A “secure system” is a system that ensures that only the authorized intended behaviors and outcomes occur, thereby providing freedom from those conditions, both intentionally/with malice and unintentionally/without malice, that can cause a loss of information assets with unacceptable consequences. The focus is on defining "adequate security" based on the organization's specific scenario (e.g., threats, risks, limitations, resources, etc.)
This definition expresses an ideal that captures three essential aspects of what it means to achieve security:
No technology can provide absolute security due to the limits of human certainty, the uncertainty that exists in the life cycle of every system, and the constraints of cost, schedule, performance, feasibility, and practicality. Trade-offs are expected to be routinely made across contradictory, competing, and conflicting needs and constraints. These trade-offs must be optimized to achieve "adequate security" - a risk-based decision made by stakeholders.
Requirements can be categorized as stakeholder requirements (design-independent) and system requirements (design-dependent). Both practitioners and architects need to understand the distinction.
An organization publishes policies to eliminate potential gaps in that desired governed behavior in an attempt to achieve “adequate security” for the organization based on what a reasonable individual would be expected to do in a similar situation. The rules associated with this “governed behavior” must be accurate, consistent, compatible, and complete with respect to the executive leadership's objectives to successfully accomplish the organization's mission and overall strategy. An organization's policies ultimately define the behavior of Individual Contributors (IC) (e.g., developers, architects) in performing their roles and associated responsibilities, as well as for the development of processes and procedures. This eventually leads to the configuration of technology assets (e.g., systems, applications, services and processes), where a discrete set of restrictions and properties must exist to specify how that asset enforces or contributes to the enforcement of the organizational security policies.
Security-relevant stakeholder requirements specify:
System requirements specify the technical view of a system or solution that meets the specified stakeholder needs. They are a transformation of the validated stakeholder requirements. System security requirements specify: