Security requirements variability for software product lines

被引:2
|
作者
Mellado, Daniel [1 ]
Fernandez-Medina, Eduardo [2 ]
Piattini, Mario [2 ]
机构
[1] Ministry Work & Social Affairs, Social Secur IT Dept, Madrid, Spain
[2] Univ Castilla La Mancha, Informat Syst Technol Dept, Alarcos Res Grp, E-13071 Ciudad Real, Spain
来源
ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY | 2008年
关键词
D O I
10.1109/ARES.2008.165
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software product line engineering has proven to be one of the most successful paradigms for developing a diversity of similar software applications and software-intensive systems at low costs, in short time, and with high quality, by exploiting commonalities and variabilities among products to achieve high levels of reuse. At the same time, due to the complexity and extensive nature of product line development, security and requirements engineering are critical success factors in the development of a software product line. However, most of the current product line practices in requirements engineering do not adequately address the security requirements engineering. Therefore, in this paper we will propose a security requirements decision model driven by security standards along with a security variability model to manage the variability of the security requirements related artefacts. The aim of this approach is to deal with security requirements from the early stages of the product line development in a systematic way, in order to facilitate the conformance to the most relevant security standards with regard to the management of security requirements, such as ISO/IEC 27001 and ISO/IEC 15408.
引用
收藏
页码:1413 / +
页数:3
相关论文
共 50 条
  • [21] Requirements Evolution in Software Product Lines: An Empirical Study
    de Oliveira, Raphael Pereira
    de Almeida, Eduardo Santana
    PROCEEDINGS 2015 NINTH BRAZILIAN SYMPOSIUM ON SOFTWARE COMPONENTS, ARCHITECTURES AND REUSE - SBCARS 2015, 2015, : 1 - 10
  • [22] RequiLine: A requirements engineering tool for software product lines
    von der Massen, T
    Lichter, H
    SOFTWARE PRODUCT-FAMILY ENGINEERING, 2004, 3014 : 168 - 180
  • [23] Managing variability for software product lines: Working with variability mechanisms
    Clements, Paul C.
    SPLC 2006: 10th International Software Product Line Conference, Proceedings, 2006, : 207 - 208
  • [24] A flexible requirements analysis approach for Software Product Lines
    Guelfi, Nicolas
    Perrouin, Gilles
    REQUIREMENTS ENGINEERING: FOUNDATION FOR SOFTWARE QUALITY, 2007, 4542 : 78 - +
  • [25] Capturing consumer preferences as requirements for software product lines
    Jelena Zdravkovic
    Eric-Oluf Svee
    Constantinos Giannoulis
    Requirements Engineering, 2015, 20 : 71 - 90
  • [26] An Experimental Study on Requirements Engineering for Software Product Lines
    Santana Neiva, Danuza Ferreira
    de Almeida, Eduardo Santana
    de Lemos Meira, Silvio Romero
    2009 35TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS, PROCEEDINGS, 2009, : 251 - +
  • [27] Consistency Checking Rules of Variability in Software product Lines
    Kim, Jeong Ah
    Kim, SeHoon
    2013 EIGHTH INTERNATIONAL CONFERENCE ON BROADBAND, WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS (BWCCA 2013), 2013, : 595 - 597
  • [28] Software product lines and variability modeling: A tertiary study
    Raatikainen, Mikko
    Tiihonen, Juha
    Mannisto, Tomi
    JOURNAL OF SYSTEMS AND SOFTWARE, 2019, 149 : 485 - 510
  • [29] Variability Driven Quality Evaluation in Software Product Lines
    Etxeberria, Leire
    Sagardui, Goiuria
    SPLC 2008: 12TH INTERNATIONAL SOFTWARE PRODUCT LINE CONFERENCE, PROCEEDINGS, 2008, : 243 - 252
  • [30] Towards Modeling Data Variability in Software Product Lines
    Zaid, Lamia Abo
    De Troyer, Olga
    ENTERPRISE, BUSINESS-PROCESS AND INFORMATION SYSTEMS MODELING, 2011, 81 : 453 - 467