If you are building a reusable Security Product tool to specifically address Security Technical Implementation Guide (STIG) Findings, should the requirements be considered Non Functional Requirements or Functional Requirements?
For example if there are a number of STIGs such as:
should I add them to the Functional or Non Functional section of my Requirements Document.
Add your answers and thoughts in comments below:
» What is the Community Blog and what are the Benefits of Contributing?
» Review our Blog Posting Guidelines.
» I am looking for the original Modern Analyst blog posts.
brought to you by enabling practitioners & organizations to achieve their goals using: