To specify security requirements, one should identify the risks that are to be dealt with ?
		A. True
B. False
Explanation: To specify security requirements, one should identify the assets that are to be dealt with.
		A. True
B. False
Explanation: To specify security requirements, one should identify the assets that are to be dealt with.
		A. True
B. False
Explanation: None.
		A. Human error or mistake
B. System fault
C. System error
D. System failure
		A. Concurrent systems can be analysed to discover race conditions that might lead to deadlock
B. Producing a mathematical specification requires a detailed analysis of the requirements
C. They require the use of specialised notations that cannot be understood by domain experts
D. All of the mentioned
		A. Attack
B. Threat
C. Vulnerability
D. Control
Explanation: The answer is self explanatory.
		A. Risk assessment before the system has been deployed
B. Risk assessment while the system is being developed
C. All of the mentioned
D. None of the mentioned
		A. Checking requirements
B. Recovery requirements
C. Redundancy requirements
D. Ambiguous requirements
Explanation: These requirements are geared to helg the system recover after a failure has occurred.