首页> 外文期刊>Computer standards & interfaces >Towards security requirements management for software product lines: A security domain requirements engineering process
【24h】

Towards security requirements management for software product lines: A security domain requirements engineering process

机译:迈向软件产品线的安全需求管理:安全域需求工程流程

获取原文
获取原文并翻译 | 示例
           

摘要

Security and requirements engineering are one of the most important factors of success in the development of a software product line due to the complexity and extensive nature of them, given that a weakness in security can cause problems throughout the products of a product line. The main contribution of this work is that of providing a security standard-based process for software product line development, which is an add-in of activities in the domain engineering. This process deals with security requirements from the early stages of the product line lifecycle in a systematic and intuitive way especially adapted for product line based development. It is based on the use of the latest security requirements techniques, together with the integration of the Common Criteria (ISO/IEC 15408) and the ISO/IEC 17799 controls into the product line lifecycle. Additionally, it deals with security artefacts variability and traceability, providing us with a Security Core Assets Repository. Moreover, it facilitates the conformance to the most relevant security standards with regard to the management of security requirements, such as ISO/IEC 27001 and ISO/IEC 17799. Finally, we will illustrate our proposed process by describing part of a real case study, as a preliminary validation of it.
机译:由于安全性和需求工程的复杂性和广泛性,安全性和需求工程是软件产品线开发成功的最重要因素之一,因为安全性薄弱会在整个产品线产品中引起问题。这项工作的主要贡献是为软件产品线开发提供了一个基于安全标准的过程,这是领域工程活动的补充。此过程以系统且直观的方式处理了产品线生命周期早期阶段的安全性要求,特别适合基于产品线的开发。它基于对最新安全要求技术的使用以及将通用标准(ISO / IEC 15408)和ISO / IEC 17799控件集成到产品线生命周期中的基础。此外,它还处理安全制品的可变性和可追溯性,从而为我们提供了一个安全核心资产存储库。此外,它有助于在安全要求的管理方面遵循最相关的安全标准,例如ISO / IEC 27001和ISO / IEC17799。最后,我们将通过描述实际案例研究的一部分来说明我们提出的过程,作为对此的初步验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号