From 13571a41cce6901b35e1062989e1fb0be989c1bf Mon Sep 17 00:00:00 2001 From: PandaeDo Date: Mon, 28 Sep 2026 14:05:06 +0200 Subject: [PATCH] add security process checks --- .../guidance/architecture_process_reqs.rst | 17 ++++++++++++++++- .../guidance/requirements_process_reqs.rst | 14 ++++++++++++++ 2 files changed, 30 insertions(+), 1 deletion(-) diff --git a/process/process_areas/architecture_design/guidance/architecture_process_reqs.rst b/process/process_areas/architecture_design/guidance/architecture_process_reqs.rst index 8c1dc7351f..1357efcf69 100644 --- a/process/process_areas/architecture_design/guidance/architecture_process_reqs.rst +++ b/process/process_areas/architecture_design/guidance/architecture_process_reqs.rst @@ -290,6 +290,22 @@ Checks for Architectural Design It shall be checked that security relevant architectural elements (Security==YES) can only be linked against security relevant architectural elements. +.. gd_req:: Check of Architecture linkage security requirement + :id: gd_req__arch_linkage_requirement_security + :status: valid + :version: 1 + :tags: prio_2_automation, attribute, check + :satisfies: wf__cr_mt_featarch[version==1], wf__cr_mt_comparch[version==1] + + It shall be checked that a security relevant requirement or AoU (Security == YES) is only + satisfied by security relevant architectural elements (Security == YES), in both link directions: + + * requirement -> satisfied_by -> feature / component + * architectural view, interface or component -> fulfils -> requirement / AoU + + Note: The reverse is allowed. A security relevant architectural element may also fulfil + requirements which are not security relevant. + .. gd_req:: Check of Architecture linkage requirement :id: gd_req__arch_linkage_requirement :status: valid @@ -341,7 +357,6 @@ Checks for Architectural Design It shall be checked if all SW components which are mentioned in the dynamic architecture views are defined in the static architecture. - Process Monitoring and Improvement ---------------------------------- diff --git a/process/process_areas/requirements_engineering/guidance/requirements_process_reqs.rst b/process/process_areas/requirements_engineering/guidance/requirements_process_reqs.rst index 48f6334910..686b01815e 100644 --- a/process/process_areas/requirements_engineering/guidance/requirements_process_reqs.rst +++ b/process/process_areas/requirements_engineering/guidance/requirements_process_reqs.rst @@ -437,6 +437,20 @@ Process Requirements Checks Note: This ensures that safety requirements are properly derived into their children. Also a mix of safe and QM aspects in a parent is avoided by this. +.. gd_req:: Requirements linkage security + :id: gd_req__req_linkage_security + :status: valid + :version: 1 + :tags: prio_2_automation, check + :satisfies: wf__req_stkh_req[version==1], wf__req_feat_req[version==1], wf__req_comp_req[version==1] + + It shall be checked that every security relevant requirement (Security == YES) which has child + requirements has at least one security relevant child requirement (Security == YES). + + Note: Unlike :need:`gd_req__req_linkage_safety`, a child which is not security relevant may be + derived from a security relevant parent, because a parent is commonly refined into security and + non-security aspects. What the check prevents is the security aspect being lost in the refinement. + .. gd_req:: Requirements validity :id: gd_req__req_validity :status: valid