What is a Requirement Specification, and what are the key types of Non-Functional Requirement?
A requirement specification is a systematically organised collection of requirements for a system or component that satisfies given criteria; non-functional requirements are the "how well" qualities — performance, scalability, portability, usability, compatibility, localization, reliability, security, maintainability and availability.
* Non-functional (quality) requirements describe how well a system behaves — the key types shown as a single radial map. *
A requirement specification is a systematically represented collection of requirements, typically for a system or component, that satisfies given criteria. "Systematically represented" is the load-bearing part: a pile of requirements is not a specification until it is organised into groups you can navigate, review and sign off.
Functional requirements say what the system does ("the user can transfer money"); non-functional requirements (quality attributes) say how well it does it:
| Category | Examples |
|---|---|
| Performance | Response time, throughput |
| Scalability | Handle growth in users or data |
| Reliability | Uptime, fault tolerance |
| Availability | System accessible when needed |
| Security | Protection against unauthorised access |
| Usability | Ease of use, learnability |
| Maintainability | Ease of modification and debugging |
| Portability | Run on different platforms |
| Compatibility | Work with other systems |
| Localization | Adapt to language, region and local conventions |
The categories overlap and trade against each other, which is the real reason to name them separately: hardening for security costs performance and usability, and designing for portability limits which platform-specific tricks you can use for performance. Naming each one forces the trade-off into the open where a stakeholder can decide it, instead of a developer settling it silently in code.
Tip: Security is a non-functional requirement — it describes how well the system protects itself, not what it does. That is also why it is the easiest one to forget: no user story ever begins "as an attacker, I would like to be stopped".
Go deeper:
AltexSoft — What are Non-functional Requirements and How Do They Work? — a walk through the very category map this figure is built from.
Non-functional requirement (Wikipedia) — a far longer list of quality attributes, each defined.