To specify security requirements, one should identify the risks that are to be dealt with.
(a) True
(b) False
I have been asked this question by my college director while I was bunking the class.
My question comes from Dependability and Security Specification topic in section Dependability and Security of Software Engineering