• DocumentCode
    1567083
  • Title

    Security Requirements Variability for Software Product Lines

  • Author

    Mellado, Daniel ; Fernández-Medina, Eduardo ; Piattini, Mario

  • Author_Institution
    Social Security IT Dept., Minist. of Work & Social Affairs, Madrid
  • fYear
    2008
  • Firstpage
    1413
  • Lastpage
    1420
  • Abstract
    Software product line engineering has proven to be one of the most successful paradigms for developing a diversity of similar software applications and software-intensive systems at low costs, in short time, and with high quality, by exploiting commonalities and variabilities among products to achieve high levels of reuse. At the same time, due to the complexity and extensive nature of product line development, security and requirements engineering are critical success factors in the development of a software product line. However, most of the current product line practices in requirements engineering do not adequately address the security requirements engineering. Therefore, in this paper we will propose a security requirements decision model driven by security standards along with a security variability model to manage the variability of the security requirements related artefacts. The aim of this approach is to deal with security requirements from the early stages of the product line development in a systematic way, in order to facilitate the conformance to the most relevant security standards with regard to the management of security requirements, such as ISO/IEC 27001 and ISO/IEC 15408.
  • Keywords
    formal specification; security of data; software metrics; software quality; software reusability; ISO/IEC 15408; ISO/IEC 27001; security requirements decision model; security requirements engineering; security requirements variability model; security standard; software complexity; software product line engineering; software quality; Costs; Engineering management; IEC standards; ISO standards; Information security; Information systems; Proposals; Software maintenance; Software quality; Standards development; Common Criteria; ISO/IEC 27001; product lines; security requirements; variability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    978-0-7695-3102-1
  • Type

    conf

  • DOI
    10.1109/ARES.2008.165
  • Filename
    4529510