• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. InstaQM: Bridging the Gap between Abstract Quality Models and Actionable Security Practices with Instances
 
  • Details
  • Full
Options
2026
Conference Paper
Title

InstaQM: Bridging the Gap between Abstract Quality Models and Actionable Security Practices with Instances

Abstract
Software engineers (SWEs) need specific and applicable guidance on designing and implementing security throughout the software lifecycle. Existing resources are often generic or lack applicable insights, leaving SWEs to scattered security information in project artifacts. We present InstaQM, a methodology for systematically creating security quality models enriched with textual instances. These models provide a structured representation of security-related concepts and their relations, enabling SWEs to better understand software project artifacts and apply security practices. Our methodology is systematically oriented on the needs of SWEs applying security practices such as STRIDE and LINDDUN, and is based on the standards ISO/IEC 25000 and NIST SP 800-53 so software engineers can use existing knowledge. We populated our quality model by systematically analyzing a large corpus of EU project deliverables. We demonstrate the usefulness of our method on illustrative scenarios in depth based on real project artifacts. To demonstrate usability of our methodology, we provide a tool prototype that uses our quality model to analyze real-world project artifacts.
Author(s)
Ehl, Marco
Universität Koblenz
Ahmadian, Amir Shayan
Universität Koblenz
Großer, Katharina
Universität Koblenz
Elsofi, Duaa Adel
Universität Koblenz
Herrmann, Marc
Gottfried Wilhelm Leibniz Universität Hannover
Specht, Alexander
Gottfried Wilhelm Leibniz Universität Hannover
Schneider, Kurt
Gottfried Wilhelm Leibniz Universität Hannover
Jürjens, Jan  
Fraunhofer-Institut für Software- und Systemtechnik ISST  
Mainwork
Applied Computing 2026. The 41st Annual ACM Symposium on Applied Computing  
Conference
Symposium on Applied Computing 2026  
Open Access
File(s)
Download (812.25 KB)
Rights
CC BY 4.0: Creative Commons Attribution
DOI
10.1145/3748522.3779711
10.24406/publica-9267
Additional link
Full text
Language
English
Fraunhofer-Institut für Software- und Systemtechnik ISST  
Keyword(s)
  • instance

  • privacy

  • quality model

  • security engineering

  • security practices

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024