From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 24,300 courses taught by industry experts.

Security requirements definition

Security requirements definition

- In this first lesson of securing the DevOps lifecycle, we want to talk about functional requirements. Functional security requirements describe what a system should do to ensure security. They define the specific behaviors and functions that a system must perform to meet security objectives. These functional requirements are essential for verifying that the system behaves as intended, as designed, and offers the necessary security controls. Some examples of functional security requirements, as it relates to DevOps, might include user authentication and authorization mechanisms, data encryption and decryption processes, access control policies and procedures, logging and monitoring activities, and data integrity mechanisms, and especially backup and recovery mechanisms. Now, we also have non-functional security requirements. These are ones that focus on how a system should perform, rather on what it should do. So non-functional requirements encompass a range of quality attributes…

Contents