From missile warhead to smart fridge: Interviews with industry experts on tracing safety- and security-relevant artifacts

Publikation: Beitrag in FachzeitschriftArtikelForschungPeer-Review

Autorschaft

Organisationseinheiten

Externe Organisationen

  • TÜV Informationstechnik GmbH
  • Universität Koblenz (UK)
  • Fraunhofer-Institut für Software- und Systemtechnik (ISST), Institutsteil Dortmund
Forschungs-netzwerk anzeigen

Details

OriginalspracheEnglisch
Aufsatznummer112551
FachzeitschriftJournal of Systems and Software
Jahrgang230
Frühes Online-Datum22 Juli 2025
PublikationsstatusVeröffentlicht - Dez. 2025

Abstract

Ensuring traceability of safety- and security-related artifacts is vital in software development to comply with standards and mitigate risks. Despite its importance, the practical implementation of defining and tracing safety- and security-relevant artifacts remains ambiguous. Based on eight semi-structured interviews with industry experts, this work explores the definitions, methods, processes, and challenges of tracing safety- and security-related artifacts. The interviews revealed that definitions of safety- and security-relevant artifacts are highly context-dependent, shaped by regulatory standards, internal processes, technical characteristics, and practitioner judgment. Rather than signaling a deficiency, this variability reflects the inherently multifaceted nature of safety and security work, where artifact classification emerges from practical reasoning rather than strict or universal criteria. Tools play a key role in supporting traceability, and cross-team alignment remains a concern in practice. Our findings provide actionable insights for organizations seeking to strengthen traceability. The recommendations encourage the development of internal classification criteria, support effective collaboration with external partners, support guidance, onboarding, and training, and help align practices across teams, fostering more reliable and transparent management of safety- and security-relevant artifacts.

ASJC Scopus Sachgebiete

Zitieren

From missile warhead to smart fridge: Interviews with industry experts on tracing safety- and security-relevant artifacts. / Herrmann, Marc; Specht, Alexander; Sekerci, Abdurrahman et al.
in: Journal of Systems and Software, Jahrgang 230, 112551, 12.2025.

Publikation: Beitrag in FachzeitschriftArtikelForschungPeer-Review

Herrmann M, Specht A, Sekerci A, Obaidi M, Ehl M, Elsofi DAA et al. From missile warhead to smart fridge: Interviews with industry experts on tracing safety- and security-relevant artifacts. Journal of Systems and Software. 2025 Dez;230:112551. Epub 2025 Jul 22. doi: 10.1016/j.jss.2025.112551
Download
@article{678e6f6e3941457f9240abf22ae6b0c9,
title = "From missile warhead to smart fridge: Interviews with industry experts on tracing safety- and security-relevant artifacts",
abstract = "Ensuring traceability of safety- and security-related artifacts is vital in software development to comply with standards and mitigate risks. Despite its importance, the practical implementation of defining and tracing safety- and security-relevant artifacts remains ambiguous. Based on eight semi-structured interviews with industry experts, this work explores the definitions, methods, processes, and challenges of tracing safety- and security-related artifacts. The interviews revealed that definitions of safety- and security-relevant artifacts are highly context-dependent, shaped by regulatory standards, internal processes, technical characteristics, and practitioner judgment. Rather than signaling a deficiency, this variability reflects the inherently multifaceted nature of safety and security work, where artifact classification emerges from practical reasoning rather than strict or universal criteria. Tools play a key role in supporting traceability, and cross-team alignment remains a concern in practice. Our findings provide actionable insights for organizations seeking to strengthen traceability. The recommendations encourage the development of internal classification criteria, support effective collaboration with external partners, support guidance, onboarding, and training, and help align practices across teams, fostering more reliable and transparent management of safety- and security-relevant artifacts.",
keywords = "Artifacts, Expert, Industry, Interview, Practice, Requirements engineering, Safety, Secure software engineering, Security, Traceability, Tracing",
author = "Marc Herrmann and Alexander Specht and Abdurrahman Sekerci and Martin Obaidi and Marco Ehl and Elsofi, {Duaa Adel Ali} and Katharina Gro{\ss}er and Jil Kl{\"u}nder and Jan J{\"u}rjens and Kurt Schneider",
note = "Publisher Copyright: {\textcopyright} 2025 The Authors",
year = "2025",
month = dec,
doi = "10.1016/j.jss.2025.112551",
language = "English",
volume = "230",
journal = "Journal of Systems and Software",
issn = "0164-1212",
publisher = "Elsevier Inc.",

