loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: Christian Biermann 1 ; 2 ; Richard May 1 and Thomas Leich 1

Affiliations: 1 Harz University of Applied Sciences, Wernigerode, Germany ; 2 Msg Systems ag, München, Germany

Keyword(s): Product-Line Engineering, Security Engineering, Security, Business Processes, Framework.

Abstract: Modern software systems are becoming increasingly configurable, often relying on Product-Line Engineering (PLE) to efficiently develop variant-rich systems while ensuring reusability. However, security considerations in existing PLE research are typically insufficient as security is often (partly) neglected or not integrated into the overall development process. To address this gap, we developed an additional layer of the PLE framework: security engineering — positioned between domain engineering and application engineering. Our results are based on a systematic review of 49 secure PLE frameworks and workflows, synthesizing their insights and our expertise in compliance with the ISO/IEC 27000 series. By following six processes and 12 activities, our iterative approach ensures that security is systematically embedded in the PLE process. We particularly highlight the importance of reusable security artifacts, secure business-process modeling, and standard compliance, aiming to facilita te the transfer of theoretical solutions into secure business practice. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 216.73.216.12

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Biermann, C., May, R., Leich and T. (2025). Integrating Security into the Product-Line-Engineering Framework: A Security-Engineering Extension. In Proceedings of the 20th International Conference on Software Technologies - ICSOFT; ISBN 978-989-758-757-3; ISSN 2184-2833, SciTePress, pages 75-86. DOI: 10.5220/0013489500003964

@conference{icsoft25,
author={Christian Biermann and Richard May and Thomas Leich},
title={Integrating Security into the Product-Line-Engineering Framework: A Security-Engineering Extension},
booktitle={Proceedings of the 20th International Conference on Software Technologies - ICSOFT},
year={2025},
pages={75-86},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0013489500003964},
isbn={978-989-758-757-3},
issn={2184-2833},
}

TY - CONF

JO - Proceedings of the 20th International Conference on Software Technologies - ICSOFT
TI - Integrating Security into the Product-Line-Engineering Framework: A Security-Engineering Extension
SN - 978-989-758-757-3
IS - 2184-2833
AU - Biermann, C.
AU - May, R.
AU - Leich, T.
PY - 2025
SP - 75
EP - 86
DO - 10.5220/0013489500003964
PB - SciTePress