# itemis AG — Vollständiger Seitenindex / Full Site Index > itemis entwickelt visionäre digitale Lösungen. Wir schaffen innovative und flexible Lösungen für jede Organisation, quer durch alle Branchen. ## Deutsch - [itemis – Software Engineering für Compliance, Model-Based Engineering und Enterprise IT](https://www.itemis.com/): itemis entwickelt Software und Werkzeuge für Compliance-Engineering (ISO 21434, CRA, ISO 26262), modellbasierte Entwicklung und maßgeschneiderte Enterprise-Anwendungen – für regulierte Branchen in Europa und den USA. - [Der itemis Blog](https://www.itemis.com/blog/): Hier teilen unsere Beraterinnen und Berater ihr Fachwissen — aus der Praxis, aus echten Projekten, zu den Themen, die sie täglich beschäftigen. - [Compliance Intelligence](https://www.itemis.com/blog/compliance-intelligence/) - [Cyber Resilience Act](https://www.itemis.com/blog/compliance-intelligence/cyber-resilience-act/): Der Cyber Resilience Act in der Praxis: Artikel zu Anforderungen, Fristen und Umsetzung der EU-Verordnung für sichere Produkte – von den Security-Experten der itemis. - [Der 7-Schritte-Leitfaden zum EU Cyber Resilience Act (CRA)](https://www.itemis.com/blog/compliance-intelligence/cyber-resilience-act/7-schritte-leitfaden-cra/): Ist Ihr Produkt ab Dezember 2027 noch legal in Europa verkäuflich? Dieser Leitfaden zeigt in 7 Schritten, wie Hersteller die CRA-Compliance strukturiert angehen und den EU-Marktzugang sichern. - [CRA-Meldepflicht: Anatomie einer Meldung, von Stunde 0 bis zum Abschlussbericht](https://www.itemis.com/blog/compliance-intelligence/cyber-resilience-act/cra-artikel-14-meldeprozess/): Ab dem 11. September 2026 greift die Meldepflicht nach CRA Artikel 14. Dieser Artikel geht den gesamten Prozess chronologisch durch – von der ersten Einschätzung bis zum Abschlussbericht – und benennt die Stellen, an denen Meldeprozesse in der Praxis reißen. - [CRA-Risikoanalyse mit Excel: Anfangen, importieren, skalieren](https://www.itemis.com/blog/compliance-intelligence/cyber-resilience-act/cra-risikoanalyse-excel-einstieg/): Excel-Vorlage für die CRA-Risikoanalyse: TARA nach ISO 21434 und IEC 62443 — wie man methodisch startet, was sich importieren lässt und wann Excel zum Engpass wird. - [Living TARA: Warum der Cyber Resilience Act Ihren Engineering-Prozess verändert, nicht Ihre Dokumentation](https://www.itemis.com/blog/compliance-intelligence/cyber-resilience-act/living-tara-cra-engineering-prozess/): Der CRA verlangt keine einmalige Risikoanalyse, sondern einen dauerhaft nachweisbaren Security-Engineering-Prozess. Wie eine Living TARA und der Security Digital Thread Ihr Risikobild kontinuierlich aktuell und auditfähig halten. - [Cyber Security](https://www.itemis.com/blog/compliance-intelligence/cyber-security/): Cyber Security im Engineering: Artikel zu Bedrohungsanalysen (TARA), Security by Design und ISO/SAE 21434 aus der Praxis der itemis Security-Experten. - [Asset Identification und Impact Rating: Wessen Schaden zählt eigentlich?](https://www.itemis.com/blog/compliance-intelligence/cyber-security/assets-impact-tara/): Asset Identification und Impact Rating liefern die eine Hälfte des Risikowerts: ab wann ein Element des Items ein Asset ist, wessen Schaden ein Schadensszenario beschreibt, warum die Safety-Bewertung nicht der Security allein gehört, und was Bewertungen über Projekte hinweg vergleichbar hält. - [Sicher ist sicher?! Automotive Security im Zeitalter vernetzter Fahrzeuge](https://www.itemis.com/blog/compliance-intelligence/cyber-security/automotive-security-vernetzte-fahrzeuge/): Der gesteigerte Anteil von Softwarelösungen stellt hohe Forderungen an die Automotive Security. Doch welche Änderungen kommen auf Industrie und Hersteller zu? - [Item Definition: Warum der erste TARA-Schritt über alle weiteren entscheidet](https://www.itemis.com/blog/compliance-intelligence/cyber-security/item-definition-tara/): Die Item Definition legt das Qualitätsniveau der gesamten TARA fest — welcher Abstraktionsgrad der richtige ist, warum das SBOM-Mapping eine Mindestauflösung erzwingt, und warum ein lebendiges Modell das Fundament für API- und MCP-Integrationen ist. - [Security by Design im