使用模型驱动工程管理安全证据:挑战、愿景和经验

R. Panesar-Walawege, M. Sabetzadeh, L. Briand
{"title":"使用模型驱动工程管理安全证据:挑战、愿景和经验","authors":"R. Panesar-Walawege, M. Sabetzadeh, L. Briand","doi":"10.1109/WoSoCER.2011.8","DOIUrl":null,"url":null,"abstract":"Certification is a major prerequisite for most safety-critical systems before they can be put into operation. During certification, system suppliers often have to present a coherent body of evidence demonstrating that the developed systems are safe for operation. Regardless of the certification approach taken (process-based or product-based), collection of proper evidence at the proper stage ofdevelopment is critical  for successful certification. Currently,system suppliers and certification bodies alike are facing various challenges in relation to safety evidence collection. Notably, they find it hard to interpret the evidence requirements imposed by the safety standards within the domain of application; little support exists for recording, querying, and reporting evidence in a structured manner; and there is a general absence of guidelines on how the collected evidence supports the safety objectives. This paper states our position on how safety evidence should be characterized and managed. Specifically, we propose the application of Model-Driven Engineering as an enabler for performing the various tasks related to safety evidence management. We outline our current work on the specification of safety evidence requirements, upfront planning of evidence collection activities, tailoring of evidence information to domain-specific needs, and storage of evidence information. Based on this work, we identify a number of challenges that need further investigation and provide a future research agenda for managing safety evidence for software safety certification.","PeriodicalId":318139,"journal":{"name":"2011 First International Workshop on Software Certification","volume":"282 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-11-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"18","resultStr":"{\"title\":\"Using Model-Driven Engineering for Managing Safety Evidence: Challenges, Vision and Experience\",\"authors\":\"R. Panesar-Walawege, M. Sabetzadeh, L. Briand\",\"doi\":\"10.1109/WoSoCER.2011.8\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Certification is a major prerequisite for most safety-critical systems before they can be put into operation. During certification, system suppliers often have to present a coherent body of evidence demonstrating that the developed systems are safe for operation. Regardless of the certification approach taken (process-based or product-based), collection of proper evidence at the proper stage ofdevelopment is critical  for successful certification. Currently,system suppliers and certification bodies alike are facing various challenges in relation to safety evidence collection. Notably, they find it hard to interpret the evidence requirements imposed by the safety standards within the domain of application; little support exists for recording, querying, and reporting evidence in a structured manner; and there is a general absence of guidelines on how the collected evidence supports the safety objectives. This paper states our position on how safety evidence should be characterized and managed. Specifically, we propose the application of Model-Driven Engineering as an enabler for performing the various tasks related to safety evidence management. We outline our current work on the specification of safety evidence requirements, upfront planning of evidence collection activities, tailoring of evidence information to domain-specific needs, and storage of evidence information. Based on this work, we identify a number of challenges that need further investigation and provide a future research agenda for managing safety evidence for software safety certification.\",\"PeriodicalId\":318139,\"journal\":{\"name\":\"2011 First International Workshop on Software Certification\",\"volume\":\"282 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2011-11-29\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"18\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2011 First International Workshop on Software Certification\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/WoSoCER.2011.8\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 First International Workshop on Software Certification","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WoSoCER.2011.8","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 18

摘要

认证是大多数安全关键系统在投入运行之前的主要先决条件。在认证期间,系统供应商通常必须提供连贯的证据,证明开发的系统可以安全运行。无论采用何种认证方法(基于过程还是基于产品),在适当的开发阶段收集适当的证据对于成功的认证至关重要。目前,系统供应商和认证机构都面临着与安全证据收集有关的各种挑战。值得注意的是,他们发现很难解释适用领域内安全标准所规定的证据要求;很少支持以结构化的方式记录、查询和报告证据;而且普遍缺乏关于如何收集证据来支持安全目标的指导方针。本文阐述了我们对安全证据应如何表征和管理的立场。具体来说,我们建议应用模型驱动工程作为执行与安全证据管理相关的各种任务的推动者。我们概述了我们目前在安全证据要求规范、证据收集活动的前期规划、根据特定领域需求定制证据信息以及证据信息存储方面的工作。基于这项工作,我们确定了一些需要进一步调查的挑战,并为管理软件安全认证的安全证据提供了未来的研究议程。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Using Model-Driven Engineering for Managing Safety Evidence: Challenges, Vision and Experience
Certification is a major prerequisite for most safety-critical systems before they can be put into operation. During certification, system suppliers often have to present a coherent body of evidence demonstrating that the developed systems are safe for operation. Regardless of the certification approach taken (process-based or product-based), collection of proper evidence at the proper stage ofdevelopment is critical  for successful certification. Currently,system suppliers and certification bodies alike are facing various challenges in relation to safety evidence collection. Notably, they find it hard to interpret the evidence requirements imposed by the safety standards within the domain of application; little support exists for recording, querying, and reporting evidence in a structured manner; and there is a general absence of guidelines on how the collected evidence supports the safety objectives. This paper states our position on how safety evidence should be characterized and managed. Specifically, we propose the application of Model-Driven Engineering as an enabler for performing the various tasks related to safety evidence management. We outline our current work on the specification of safety evidence requirements, upfront planning of evidence collection activities, tailoring of evidence information to domain-specific needs, and storage of evidence information. Based on this work, we identify a number of challenges that need further investigation and provide a future research agenda for managing safety evidence for software safety certification.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信