Security requirements variability for software product lines

被引:2
|
作者
Mellado, Daniel [1 ]
Fernandez-Medina, Eduardo [2 ]
Piattini, Mario [2 ]
机构
[1] Ministry Work & Social Affairs, Social Secur IT Dept, Madrid, Spain
[2] Univ Castilla La Mancha, Informat Syst Technol Dept, Alarcos Res Grp, E-13071 Ciudad Real, Spain
关键词
D O I
10.1109/ARES.2008.165
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software product line engineering has proven to be one of the most successful paradigms for developing a diversity of similar software applications and software-intensive systems at low costs, in short time, and with high quality, by exploiting commonalities and variabilities among products to achieve high levels of reuse. At the same time, due to the complexity and extensive nature of product line development, security and requirements engineering are critical success factors in the development of a software product line. However, most of the current product line practices in requirements engineering do not adequately address the security requirements engineering. Therefore, in this paper we will propose a security requirements decision model driven by security standards along with a security variability model to manage the variability of the security requirements related artefacts. The aim of this approach is to deal with security requirements from the early stages of the product line development in a systematic way, in order to facilitate the conformance to the most relevant security standards with regard to the management of security requirements, such as ISO/IEC 27001 and ISO/IEC 15408.
引用
收藏
页码:1413 / +
页数:3
相关论文
共 50 条
  • [31] Towards Modeling Data Variability in Software Product Lines
    Zaid, Lamia Abo
    De Troyer, Olga
    ENTERPRISE, BUSINESS-PROCESS AND INFORMATION SYSTEMS MODELING, 2011, 81 : 453 - 467
  • [32] Software product lines and variability modeling: A tertiary study
    Raatikainen, Mikko
    Tiihonen, Juha
    Mannisto, Tomi
    JOURNAL OF SYSTEMS AND SOFTWARE, 2019, 149 : 485 - 510
  • [33] Variability Hiding in Contracts for Dependent Software Product Lines
    Thuem, Thomas
    Winkelmann, Tim
    Schroeter, Reimar
    Hentschel, Martin
    Kruger, Stefan
    TENTH INTERNATIONAL WORKSHOP ON VARIABILITY MODELLING OF SOFTWARE-INTENSIVE SYSTEMS (VAMOS 2016), 2016, : 97 - 104
  • [34] Handling Database Schema Variability in Software Product Lines
    Khedri, Niloofar
    Khosravi, Ramtin
    2013 20TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2013), VOL 1, 2013, : 331 - 338
  • [35] A Variability Fault Localization Approach for Software Product Lines
    Trang Thu Nguyen
    Kien-Tuan Ngo
    Son Nguyen
    Hieu Dinh Vo
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (10) : 4100 - 4118
  • [36] Promoting Modularity in a Requirements Engineering Process for Software Product Lines
    Netto, Dorgival
    Silva, Carla
    NEW ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, 2016, 444 : 599 - 608
  • [37] Requirements engineering for software product lines: A systematic literature review
    Alves, Vander
    Niu, Nan
    Alves, Carina
    Valenca, George
    INFORMATION AND SOFTWARE TECHNOLOGY, 2010, 52 (08) : 806 - 820
  • [38] Secure Tropos framework for software product lines requirements engineering
    Mellado, Daniel
    Mouratidis, Haralambos
    Fernandez-Medina, Eduardo
    COMPUTER STANDARDS & INTERFACES, 2014, 36 (04) : 711 - 722
  • [39] An Integrated Requirements Engineering Framework for Agile Software Product Lines
    Haidar, Hassan
    Kolp, Manuel
    Wautelet, Yves
    SOFTWARE TECHNOLOGIES, ICSOFT 2018, 2019, 1077 : 124 - 149
  • [40] Aspect-oriented requirements engineering for software product lines
    Kuloor, C
    Eberlein, A
    ECBS 2003: 10TH IEEE INTERNATIONAL CONFERENCE AND WORKSHOP ON THE ENGINEERING OF COMPUTER-BASED SYSTEMS, PROCEEDINGS, 2003, : 98 - 107