Automotive-Entwicklungsprozess](https://www.itemis.com/blog/compliance-intelligence/cyber-security/security-by-design-automotive/): Im Automotive-Bereich wird Security immer wichtiger – insbesondere für die neuen Generationen vernetzter, (teil-)autonomer Fahrzeuge. Erfahren Sie, wie ein sicheres Systemdesign entsteht und welche zusätzlichen Security-Herausforderungen auftreten können. - [Warum Sicherheit eine der größten Engineering-Herausforderungen der Zukunft ist](https://www.itemis.com/blog/compliance-intelligence/cyber-security/sicherheit-engineering-herausforderung/): Angesichts von Spectre und Meltdown ist völlig klar, dass Sicherheit eine große Engineering-Herausforderung ist. Erfahren Sie mehr über Safety und Security in diesem Beitrag. - [Was ist eine TARA? Und warum eine Tabelle irgendwann nicht mehr reicht](https://www.itemis.com/blog/compliance-intelligence/cyber-security/was-ist-eine-tara/): Eine TARA ist kein Bedrohungskatalog, sondern ein Nachweis von Risikoentscheidungen — was dahintersteckt, wie der Ablauf aussieht und ab wann Excel an seine Grenzen stößt. - [Functional Safety](https://www.itemis.com/blog/compliance-intelligence/functional-safety/): Funktionale Sicherheit verständlich erklärt: Artikel zu ISO 26262, ASIL, Safety-Nachweisen und sicherer Softwareentwicklung in regulierten Branchen. - [Requirements Traceability](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/): Requirements Traceability in der Praxis: Artikel zu Nachverfolgbarkeit von Anforderungen, Traceability-Strategien und Tool-Unterstützung im Engineering. - [Link-Coverage 100 %, ASPICE-Assessment trotzdem gefährdet.](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/aspice-traceability-vs-consistency/): 100 % Link-Coverage heißt nicht ASPICE-konform. Wie Type Check, Consistency Check und Consistency Score semantische Inkonsistenzen LLM-gestützt aufdecken. - [Compliance war nie eine Frage des Dokuments](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/compliance-artefakte-ki/): KI kann heute TARAs, Traceability-Matrizen und Safety Cases erzeugen, die strukturell vollständig und terminologisch korrekt sind. Das wirft eine Frage auf: Was wird dabei eigentlich verifiziert? Das Problem ist nicht KI-generierte Dokumentation. Es sind Compliance-Prozesse, die auf Artefakte optimieren statt auf die Eigenschaften, die diese Artefakte abbilden sollen. - [Sitz, Bleib, Hol: KI für ASPICE trainieren](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/ki-fuer-aspice-trainieren/): Sechs Leitplanken für KI-Agenten in ASPICE-Assessments: Skripte statt Prompts, gesicherte Zwischenergebnisse, Batches, Ja/Nein-Fragen, Verbote, Kennzeichnen. - [Was ist Requirements Coverage und wie lässt sie sich analysieren?](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/requirements-coverage-analyse/): Requirements Coverage wird von Prozessstandards wie Automotive SPICE gefordert, ist aber kaum einheitlich definiert. Was der Begriff wirklich bedeutet und wie man ihn sinnvoll misst. - [5 + 1 Fragen, die eine Requirements Traceability Matrix beantwortet](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/requirements-traceability-matrix-fragen/): Eine Requirements Traceability Matrix ist mehr als ein Buchführungswerkzeug. Fünf zentrale Fragen, die sie im Projektalltag beantwortet — plus eine Bonusfrage. - [Requirements Traceability Matrix erstellen: Schritt für Schritt](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/requirements-traceability-matrix/): Eine Requirements Traceability Matrix (RTM) ist eine einfache Tabelle, die bidirektionale Nachverfolgbarkeit im Projekt sicherstellt. Was sie ist und wie man sie in vier Schritten aufbaut. - [Requirements Traceability in der Softwarewartung: Messbarer Nutzen](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/requirements-traceability-wartung/): Eine empirische Studie mit 71 Probanden zeigt: Requirements Traceability führt bei der Softwarewartung zu 24 % schnellerer Bearbeitung und 50 % mehr korrekten Lösungen. - [Was ist Traceability? Nutzen und Herausforderungen in der Softwareentwicklung](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/traceability-grundlagen/): Traceability ist mehr als ein Compliance-Pflichtpunkt. Was der Begriff in der Software- und Systementwicklung