Effective Systems Security Requirements in Product Line Engineering

被引:0
|
作者
Adejokun, Ademola [1 ]
Siok, Michael F. [2 ]
机构
[1] Lockheed Martin Aeronautics, Fort Worth,TX, United States
[2] Computer Science and Engineering Department at the University of Texas, Arlington,TX, United States
关键词
Cryptography - Product design;
D O I
10.1002/inst.12306
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Requirements engineering for complex software-intensive systems (and other systems) requires identifying, specifying, analyzing, and reviewing system requirements early in the system development process. However, many cases overlook system security requirements, treating them as an afterthought during this important initial process stage. Missing security requirements for these system types cannot guarantee system integrity. It is not cost efficient to retrofit requirements at later stages to include missing security capabilities specified earlier in-process. Detailed analysis and understanding of security requirements enable building confidentiality and integrity into our systems. Thus, early process activities must include security requirements engineering. Product Line Engineering development must guarantee system integrity and assurance for a family of systems borne from a common design. Hence, detailed requirements elicitation and specification is important early in the product-line development and must include security requirements. Further, security requirements must revisit applicability, extension, and new security requirements specified to provide for security coverage of selected features contained within the product line's instances. This paper describes an approach to security requirements engineering identification and includes introducing a security profile to facilitate developing and evolving a secure product line for software-intensive systems. © 2020 by Ademola Adejokun and Michael F. Siok. Published and used by INCOSE with permission.
引用
收藏
页码:26 / 30
相关论文
共 50 条
  • [31] Software Product Line Engineering for Robotic Perception Systems
    Brugali, Davide
    Hochgeschwender, Nico
    INTERNATIONAL JOURNAL OF SEMANTIC COMPUTING, 2018, 12 (01) : 89 - 107
  • [32] Special issue on systems and software product line engineering
    Acher, Mathieu
    Cohen, Myra B.
    JOURNAL OF SYSTEMS AND SOFTWARE, 2019, 154 : 110 - 111
  • [33] Second Generation Systems and Software Product Line Engineering
    Krueger, Charles W.
    Clements, Paul C.
    18TH INTERNATIONAL SOFTWARE PRODUCT LINE CONFERENCE (SPLC 2014), VOL 1, 2014, : 358 - 358
  • [34] Security and trust requirements engineering
    Giorgini, P
    Massacci, F
    Zannone, N
    FOUNDATIONS OF SECURITY ANALYSIS AND DESIGN III, 2005, 3655 : 237 - 272
  • [35] Security requirements engineering for software systems: Case studies in support of software engineering education
    Mead, Nancy R.
    Hough, Eric D.
    19TH CONFERENCE ON SOFTWARE ENGINEERING EDUCATION & TRAINING, PROCEEDINGS, 2006, : 149 - +
  • [36] Ontology as a requirements engineering product
    Breitman, KK
    Leite, JCSD
    11TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE, PROCEEDINGS, 2003, : 309 - 319
  • [37] Using requirements management tools in software product line engineering: The state of the practice
    Beuche, Danilo
    Birk, Andreas
    Dreier, Heinrich
    Fleischmann, Andreas
    Galle, Heidi
    Heller, Gerald
    Janzen, Dirk
    John, Isabel
    Kolagari, Ramin Tavakoli
    von der Massen, Thomas
    Wolfram, Andreas
    SPLC 2007: 11TH INTERNATIONAL SOFTWARE PRODUCT LINE CONFERENCE, PROCEEDINGS, 2007, : 84 - +
  • [38] Rigorous engineering of product-line requirements: A case study in failure management
    Snook, Colin
    Poppleton, Michael
    Johnson, Ian
    INFORMATION AND SOFTWARE TECHNOLOGY, 2008, 50 (1-2) : 112 - 129
  • [39] Measuring usability of requirements using social network service in product line engineering
    Park, Sang-Eun
    Kim, Neunghoe
    Lee, Jung-Been
    Lee, Geunhyung
    In, Hoh Peter
    International Journal of Multimedia and Ubiquitous Engineering, 2014, 9 (03): : 213 - 218
  • [40] Towards the Model-Driven Engineering of Security Requirements for Embedded Systems
    Roudier, Yves
    Idrees, Muhammad Sabir
    Apvrille, Ludovic
    2013 3RD INTERNATIONAL WORKSHOP ON MODEL-DRIVEN REQUIREMENTS ENGINEERING (MODRE), 2013, : 55 - 64