Glossary
Technical terms from functional safety, cybersecurity, requirements traceability, model-based engineering and software development — explained precisely by the itemis experts.
A
AI Agent
An AI agent is a software system that, based on an LLM, autonomously plans and executes multi-step tasks: it uses tools such as file …
ALM
ALM (Application Lifecycle Management) refers to the coordinated management of the entire software lifecycle — from requirements through …
ASIL
ASIL (Automotive Safety Integrity Level) is the risk classification of ISO 26262 for safety-related E/E systems in vehicles. The four levels …
Attack Tree
An attack tree decomposes an attacker’s goal hierarchically into sub-goals and concrete attack steps. In the TARA according to ISO/SAE …
Automotive SPICE
Automotive SPICE (ASPICE) is the automotive industry’s process assessment model for evaluating the maturity of development processes for …
AUTOSAR
AUTOSAR (AUTomotive Open System ARchitecture) is a worldwide development partnership of vehicle manufacturers, suppliers and tool vendors …
B
Best of Breed
Best of breed refers to the tool strategy of using the best specialized tool for each engineering task instead of relying on the all-in-one …
BPMN
BPMN (Business Process Model and Notation) is the graphical notation standard for modeling business processes standardized by the OMG. BPMN …
C
Cloud Migration
Cloud migration refers to moving applications, data and infrastructure from your own data center to a cloud environment. The spectrum ranges …
CSMS
A CSMS (Cyber Security Management System) bundles the processes, roles and responsibilities with which a vehicle manufacturer identifies, …
CVD
CVD (Coordinated Vulnerability Disclosure) is the coordinated process through which security researchers and other reporters report …
CRA
The Cyber Resilience Act (CRA) is the EU regulation with binding cybersecurity minimum requirements for products with digital elements. From …
D
F
FMEA
FMEA (Failure Mode and Effects Analysis) is a systematic, inductive analysis method: it identifies possible failure modes of a system, …
Functional Safety
Functional safety is the part of a system's safety that depends on the correct functioning of safety-related E/E systems. The goal is the …
H
I
IEC 61508
IEC 61508 is the cross-industry basic standard for the functional safety of electrical, electronic and programmable electronic (E/E/PE) …
IEC 62443
IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems (OT). Its core …
Impact Analysis
Impact analysis uses trace links to determine which artifacts — requirements, architecture, code, tests, evidence — are affected by a …
ISO 26262
ISO 26262 is the international standard for the functional safety of electrical and electronic (E/E) systems in road vehicles. It is derived …
ISO/SAE 21434
ISO/SAE 21434 is the central cybersecurity standard of the automotive industry. It describes an end-to-end cybersecurity engineering process …
L
Language Workbench
A language workbench is a development environment for building custom, usually domain-specific languages (DSLs). It provides everything that …
Legacy Modernization
Legacy modernization refers to transferring historically grown legacy systems — such as COBOL or mainframe applications — to modern …
Living TARA
A Living TARA (also Dynamic TARA) is a threat analysis and risk assessment that is kept up to date across the entire product lifecycle. New …
LLM
An LLM (Large Language Model) is a neural network trained on very large amounts of text that models language statistically and thereby …
M
MBSE
MBSE (Model-Based Systems Engineering) is a systems engineering approach in which a formal, machine-readable system model — not documents — …
MCP
MCP (Model Context Protocol) is an open standard that connects AI applications such as LLMs and AI agents with external data sources and …
MDSD
MDSD (Model-Driven Software Development) is a development approach in which formal models are the primary artifacts of software development. …
Metamodel
A metamodel is the model of a model: it defines which elements, relationships and rules are allowed in a model. Metamodels play the same …
Microservices
Microservices are an architectural style in which an application consists of many small, business-aligned services that are developed, …
N
P
R
RAG
RAG (Retrieval-Augmented Generation) is an architectural pattern that supplies an LLM with content from external knowledge sources at answer …
ReqIF
ReqIF (Requirements Interchange Format) is an XML-based OMG standard for exchanging requirements — including attributes, structure and links …
Requirements Coverage
Requirements coverage denotes the degree to which requirements are covered by other development artifacts — typically test cases. Process …
Requirements Engineering
Requirements engineering is the systematic discipline of eliciting, documenting, validating and managing requirements for a system over its …
Requirements Traceability
Requirements traceability is the ability to trace each requirement from its origin through architecture, implementation and testing to …
S
Safety Case
A safety case is the structured argument that a system is acceptably safe in its context of use — supported by traceable evidence from the …
SBOM
An SBOM (Software Bill of Materials) is the machine-readable inventory of all software components of a product, including open-source …
Security by Design
Security by design is the principle of engineering security into a product from the very first concept phase, instead of retrofitting it …
SIL
SIL (Safety Integrity Level) is the risk classification of IEC 61508 for safety-related E/E/PE systems. The four levels SIL 1 to SIL 4 …
SOTIF
SOTIF (Safety of the Intended Functionality, ISO 21448) addresses hazards without malfunction: the system works exactly as specified, but …
SysML
SysML (Systems Modeling Language) is the graphical modelling language for systems engineering standardised by the OMG. It describes …
Systems Engineering
Systems engineering is the interdisciplinary approach to developing complex technical systems across the entire lifecycle — from stakeholder …
T
TARA
TARA (Threat Analysis and Risk Assessment) is the threat analysis and risk assessment method of ISO/SAE 21434. It systematically determines …
Threat Modeling
Threat modeling is the systematic analysis of a system from an attacker's perspective: which assets are worth protecting, by which paths …
TIM
A Traceability Information Model (TIM) defines which artifact types of a development process must be connected by which relationship types — …
Tool Qualification
Tool qualification is the evidence according to ISO 26262-8 that a software tool is sufficiently trustworthy for use in safety-related …
Toolchain Integration
Toolchain integration connects the tools of an engineering organization — requirements management, modeling, development, testing — into an …
Traceability Matrix
A traceability matrix (RTM) is a table that maps relationships between development artifacts such as requirements and test cases via unique …
U
UML
UML (Unified Modeling Language) is the graphical modelling language standardised by the OMG for specifying, visualising and documenting …
UML Profile
A UML profile is the standardized extension mechanism of UML: through stereotypes, tagged values and constraints, generic model elements are …
UNECE R155
UNECE R155 is UN Regulation No. 155 on the cybersecurity of road vehicles. It makes an audited Cyber Security Management System (CSMS) a …