bedeutet, welche Erkenntnisse sie liefert und welche Herausforderungen damit verbunden sind. - [Custom Software Development](https://www.itemis.com/blog/custom-software/) - [Full-Stack & Cloud](https://www.itemis.com/blog/custom-software/full-stack/): Full-Stack-Entwicklung in der Praxis: Artikel zu modernen Web-Technologien, Softwarearchitektur und Individualsoftware von den Entwicklern der itemis. - [Was ist zu tun nach dem Camunda 7 CE End-of-Life?](https://www.itemis.com/blog/custom-software/full-stack/operaton-openbpm-camunda-7-end-of-life/): Camunda 7 CE erreicht sein End-of-Life. Operaton und die OpenBPM Platform bieten eine leistungsstarke, offene Alternative – mit minimalem Migrationsaufwand und maximaler Zukunftssicherheit. - [AI Enablement](https://www.itemis.com/blog/custom-software/ki-enablement/): KI-Enablement für Unternehmen: Artikel zu KI-gestützter Softwareentwicklung, AI-Agenten und dem produktiven Einsatz von Large Language Models. - [Horizontale Skills und vertikale Agenten](https://www.itemis.com/blog/custom-software/ki-enablement/horizontal-skills-vertikale-agenten/): Wie man den Großteil der Softwareentwicklung an KI-Agenten übergibt – und trotzdem ein Ergebnis bekommt, dem man vertrauen kann. Ein Praxisblick auf vertikale Agenten und horizontale Skills für Enterprise-Teams. - [AI-driven Development: Warum Technologie nur die halbe Miete ist – und wie Ziellosigkeit zum größten Scheitern führt](https://www.itemis.com/blog/custom-software/ki-enablement/ki-entwicklung-ziellosigkeit/): AI-driven Development scheitert selten am Code – es scheitert an der Ziellosigkeit. Warum Technologie nur die halbe Miete ist und was wirklich über den Projekterfolg entscheidet. - [Legacy-Modernisierung](https://www.itemis.com/blog/custom-software/legacy-modernisierung/): Legacy-Modernisierung ohne Risiko: Artikel zu Strategien, Migrationspfaden und Werkzeugen, um Altsysteme zukunftssicher zu machen. - [Kann die Modernisierung deines Legacy Systems automatisiert werden?](https://www.itemis.com/blog/custom-software/legacy-modernisierung/automatisierte-modernisierung/): Wann lohnt sich eine automatisierte Modernisierung von Legacy-Systemen? Eine Analyse der Chancen, Grenzen und passenden Transformationswerkzeuge. - [Legacy System – Fachlichkeit begraben im Sourcecode](https://www.itemis.com/blog/custom-software/legacy-modernisierung/legacy-system-fachlichkeit-im-sourcecode/): Fachlicher und technischer Code in Legacy-Systemen vermischen sich über die Jahre — mit schwerwiegenden Folgen. Was das bedeutet und wie du dem begegnest. - [Wie man Legacy-Eclipse-Anwendungen zu Web und Visual Studio Code migriert](https://www.itemis.com/blog/custom-software/legacy-modernisierung/migrate-legacy-eclipse-to-web-vscode/): Lessons learned aus der Migration von itemis CREATE – einem Eclipse-Projekt mit 280.000 Zeilen Code – zu Web und Visual Studio Code. - [Model-Based Engineering](https://www.itemis.com/blog/model-based-engineering/) - [Custom Tools & DSLs](https://www.itemis.com/blog/model-based-engineering/custom-tools/): Custom Tools für das Engineering: Artikel zu maßgeschneiderten Entwicklungswerkzeugen, domänenspezifischen Sprachen (DSLs) und Tool-Entwicklung. - [KI-Agenten treffen auf Projectional Editing: Portalon für MPS](https://www.itemis.com/blog/model-based-engineering/custom-tools/ai-agents-meet-mps-with-portalon/): Wie das Portalon-Plugin KI-Coding-Agenten wie Claude über MCP mit dem laufenden Modell eines JetBrains-MPS-Projekts verbindet – strukturell sichere Änderungen, Validierung und Language-Engineering-Skills, auf Ihrer aktuellen MPS-Version. - [Schnittstellen mit Verhaltensvertrag: Protocol State Machines in der Praxis](https://www.itemis.com/blog/model-based-engineering/custom-tools/contract-based-software-development-franca/): Warum das dynamische Verhalten in den Schnittstellenvertrag gehört: Protocol State Machines spezifizieren erlaubte Ereignis-Reihenfolgen formal – mit Franca IDL als Beispiel und einem Blick auf Dezyne, P und Session Types. - [Custom Tooling auf EA-Modellen: vom Modell zum generierten Code](https://www.itemis.com/blog/model-based-engineering/custom-tools/ea-bridge-custom-tooling-codegenerierung/): Wie die itemis EA Bridge