We propose an integrated process for component-based system development and security risk analysis. The integrated process is evaluated in a case study involving an instant messaging component for smart phones. We specify the risk behaviour and functional behaviour of components using the same kinds of description techniques. We represent main security risk analysis concepts, such as assets, stakeholders, threats and risks, at the component level. Categories and Subject Descriptors D.2 [Software]: Software Engineering--requirements/ specifications General Terms Security, Theory Keywords Case studies, Security Risk Analysis