Abstract
Security requirements needs to be integrated into the earliest stages of the software development life cycle, and propagated throughout its various phases. Therefore, it is beneficial to have secure development integrated with industry standard methodologies and notations. One of the tool often used in capturing software requirements is use case. Although use case diagrams visually represent the behavioral requirements of a proposed software system, they are not sufficient to represent existing access control policies. At best, use case diagram shows some access control by stating the roles that actors are permitted to invoke. This paper enhanced previous attempts by several scientists to enrich the use case diagram in order to capture more access control polices. This introduction fell in the effort to provide more tools and notations to think and embed security requirements in the early stage of the life cycle.