Enterprise-Architect-Modelle als stabile, maschinenlesbare Daten bereitstellt, auf denen sich maßgeschneiderte Codegenerierung, Validierung und Dokumentation aufsetzen lassen. - [Variantenmanagement: mehr als Feature-Strings](https://www.itemis.com/blog/model-based-engineering/custom-tools/produktlinien-variantenmanagement-enge-kopplung/): Feature-Modelle lose mit Entwicklungsartefakten zu verknüpfen ist praktisch – birgt aber Risiken. Dieser Artikel zeigt, welche Vorteile eine enge Integration bietet: frühzeitige Fehlererkennung, implizite Variationspunkte und automatische Konsistenzprüfungen. - [Zustandsautomaten-Origami](https://www.itemis.com/blog/model-based-engineering/custom-tools/zustandsautomaten-origami/): Wie Franca IDL und itemis CREATE integriert werden können, um Embedded-Softwarekomponenten bereits während der Entwicklung interaktiv gegen Interface-Verträge zu validieren. - [Model-Driven Software Development](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/): Modellgetriebene Softwareentwicklung (MDSD): Artikel zu Codegenerierung, Zustandsautomaten, DSLs und Modellierungswerkzeugen aus über 20 Jahren Praxis. - [Formale Methoden zur Fehlererkennung: Was geht, was nicht](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/formale-methoden-fehlererkennung/): Eine unerreichbare Transition, ein Guard, der nie erfüllbar ist: Solche Fehler stecken im Modell, lange bevor ein Test sie zeigt. Ein Ergebnisbericht aus zwei Masterarbeiten über formale Fehlererkennung auf Zustandsautomaten mit Symbolic Execution und SMT-Solver. - [Model-Driven Software Development meets Test-Driven Development](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/mdd-meets-tdd/): Wie sich Test-Driven Development auf die modellgetriebene Softwareentwicklung anwenden lässt – am Beispiel von SCTUnit, dem Unit-Testing-Framework von itemis CREATE. - [Eine Einführung in die Modellierung und Language Engineering – Teil 1](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/modellierung-language-engineering-teil-1/): Was sind Modelle, Abstraktionen und Metamodelle? Mit LEGO® als Analogie erklärt dieser Artikel die Grundlagen der Modellierung und des Language Engineerings. - [Eine Einführung in die Modellierung und Language Engineering – Teil 2](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/modellierung-language-engineering-teil-2/): Teil 2 beleuchtet domänenspezifische Sprachen, Language Workbenches wie Xtext und MPS sowie die Rolle des Language Engineers in der Softwareentwicklung. - [MSP430 mit Zustandsautomaten programmieren in 5 Minuten](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/msp430-state-machines-itemis-create/): So programmierst du einen MSP430-Mikrocontroller mit Zustandsautomaten und itemis CREATE, vollständig integriert in Code Composer Studio – mit automatischer Code-Generierung und grafischem Editor. - [SCXML auf das nächste Level bringen](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/scxml-itemis-create/): Wie itemis CREATE Higher-Level-Modellierung, Simulation und Unit-Tests auf dem SCXML-Standard aufbaut. - [Traceability für itemis CREATE sicherstellen](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/traceability-fuer-itemis-create/): So stellst du Traceability für deine itemis-CREATE-Statechart-Modelle sicher – mit Werkzeugunterstützung, die über manuelle Trace-Links hinaus skaliert. - [Werkzeugvergleich: MathWorks Stateflow vs. IBM Rhapsody vs. itemis CREATE](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/werkzeugvergleich-zustandsautomaten-rhapsody-stateflow-itemis-create/): Ein ehrlicher, detaillierter Vergleich der drei führenden Statechart-Werkzeuge — MathWorks Stateflow, IBM Rhapsody und itemis CREATE — mit Funktionsvergleich, Preisen und Empfehlungen. - [Zustandsautomaten modellieren: Entry-, Exit- und Final-Zustände](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/zustandsautomaten-entry-exit-final/): Wie man Entry Points, Exit Points und Final States beim Modellieren von Zustandsautomaten mit itemis CREATE einsetzt. - [Modellieren mit Zustandsautomaten – Teil 1](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/zustandsautomaten-modellierung-teil-1/): Wie funktionieren Zustandsautomaten und warum sollte