1,721,018 research outputs found

    Requirement-Based Methodological Steps to Identify Ontologies for Reuse

    Get PDF
    Ontology reuse is one of the fundamental activities of ontology development methodologies. By striving to reuse existing ontologies, developers align the new product with established models, an essential prerequisite for seamless communication and integration among systems. Although ontology reuse has been increasingly endorsed over the past twenty years, there remains a significant lack of practical solutions to assist developers in semi-automatically assessing the suitability of a candidate ontology for reuse, based on a new set of requirements. This paper advocates for an explicit phase to be incorporated into existing ontology development methodologies, involving a principled identification of candidate ontologies for reuse based on requirement similarity. The paper identifies the methodological steps that this phase should entail, and demonstrates these steps through a practical case study. It therefore offers concrete support to ontology engineers by providing an objective method to identify suitable candidate ontologies for reuse, and overall contributes to the ontology design endevour

    Toward ontology-guided IFRS standard-setting

    No full text
    This paper addresses the critical gap in the International Financial Reporting Standards (IFRS), widely adopted across 168 jurisdictions, which lack a formal and explicit shared conceptualization, leading to inconsistencies and challenges in financial report comparability. Despite being based on the Conceptual Framework for Financial Reporting (CF), discrepancies such as those between the concepts of transferability and control persist across different frameworks and standards. We propose a novel solution through the grounding of these concepts in the Unified Foundational Ontology (UFO), which has shown to improve framework coherence significantly. Leveraging this approach, we have developed, refined, and herein present the CF Ontology. Using CF Ontology, we conduct an ontological analysis of the IFRS Revenue from Contracts with Customers and introduce preliminary ontology model for this standard in OntoUML

    Measuring security requirements for software security

    Get PDF
    For the last decade's software security has gained attention by industries, experts and all other communities. Secure software is about mitigating risks from assets to achieve business goals. Security is highly depending on the context where software is deployed. But measuring software security even within a specific context is still not mature. This is because properties and metrics for measuring security are not properly defined and methods are lacking to provide a complete picture for measuring software security. Here we identify security requirements through asset based risk management process to describe soft ware security goal. Then based on the Goal-Question-Metric approach the identified security requirements are evaluated for measuring software security

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Enhancing Security Requirements Engineering by Organisational Learning

    Get PDF
    More and more software projects today are security-related in one way or the other.Requirements engineers often fail to recognise indicators for security problems which is a major sourceof security problems in practice. Identifying security-relevant requirements is labour-intensive and errorprone.In order to facilitate the security requirements elicitation process, we present an approachsupporting organisational learning on security requirements by establishing company-wide experienceresources, and a socio-technical network to benefit from them. The approach is based on modelling theflow of requirements and related experiences. Based on those models, we enable people to exchangeexperiences about security-requirements while they write and discuss project requirements. At the sametime, the approach enables participating stakeholders to learn while they write requirements. This canincrease security awareness and facilitate learning on both individual and organisational levels. As a basisfor our approach, we introduce heuristic assistant tools which support reuse of existing security-relatedexperiences. In particular, they include Bayesian classifiers which issue a warning automatically whennew requirements seem to be security-relevant. Our results indicate that this is feasible, in particular ifthe classifier is trained with domain specific data and documents from previous projects. We show howthe ability to identify security-relevant requirements can be improved using this approach. We illustrateour approach by providing a step-by-step example of how we improved the security requirementsengineering process at the European Telecommunications Standards Institute (ETSI) and report onexperiences made in this application

    Softwareentwicklung Risikomanagement- Modellierung

    No full text
    Risk management is an effective tool to control risks in software projects and increases the likelihood of project success. Risk management needs to be integrated as early as possible in the project. This dissertation proposes a Goal-driven Software Development Risk Management Model (GSRM) and explicitly integrates it into requirements engineering phase. This integration provides an early warning of potential problems so that both preventive and corrective actions can be undertaken to avoid the causes of the negative consequences. Based on the empirical investigation, we have shown that goal-driven approach is suitable for risk management and GSRM is well integrated into requirements engineering.Software Risikomanagement stellt ein effektives Mittel zur Risikominimierung in der Software Entwicklung dar. Es muss durchgängig in den Entwicklungsprozess integriert werden. Diese Dissertation schlägt ein zielbasiertes Risikomanagement-Model vor und integriert dieses in die erste Phase des Entwicklungprozess, in das Requirements Engineering. Diese Integration trägt dazu bei, frühzeitig potentielle Probleme zu erkennen und diese in Form von korrigierenden Maßnahmen zu umgehen. Anhand mehrerer Fallstudien haben wir gezeigt, dass der vorgeschlagene zielorientierte Ansatz für Risikomanagement geeignet ist und sich gut in das Anforderungsmanagement integrieren lässt

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship

    Eliciting Security Requirements and Tracing them to Design: An Integration of Common Criteria, Heuristics, and UMLsec

    Get PDF
    Building secure systems is difficult for many reasons.This paper deals with two of the main challenges: (i)the lack of security expertise in development teams, and (ii)the inadequacy of existing methodologies to support developerswho are not security experts. The security standardISO 14508 (Common Criteria) together with secure designtechniques such as UMLsec can provide the security expertise,knowledge, and guidelines that are needed. However,security expertise and guidelines are not stated explicitly inthe Common Criteria. They are rather phrased in securitydomain terminology and difficult to understand for developers.This means that some general security and secure designexpertise are required to fully take advantage of the CommonCriteria and UMLsec. In addition, there is the problem of tracing security requirements and objectives into solutiondesign,which is needed for proof of requirements fulfilment.This paper describes a security requirements engineeringmethodology called SecReq. SecReq combines three techniques:the Common Criteria, the heuristic requirements editorHeRA,andUMLsec. SecReqmakes systematic use of thesecurity engineering knowledge contained in the CommonCriteria and UMLsec, as well as security-related heuristicsin the HeRA tool. The integrated SecReq method supportsearly detection of security-related issues (HeRA), their systematicrefinement guided by the Common Criteria, and theability to trace security requirements into UML design models.A feedback loop helps reusing experiencewithin SecReqand turns the approach into an iterative process for the securesystem life-cycle, also in the presence of system evolution

    Appropriate Similarity Measures for Author Cocitation Analysis

    Get PDF
    We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis
    corecore