Authors:
Christian Biermann
1
;
2
;
Richard May
1
and
Thomas Leich
1
Affiliations:
1
Harz University of Applied Sciences, Wernigerode, Germany
;
2
Msg Systems ag, München, Germany
Keyword(s):
Product-Line Engineering, Security Engineering, Security, Business Processes, Framework.
Abstract:
Modern software systems are becoming increasingly configurable, often relying on Product-Line Engineering (PLE) to efficiently develop variant-rich systems while ensuring reusability. However, security considerations in existing PLE research are typically insufficient as security is often (partly) neglected or not integrated into the overall development process. To address this gap, we developed an additional layer of the PLE framework: security engineering — positioned between domain engineering and application engineering. Our results are based on a systematic review of 49 secure PLE frameworks and workflows, synthesizing their insights and our expertise in compliance with the ISO/IEC 27000 series. By following six processes and 12 activities, our iterative approach ensures that security is systematically embedded in the PLE process. We particularly highlight the importance of reusable security artifacts, secure business-process modeling, and standard compliance, aiming to facilita
te the transfer of theoretical solutions into secure business practice.
(More)