man sie einsetzen? Dieser Beitrag schildert die Modellierung eines endlichen Automaten am Beispiel einer Jalousiesteuerung. - [Modellieren mit Zustandsautomaten – Teil 2](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/zustandsautomaten-modellierung-teil-2/): Im zweiten Teil der Serie klären wir weitere Faktoren, die auf das Modellieren mit Zustandsautomaten Einfluss haben: zeitgesteuerte Transitionen, Orthogonalität und Subdiagramme. - [Modellieren mit Zustandsautomaten – Teil 5: Das State-Pattern](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/zustandsautomaten-state-pattern-teil-5/): Zustandsautomaten lassen sich nicht nur modellieren. Im fünften Teil stellen wir als Implementierungsvariante das State-Pattern vor. - [Modellieren mit Zustandsautomaten – Teil 3: Die große Switch-Anweisung](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/zustandsautomaten-switch-anweisung-teil-3/): Wie wird aus modellierten Zustandsautomaten eigentlich Programmcode? Zum Beispiel mit Hilfe einer Switch-Anweisung! Wir zeigen, wie die Implementierung funktioniert. - [Modellieren mit Zustandsautomaten – Teil 4: Darstellung als Tabelle](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/zustandsautomaten-tabelle-teil-4/): Zustandsautomaten lassen sich modellieren – aber wie lassen sie sich eigentlich realisieren? Zum Beispiel mit Hilfe von Zustandstabellen. - [Model-Based Systems Engineering](https://www.itemis.com/blog/model-based-engineering/systems-engineering/): Model-Based Systems Engineering (MBSE): Artikel zu SysML, Systemmodellierung und der Einführung von MBSE in der Produktentwicklung. - [Es ist kein MBSE, wenn du draw.io oder Visio verwendest](https://www.itemis.com/blog/model-based-engineering/systems-engineering/kein-mbse-mit-drawio-visio/): Kollaborative Modellierungsworkshops sind wertvoll — aber Bilder zeichnen ist kein MBSE. Wer aus seinen Modellen nicht validieren, ableiten oder generieren kann, verfehlt den Kern der Methode. - [Von SysML v1 zu SysML v2: Lohnt sich der Umstieg?](https://www.itemis.com/blog/model-based-engineering/systems-engineering/sysml-v1-zu-v2-lohnt-sich-der-umstieg/): SysML v2 verspricht klarere Konzepte, textuelle Notation und eine Standard-API. Aber rechnet sich der Umstieg? Vor- und Nachteile, eine ROI-Betrachtung entlang dreier Ausgangslagen und eine ehrliche Einschätzung, wer wechseln sollte und wer besser nicht. - [MathWorks System Composer vs. SysML-Tools: Was passt zu deinem Projekt?](https://www.itemis.com/blog/model-based-engineering/systems-engineering/system-composer-vs-sysml-tools/): System Composer oder ein SysML-Tool für die Architekturmodellierung? Ein Vergleich entlang Requirements-Handling, Simulation, Onboarding, Stakeholder-Views, KI-Integration und Kosten — und warum die Antwort vom Projekt abhängt. - [Toolchain Integration](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/): Toolchain Integration im Engineering: Artikel zur Anbindung von Enterprise Architect & Co., Datenaustausch und durchgängigen Werkzeugketten. - [Die richtige Werkzeugstrategie: Best-of-Breed oder All-in-One-Suite?](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/best-of-breed-oder-suite-engineering-werkzeuge/): Best-of-Breed oder All-in-One-Suite? Ein Blick auf die echten Abwägungen in der Engineering-Werkzeugstrategie — und warum die Eignung eines Werkzeugs immer Vorrang haben sollte. - [Enterprise Architect in der Toolchain: EA-Modelle automatisiert verarbeiten](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/ea-bridge-enterprise-architect-toolchain/): Wie die itemis EA Bridge den Enterprise Architect vom isolierten Modellierungswerkzeug zum Datenlieferanten macht: Validierung, Code-Generierung, Report-Generierung und KI-Reasoning, performant und plattformunabhängig. - [Eclipse-basierte Codegenerierung für Enterprise-Architect-Modelle](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/eclipse-based-code-generation-enterprise-architect/): Wie Eclipse mit Xtend und der Java-basierten EA-Bridge eine robuste Alternative zu EAs eigener Codegenerierung bietet — und wie das AUTOSAR-Konsortium diesen Ansatz headless im großen Maßstab einsetzt. - [Eclipse-basierte UML-Validierung von