Effective Systems Security Requirements in Product Line Engineering

被引:0
|
作者
Adejokun, Ademola [1 ]
Siok, Michael F. [2 ]
机构
[1] Lockheed Martin Aeronautics, Fort Worth,TX, United States
[2] Computer Science and Engineering Department at the University of Texas, Arlington,TX, United States
关键词
Cryptography - Product design;
D O I
10.1002/inst.12306
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Requirements engineering for complex software-intensive systems (and other systems) requires identifying, specifying, analyzing, and reviewing system requirements early in the system development process. However, many cases overlook system security requirements, treating them as an afterthought during this important initial process stage. Missing security requirements for these system types cannot guarantee system integrity. It is not cost efficient to retrofit requirements at later stages to include missing security capabilities specified earlier in-process. Detailed analysis and understanding of security requirements enable building confidentiality and integrity into our systems. Thus, early process activities must include security requirements engineering. Product Line Engineering development must guarantee system integrity and assurance for a family of systems borne from a common design. Hence, detailed requirements elicitation and specification is important early in the product-line development and must include security requirements. Further, security requirements must revisit applicability, extension, and new security requirements specified to provide for security coverage of selected features contained within the product line's instances. This paper describes an approach to security requirements engineering identification and includes introducing a security profile to facilitate developing and evolving a secure product line for software-intensive systems. © 2020 by Ademola Adejokun and Michael F. Siok. Published and used by INCOSE with permission.
引用
收藏
页码:26 / 30
相关论文
共 50 条
  • [22] Constructing Traceability between Features and Requirements for Software Product Line Engineering
    Yu, Dongjin
    Geng, Peng
    Wu, Wei
    2012 19TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE WORKSHOPS (APSECW), VOL. 2, 2012, : 27 - 34
  • [23] Rationale-based variability management in product line requirements engineering
    Thurimella, Anil Kumar
    PROCEEDINGS OF THE IASTED INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, 2007, : 210 - 215
  • [24] Engineering safety and security related requirements for software intensive systems
    Firesmith, Donald G.
    29th International Conference on Software Engineering: ICSE 2007 Companion Volume, Proceedings, 2007, : 169 - 169
  • [25] Security Requirements Engineering: A Framework for Cyber-Physical Systems
    Rehman, Shafiq Ur
    Allgaier, Christopher
    Gruhn, Volker
    2018 INTERNATIONAL CONFERENCE ON FRONTIERS OF INFORMATION TECHNOLOGY (FIT 2018), 2018, : 315 - 320
  • [26] Effective Requirements Engineering
    Bail, William
    SIGADA 2010: PROCEEDING OF THE 2010 ACM INTERNATIONAL CONFERENCE ON ADA AND RELATED TECHNOLOGIES, 2010, : 1 - 1
  • [27] BridgeSec: Facilitating effective communication between security engineering and systems engineering
    Shaked, Avi
    Messe, Nan
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2025, 89
  • [28] Requirements Engineering for Product Service Systems A State of the Art Analysis
    Berkovich, Marina
    Krcmar, Helmut
    Leimeister, Jan Marco
    BUSINESS & INFORMATION SYSTEMS ENGINEERING, 2011, 3 (06): : 369 - 380
  • [29] Mapping Product Line Requirements to a Product Line Architecture
    Mannion, Mike
    Savolainen, Juha
    18TH INTERNATIONAL SOFTWARE PRODUCT LINE CONFERENCE (SPLC 2014), VOL 1, 2014, : 362 - 362
  • [30] System Security Engineering and Feature-based Product Line Engineering: A Productive Marriage
    Young, Bobbi
    Darbin, Rowland
    Clements, Paul
    Insight, 2020, 23 (03) : 13 - 16