Functional Requirements Definition

Defining functional requirements with embedded security considerations directs development toward applications that satisfy user needs while meeting protection goals.

5 slides · 2 min read · Domain 8

Slide 1

The Requirements Analysis phase of the Software Development Life Cycle (SDLC) is when the project management and systems development teams conduct a comprehensive analysis of functional requirements.

This phase focuses on understanding the needs of the system, both current and future, to define what the software must do.

Functional and nonfunctional requirements for security controls and compliance needs should be identified during this phase, too. The teams, including their security representatives, also review the documents from the project initiation phase and make any revisions or updates as needed. At this point, security requirements should be formalized by involving all parties-the owners, compliance, privacy, businessfacing functions, and other stakeholders that should be aware of the security needs that must be addressed.

The figure shows some of the security activities in the Requirements Analysis phase. Most systems have three types of requirements: functional, nonfunctional, and emerging.

Waterfall SDLC and many other software development methodologies face difficulties in adequately addressing nonfunctional requirements, and analysts and designers often express frustration with nonfunctional requirements that don't neatly align with specific design elements or subfunctions.

A potential pitfall in software requirements analysis is where the focus on functional requirements (what the system does) can overshadow nonfunctional requirements (how the system behaves, such as performance, security, and usability. This is considered a fallacy of reasoning by many, especially within the systems safety communities.

Text on this slide

Identity Develop Functional Project Plan Requirements Set Test Criteria

Identify Security

Areas

Establish Security Requirements Security Tests

Prepare Risk Analysis and Contingency Plan Figure: Functional requirements specifications security activities

Define Strategy Develop Functional Baseline

Include Security Include Functional Requirements in RFPs, Security Contracts Requirements

To date, no practical way has been found to take a set of systems requirements-functional, nonfunctional, and emerging properties-and formally analyze or prove that they are complete, not self-contradictory, and correctly reflect what the people writing them intended.

Errors in the requirements process can, of course, lead to systems that ultimately behave during operational use in unreliable, unsafe, or unsecure ways. Risk management attempts to reduce this inevitability; it cannot eliminate it completely.

Test this domain