Enterprise-Architect-Modellen](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/eclipse-based-uml-validation-enterprise-architect/): Wie die Eclipse-basierte EA-Bridge Enterprise-Architect-Modelle als Eclipse-UML-Modelle lädt, syntaktische Fehler meldet und benutzerdefinierte Validierungsregeln mit Quick Fixes ermöglicht. - [Wie Modellierung Anforderungen klarer und präziser macht](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/modellierung-anforderungen-praeziser/): Der Wechsel von statischen Diagrammen zu ausführbaren Modellen im Requirements Engineering verbessert Präzision und Testbarkeit im Systementwurf. - [Enterprise Architect mit Add-ins anpassen](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/tailoring-enterprise-architect-with-add-ins/): Wie Enterprise Architect mit Add-ins erweitert wird: Model Assistants, Integrity Checks und Installer-basiertes Rollout — und welche Aufgaben besser externe Werkzeuge wie die EA-Bridge übernehmen. - [UML-Profile in Enterprise-Architect-Modellen – Beispiel Codegenerierung](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/uml-profiles-enterprise-architect-code-generation/): Wie UML-Profile in Enterprise Architect eingesetzt werden und wie profilierte Modelle mit der Eclipse-basierten EA-Bridge zur Codegenerierung mit Xtend genutzt werden können. - [Compliance Intelligence](https://www.itemis.com/compliance-intelligence/): Werkzeuge und Beratung für die zentralen Compliance-Standards moderner Produktentwicklung — Cybersecurity, Funktionale Sicherheit, Requirements Traceability. - [EU Cyber Resilience Act (CRA): Compliance-Roadmap bis 2027](https://www.itemis.com/compliance-intelligence/cyber-resilience-act/): CRA-Fristen 2026 und 2027, Betroffenheit, Roadmap und Umsetzung mit itemis SECURE und der CRAIG-Community. Der Selbstcheck für Hersteller von Produkten mit digitalen Elementen. - [CRA GAP-Analyse: Kostenloser Online-Check](https://www.itemis.com/compliance-intelligence/cyber-resilience-act/gap-analyse/): In 17 Fragen zum CRA-Reifegrad: Prüfen Sie Ihren Umsetzungsstand zum EU Cyber Resilience Act in 7 Bereichen – kostenlos, ohne Registrierung, mit Radar-Diagramm. - [CRA GAP-Checkliste: 75 Prüfpunkte als Excel-Vorlage](https://www.itemis.com/compliance-intelligence/cyber-resilience-act/gap-checkliste/): Kostenlose Excel-Vorlage für die vollständige CRA-GAP-Analyse: 75 Prüfpunkte in acht Bereichen, Reifegradbewertung nach dem ENISA-Modell, Auswertung und Maßnahmenplan — für Hersteller digitaler Produkte. - [TARA-Excel-Vorlage für die CRA-Risikoanalyse](https://www.itemis.com/compliance-intelligence/cyber-resilience-act/tara-excel-vorlage/): Kostenlose Excel-Vorlage für die Cybersecurity-Risikoanalyse nach Cyber Resilience Act: Assets, Damage Scenarios, Threat Catalog, Attack Steps und Controls — AFL, IL und RL werden automatisch berechnet. - [ISO/SAE 21434 & IEC 62443: Cybersecurity für Automotive und Industrie](https://www.itemis.com/compliance-intelligence/cyber-security/): Leitfaden zu ISO/SAE 21434 (TARA, UNECE R155) und IEC 62443 (Zonen, Conduits, Security Level). Umsetzung mit itemis SECURE, einem Tool für beide Standards. - [Webinare](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/): Webinare zu Cyber Security im Engineering: Live-Termine und Aufzeichnungen zu TARA, ISO/SAE 21434 und Security by Design – kostenlos von itemis. - [CSMS für Typgenehmigungen automatisieren: Modellbasierte TARAs und Knowledge Graphs](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/automating-csms-for-type-approvals/): Wie modellbasierte TARA-Tools und Knowledge Graphs die CSMS-Automatisierung für Typgenehmigungen ermöglichen. Das 20-50-90-Regel erklärt. - [Beyond 2024: Pionierarbeit im Risikomanagement für Fahrzeug-Cybersecurity](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/beyond-2024/): Aktuelle Herausforderungen im Risikomanagement für OEMs und Zulieferer, Best-of-Breed-Toolchains und der Nutzen von Traceability und Knowledge Graphs. - [SECURE & INCYDE – Cybersecurity für Elektrofahrzeuge](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/charging-up-cybersecurity/): Cybersecurity-Herausforderungen der Smart-Charging-Infrastruktur und TARAs für Elektrofahrzeuge. Erfahren Sie, wie das EV-Ökosystem sicher gestaltet