We discussed security requirements in four areas. We provided samples of how to define security release gates for each development stage, such as design, coding, build, testing, delivery, and monitoring. CVSS evaluation is also suggested whenever there is a dilemma: whether to go for the next release or not.
For a product manager to plan security features, we recommend OWASP ASVS. Depending on the business scenario, there are three levels of security. Based on the OWASP ASVS, an open source OWASP Security Knowledge Framework was introduced to help an organization to set up an in-house security knowledge portal.
For data security and privacy, we discussed the security requirements for big data.
For big data requirements, the CSA defines four security categories: such as Infrastructure Security, Data Privacy, Data Management and Integrity, and Reactive Security. In addition...