEReq to improve the writing of complete security requirements. This tool provides four important key-features, which are (1) extraction of security requirements components from client-stakeholders; (2) validation of security requirements probability density and security requirements syntax density; (3) checking the security requirements and key-structure components; and (4) validation of completeness prioritization. To do this, we used our pattern libraries: SecLib and SRCLib to support the automation process of elicitation, especially in writing the security requirements. To evaluate our approach and tool, we have conducted completeness tests to compare the completeness of writing security requirements through the results provided by SecureMEReq and manual writing. Our evaluation results show that our prototype tool is capable to facilitate the writing of complete security requirements and useful in assisting the REs to elicit the security requirements.  \nKeywords: Tool Security Requirements, Template-Based Approach, Security Requirements Completeness, Template-Based Density, Syntax Density  \n1. INTRODUCTION  \nCapturing complete security requirements is crucial for the development of a secure software because incompletely defined and poor elicited security requirements may result in costly development failure [1] . Further, incomplete security requirements could lead to generating incorrect non-functional security requirements [2] . At present, when capturing security requirements  \nfrom clients, Requirement Engineers (RE) often uses some forms of natural language, written either by clients or themselves. These requirements are captured from the discussion and negotiation between both parties; clients and the RE. However, due to the ambiguities and complexities of natural language [3][4] and the process of capturing, these requirements often have incompleteness. RE also faced problems in eliciting consisten","cbCaiaSvYWrX2IWW","https://ap.wps.com/l/cbCaiaSvYWrX2IWW","pdf",2124412,"English","# Abstract\n# Introduction\n## Importance of Complete Security Requirements\n## Security Requirements Definition and Examples\n## Motivation for Early Completeness Checking\n# Background and Motivations\n# Template-Based Approach Overview\n# Tool Support Implementation\n# Tool Validation Methodology\n# Threats to Validity\n# Results and Discussion\n# Conclusion and Future Work","[{\"question\":\"Why does writing complete security requirements matter in secure software development?\",\"answer\":\"Incomplete security requirements can cause costly development failure and may produce incorrect non-functional security requirements.\"},{\"question\":\"What makes eliciting and writing complete security requirements difficult?\",\"answer\":\"The process relies heavily on natural-language discussions, where ambiguity and misunderstanding of security terms lead to incompleteness.\"},{\"question\":\"How does SecureMEReq support requirements engineers in writing complete security requirements?\",\"answer\":\"SecureMEReq provides features to extract security requirement components, validate density and syntax, check requirements and key-structure components, and validate completeness prioritization using pattern libraries.\"}]","SECURITY REQUIREMENTS TEMPLATE-BASED APPROACH TO IMPROVE THE WRITING OF COMPLETE SECURITY REQUIREMENTS | PDF",1789150818]