wird. - [Cybersecurity und Risikomanagement: Best Practices für CFOs und Auditoren](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/cybersecurity-and-risk-management/): Best Practices für TARA-Management und Cybersecurity-Risikokontrolle für CFOs, Chief Compliance Officers und Auditoren vernetzter Produkte. - [Auf Schwachstellen reagieren: Bedrohungs- und Kontrollkataloge für ISO/SAE 21434](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/deep-dive-threat-catalogs-for-iso-21434/): Überblick über Bedrohungs- und Kontrollkataloge, die Ihre ISO/SAE 21434-konformen TARAs über den gesamten Lebenszyklus beschleunigen. - [ISO/SAE 21434: Was Motorrad- und ATV-Hersteller wissen müssen](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/iso-sae-21434-what-motorcycle-and-atv-companies-need-to-know/): UN Regulation No. 155 trifft Motorradhersteller ab 2029. Erfahren Sie, welche Herausforderungen und Compliance-Strategien entscheidend sind. - [ISO/SAE 21434 und UN R155: Lifecycle-Management-Herausforderungen](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/iso-sae-21434/): Die wichtigsten Aspekte und größten Herausforderungen von UN Regulation 155 und ISO/SAE 21434 beim Product Lifecycle Management. - [itemis SECURE KI-gestützte TARA: Von der Compliance zum Wettbewerbsvorteil](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/itemis-secure-ai-powered-tara/): Erfahren Sie, wie KI-gestützte TARA-Erstellung mit itemis SECURE Ihre Cybersecurity-Compliance beschleunigt. Jetzt Aufzeichnung ansehen. - [itemis SECURE Goes Cloud](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/itemis-secure-goes-cloud/): itemis SECURE ist jetzt auch als Web-Version verfügbar. Kollaborieren Sie an Cybersecurity-Projekten in Echtzeit. Jetzt Aufzeichnung ansehen. - [Vehicle Risk Management der nächsten Stufe: Automatisierter Vulnerability-to-TARA-Prozess](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/next-level-vehicle-risk-management/): Erfahren Sie, wie Dynamic-TARA die automatische Schwachstellenerkennung mit umfassender Bedrohungsanalyse verbindet. Jetzt Aufzeichnung ansehen. - [Die kommende TARA-Welle effizient managen](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/summer-2024-managing-the-coming-tara-wave/): Wie Sie den TARA-Prozess effizient gestalten und mit der 20-50-90-Regel die Cybersecurity-Ausgaben Ihres Unternehmens signifikant reduzieren. - [TARA-Automatisierung für die Automotive Cybersecurity](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/tara-automation/): Wie TARA-Automatisierung mit itemis SECURE (ehemals YAKINDU Security Analyst) die Automotive Cybersecurity effizienter gestaltet. - [TARA Deep Dive: Lifecycle-Management-Herausforderungen aus UN R155 und ISO/SAE 21434](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/tara-deep-dive/): Tiefgehende Analyse der TARA-Anforderungen aus UN R155 und ISO/SAE 21434 – wichtigste Aspekte und Herausforderungen für die gesamte Automobilindustrie. - [Integriertes Produkt-Security-Management für Software-Defined Vehicles](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/towards-an-integrated-product-security-management-for-software-defined-vehicles/): Wie Software-Defined Vehicles ein ganzheitliches Sicherheitsmanagement erfordern. Verkürzte Entwicklungszyklen und OTA-Updates sicher gestalten. - [Legacy-TARAs für ISO/SAE 21434 überführen](https://www.itemis.com/compliance-intelligence/cyber-security/webinar/transitioning-legacy-taras-for-iso-sae-21434/): Warum Sie Ihre TARAs von Spreadsheets in automatisierte Prozesse überführen sollten und wie Sie Ihre TARA-Landschaft mit OEM und Zulieferern harmonisieren. - [Whitepaper: Cyber Security](https://www.itemis.com/compliance-intelligence/cyber-security/whitepaper/): Kostenlose Whitepapers zu ISO/SAE 21434, IEC 62443 und Cybersecurity-Lifecycle-Management — für Automotive-OEMs, Tier-1-Zulieferer und Bahnhersteller. - [Cyber Risk Assessment für Einsteiger](https://www.itemis.com/compliance-intelligence/cyber-security/whitepaper/cyber-risk-assessment-fuer-einsteiger/): 7-teiliger Praxisleitfaden zur systematischen Cyber-Risikoanalyse: Risikodefinition, MoRA-Methodik, Schadens- und Bedrohungsszenarien, Risikomatrix und Living TARA. Kostenlos