
240 ◾ The Security Risk Assessment Handbook
© 2011 by Taylor & Francis Group, LLC
1. Determine the security requirements of the critical systems.
2. Assess the security design against basic security engineering principles.
3. Assess the security design against a set of common mistakes or investigation
areas.
7.2.1.3.1 Determine Security Requirements
In government systems, this process can typically be accomplished without too
much eort, because the security requirements should be documented in the certi-
cation and accreditation package. For those systems outside government agencies,
determining the security requirements of the system may ...