It is therefore necessary to define a set of metrics, both at the
design level and later, which is related to the implementation level
and which will allow us to evaluate the fulfilment level needed by
security requirements which have been specified in the software
analysis stages. These metrics must, moreover, be integrated into a
security model (as a quality component) which has a clearly
identified taxonomy of security requirements for which they can
be identified, modelled and implemented, along with the
remaining requirements, be they functional or non-functional.
In future works we shall use the approaches analysed here as
basis to propose both a security model and a design security
metrics model. These models will be a concept integrated
approach whose intention will be to offer a common vision of the
area, both with regard to characteristics and sub-characteristics
and to their formal definition.