  1. What do you understand by Security Requirements Engineering? Explain to understand.
  2. Distinguish between a reactionary and proactive approach to secure software.
  3. The Author says “In order to be successful, the overall approach (process and tools) must be both measurable and feasible”.  What do you understand by this statement?
  4. Defining security requirements can be difficult due to a lack of common ground among stakeholders in terms of security knowledge, skill, and even vocabulary. Do you agree or disagree? Why?
  5. It is highly desirable to develop stable requirements as early as possible. Why?

see the attchment to answer them

