• DocumentCode
    1922122
  • Title

    Automated Support for Security Requirements Engineering in Software Product Line Domain Engineering

  • Author

    Mellado, Daniel ; Rodriguez, Jose ; Fernandez-Medina, E. ; Piattini, Mario

  • Author_Institution
    IT & Syst. Dept., Nat. Competition Comm., Madrid
  • fYear
    2009
  • fDate
    16-19 March 2009
  • Firstpage
    224
  • Lastpage
    231
  • Abstract
    Security and requirements engineering are one of the most important factor of success in the development of a software product line due to the complexity and extensive nature of them, given that a weakness in security can cause problems throughout all the products of a product line. However, without a CARE (computer-aided requirements engineering) tool, the application of any security requirements engineering process or methodology is much more difficult because it has to be manually performed. Therefore, in this paper, we will present a prototype of SREPPLineTool, which provides automated support to facilitate the application of the security quality requirements engineering process for software product lines, SREPPLine. SREPPLineTool simplifies the management of security requirements in product lines by providing us with a guided, systematic and intuitive way to deal with them from the early phases of product lines development, simplifying the management and the visualization of the artefacts variability and traceability links and the integration of the security standards, as well as the management of the security reference model proposed by SREPPLine. Finally we shall illustrate the application of SREPPLineTool by describing a simple example as a preliminary validation of it.
  • Keywords
    formal specification; formal verification; security of data; systems analysis; CARE; SREPPLineTool; automated support; computer-aided requirements engineering; security quality requirements engineering process; security reference model; software product line domain engineering; Application software; Computer security; Design engineering; Engineering management; Information security; National security; Quality management; Reliability engineering; Software prototyping; Standards development; Common Criteria; Security requirements; product lines; security; security variability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2009. ARES '09. International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4244-3572-2
  • Electronic_ISBN
    978-0-7695-3564-7
  • Type

    conf

  • DOI
    10.1109/ARES.2009.23
  • Filename
    5066477