As per the ASAP Process what all artifacts are provided to help aid in the analysis phase?
-
Security URS
-
Security URS and SRS
-
Security Design Guidelines
-
All of the above
ASAP provides Security URS (User Requirement Specification) and Security SRS (Software Requirement Specification) artifacts to guide the analysis phase. These documents capture security requirements and specifications that must be addressed throughout development.
In the ASAP (Application Security Assurance Process) style methodologies, the analysis phase is fed by requirements-level artifacts: the Security User Requirements Specification (URS) and the Security Requirements Specification (SRS). These capture what the business and security needs are before design begins, so they're the natural inputs to an analysis step. Design guidelines belong to the design phase, not analysis, which is why 'All of the above' overreaches.