Security requirements variability for software product lines

被引:2
|
作者
Mellado, Daniel [1 ]
Fernandez-Medina, Eduardo [2 ]
Piattini, Mario [2 ]
机构
[1] Ministry Work & Social Affairs, Social Secur IT Dept, Madrid, Spain
[2] Univ Castilla La Mancha, Informat Syst Technol Dept, Alarcos Res Grp, E-13071 Ciudad Real, Spain
关键词
D O I
10.1109/ARES.2008.165
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software product line engineering has proven to be one of the most successful paradigms for developing a diversity of similar software applications and software-intensive systems at low costs, in short time, and with high quality, by exploiting commonalities and variabilities among products to achieve high levels of reuse. At the same time, due to the complexity and extensive nature of product line development, security and requirements engineering are critical success factors in the development of a software product line. However, most of the current product line practices in requirements engineering do not adequately address the security requirements engineering. Therefore, in this paper we will propose a security requirements decision model driven by security standards along with a security variability model to manage the variability of the security requirements related artefacts. The aim of this approach is to deal with security requirements from the early stages of the product line development in a systematic way, in order to facilitate the conformance to the most relevant security standards with regard to the management of security requirements, such as ISO/IEC 27001 and ISO/IEC 15408.
引用
收藏
页码:1413 / +
页数:3
相关论文
共 50 条
  • [1] Security requirements in software product lines
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    SECRYPT 2008: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2008, : 442 - +
  • [2] Security requirements engineering framework for software product lines
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    INFORMATION AND SOFTWARE TECHNOLOGY, 2010, 52 (10) : 1094 - 1117
  • [3] Representing and Configuring Security Variability in Software Product Lines
    Myllarniemi, Varvana
    Raatikainen, Mikko
    Mannisto, Tomi
    QOSA'15 PROCEEDINGS OF THE 11TH INTERNATIONAL ACM SIGSOFT CONFERENCE ON QUALITY OF SOFTWARE ARCHITECTURES, 2015, : 1 - 10
  • [4] Towards security requirements management for software product lines:: A security domain requirements engineering process
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    COMPUTER STANDARDS & INTERFACES, 2008, 30 (06) : 361 - 371
  • [5] A metamodeling approach to tracing variability between requirements and architecture in software product lines
    Moon, Mikyeong
    Chae, Heung Seok
    Nam, Taewoo
    Yeom, Keunhyuk
    2007 CIT: 7TH IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY, PROCEEDINGS, 2007, : 927 - 933
  • [6] Variability issues in software product lines
    Bosch, J
    Florijn, G
    Greefhorst, D
    Kuusela, J
    Obbink, JH
    Pohl, K
    SOFTWARE PRODUCT-FAMILY ENGINEERING, 2002, 2290 : 13 - 21
  • [7] Optimization of variability in software product lines
    Loesch, Felix
    Ploedereder, Erhard
    SPLC 2007: 11TH INTERNATIONAL SOFTWARE PRODUCT LINE CONFERENCE, PROCEEDINGS, 2007, : 151 - +
  • [8] On the notion of variability in software product lines
    van Gurp, J
    Bosch, J
    Svahnberg, M
    WORKING IEEE/IFIP CONFERENCE ON SOFTWARE ARCHITECTURE, PROCEEDINGS, 2001, : 45 - 54
  • [9] A Framework for Managing Requirements of Software Product Lines
    Arias, Maximiliano
    Buccella, Agustina
    Cechich, Alejandra
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2018, 339 : 5 - 20
  • [10] Extracting core requirements for software product lines
    Iris Reinhartz-Berger
    Mark Kemelman
    Requirements Engineering, 2020, 25 : 47 - 65