Combining Privacy and Security Risk Assessment in Security Quality Requirements Engineering

Security risk assessment identifies the threats to sys- tems, while privacy risk assessment identifies data sen- sitivities in systems. The Security Quality Require- ments Engineering (SQUARE) method is used to iden- tify software security issues in the early stages of the development lifecycle. We propose combining the ex- isting security risk assessment techniques in SQAURE with the Privacy Impact Assessment (PIA) technique and the Health Insurance Portability and Accountability Act (HIPAA) to address the full spectrum of security and privacy risks. Our ultimate goal is to introduce a privacy requirements engineering method that uses steps of SQUARE for privacy instead of or in addition to security.