}

Download

TY - JOUR

T1 - From missile warhead to smart fridge

T2 - Interviews with industry experts on tracing safety- and security-relevant artifacts

AU - Herrmann, Marc

AU - Specht, Alexander

AU - Sekerci, Abdurrahman

AU - Obaidi, Martin

AU - Ehl, Marco

AU - Elsofi, Duaa Adel Ali

AU - Großer, Katharina

AU - Klünder, Jil

AU - Jürjens, Jan

AU - Schneider, Kurt

N1 - Publisher Copyright: © 2025 The Authors

PY - 2025/12

Y1 - 2025/12

N2 - Ensuring traceability of safety- and security-related artifacts is vital in software development to comply with standards and mitigate risks. Despite its importance, the practical implementation of defining and tracing safety- and security-relevant artifacts remains ambiguous. Based on eight semi-structured interviews with industry experts, this work explores the definitions, methods, processes, and challenges of tracing safety- and security-related artifacts. The interviews revealed that definitions of safety- and security-relevant artifacts are highly context-dependent, shaped by regulatory standards, internal processes, technical characteristics, and practitioner judgment. Rather than signaling a deficiency, this variability reflects the inherently multifaceted nature of safety and security work, where artifact classification emerges from practical reasoning rather than strict or universal criteria. Tools play a key role in supporting traceability, and cross-team alignment remains a concern in practice. Our findings provide actionable insights for organizations seeking to strengthen traceability. The recommendations encourage the development of internal classification criteria, support effective collaboration with external partners, support guidance, onboarding, and training, and help align practices across teams, fostering more reliable and transparent management of safety- and security-relevant artifacts.

AB - Ensuring traceability of safety- and security-related artifacts is vital in software development to comply with standards and mitigate risks. Despite its importance, the practical implementation of defining and tracing safety- and security-relevant artifacts remains ambiguous. Based on eight semi-structured interviews with industry experts, this work explores the definitions, methods, processes, and challenges of tracing safety- and security-related artifacts. The interviews revealed that definitions of safety- and security-relevant artifacts are highly context-dependent, shaped by regulatory standards, internal processes, technical characteristics, and practitioner judgment. Rather than signaling a deficiency, this variability reflects the inherently multifaceted nature of safety and security work, where artifact classification emerges from practical reasoning rather than strict or universal criteria. Tools play a key role in supporting traceability, and cross-team alignment remains a concern in practice. Our findings provide actionable insights for organizations seeking to strengthen traceability. The recommendations encourage the development of internal classification criteria, support effective collaboration with external partners, support guidance, onboarding, and training, and help align practices across teams, fostering more reliable and transparent management of safety- and security-relevant artifacts.

KW - Artifacts

KW - Expert

KW - Industry

KW - Interview

KW - Practice

KW - Requirements engineering

KW - Safety

KW - Secure software engineering

KW - Security

KW - Traceability

KW - Tracing

UR - http://www.scopus.com/inward/record.url?scp=105011387117&partnerID=8YFLogxK

U2 - 10.1016/j.jss.2025.112551

DO - 10.1016/j.jss.2025.112551

M3 - Article

AN - SCOPUS:105011387117

VL - 230

JO - Journal of Systems and Software

JF - Journal of Systems and Software

SN - 0164-1212

M1 - 112551

ER -

Von denselben Autoren