Security requirement
A documented, approved, and verifiable statement of a security property, behavior, constraint, or outcome that the software or its supporting environment must satisfy.
Example: Replace the vague statement with a requirement that identifies the subject, protected object, triggering condition, required behavior, and verification criterion.
Counterexample: Approve “The application shall be secure” as a complete requirement without defining observable behavior or a pass/fail test. | Replace the sentence with “Use AES-256 and MFA” without stating protected objects, conditions, or expected behavior. | Accept the statement because penetration testing will determine whether the application is secure, and the test team would still have no objective pass/fail basis.