von Dirk Leopold, itemis. - [itemis SECURE Lifecycle Integrations](https://www.itemis.com/compliance-intelligence/cyber-security/whitepaper/cybersecurity-lifecycle-integration/): Wie itemis SECURE und itemis ANALYZE einen Living Digital Thread für Automotive-Cybersecurity aufbauen — die TARA vom statischen Compliance-Dokument zum dynamischen Steuerungsinstrument. Kostenloses Whitepaper. - [The Future Challenges of ISO SAE 21434](https://www.itemis.com/compliance-intelligence/cyber-security/whitepaper/future-challenges-iso-sae-21434/): Ein umfassender Leitfaden zur Implementierung von ISO/SAE 21434 — von der organisatorischen Cybersecurity-Governance (Clause 5) bis zur TARA (Clause 15), gemeinsam entwickelt von itemis und Deloitte. Kostenloses Whitepaper. - [Industrial & Automotive Functional Safety: ISO 26262 & IEC 61508](https://www.itemis.com/compliance-intelligence/functional-safety/): ISO 26262, IEC 61508 und funktionale Sicherheit für sicherheitskritische Systeme in Automotive und Industrie. - [Webinare](https://www.itemis.com/compliance-intelligence/functional-safety/webinar/): Webinare zu Funktionaler Sicherheit: Live-Termine und Aufzeichnungen zu ISO 26262, ASIL und Safety-Nachweisen – kostenlos von den itemis Experten. - [Automotive SPICE 4.0: Auswirkungen auf Hard- & Softwareentwicklung](https://www.itemis.com/compliance-intelligence/functional-safety/webinar/automotive-spice-4-0/): Erfahren Sie im Webinar, wie Automotive SPICE 4.0 Ihre Hard- und Softwareentwicklung beeinflusst – mit Praxiseinblicken von führenden Experten. - [itemis ANALYZE: ASPICE-Assessment in 5 Stunden statt 5 Wochen](https://www.itemis.com/compliance-intelligence/functional-safety/webinar/itemis-analyze-aspice-in-5-hours-instead-of-5-weeks/): Erfahren Sie, wie Sie mit itemis ANALYZE ASPICE-Assessments von fünf Wochen auf fünf Stunden reduzieren – ohne Abstriche bei Qualität und Compliance. - [itemis ANALYZE Goes Cloud: KI-gestützte Engineering Intelligence](https://www.itemis.com/compliance-intelligence/functional-safety/webinar/itemis-analyze-goes-cloud/): Erfahren Sie, wie itemis ANALYZE in der Cloud Datensilos überwindet und KI-Assistenten mit echtem Engineering-Kontext versorgt. - [Whitepaper: Functional Safety & Cyber Security](https://www.itemis.com/compliance-intelligence/functional-safety/whitepaper/): Kostenlose Whitepaper zu ISO 26262, ISO/SAE 21434 und enterprise-weiter Compliance — für OEMs und Tier-1-Zulieferer. - [Automatic Generation of a Design-FMEA](https://www.itemis.com/compliance-intelligence/functional-safety/whitepaper/automatic-fmea-generation/): Wie eine vollständige Design-FMEA automatisch aus bestehenden Engineering-Work-Products generiert werden kann — ein natürlicher Schritt im modellbasierten Systems Engineering. Kostenloses Whitepaper. - [Cohesion Without Disruption](https://www.itemis.com/compliance-intelligence/functional-safety/whitepaper/cohesion-without-disruption/): Wie führende OEMs und Tier-1-Zulieferer Functional Safety (ISO 26262) und Cyber Security (ISO/SAE 21434) enterprise-weit vereinen — ohne ihre lokalen Best-of-Breed-Toolchains zu ersetzen. - [Unabhängigkeit als prüfbare Eigenschaft](https://www.itemis.com/compliance-intelligence/functional-safety/whitepaper/unabhaengigkeit-als-pruefbare-eigenschaft/): Wie sich Unabhängigkeit bei ASIL-Zerlegung maschinell prüfen lässt: graphentheoretisches Kopplungsverfahren, Defeater-Semantik und kontinuierliche Assurance mit LLM-Agenten und itemis ANALYZE. Kostenlos von Sebastian Ruppel, itemis. - [Requirements Traceability: End-to-End-Traceability für regulierte Industrien](https://www.itemis.com/compliance-intelligence/requirements-traceability/): Durchgängige, auditierbare Requirements Traceability für Automotive, Defence, Industrial und MedTech: von Anforderungen über Architektur bis zu Tests, Validierung und Releases. - [Requirements Traceability Matrix: das Excel-Beispiel](https://www.itemis.com/compliance-intelligence/requirements-traceability/rtm-excel-vorlage/): Kostenlose Excel-Vorlage einer Requirements Traceability Matrix: drei Link-Matrices von der Kundenanforderung bis zum Testfall, kumulierte Sicht und Coverage-Berechnung mit Realized-Status. - [Webinare](https://www.itemis.com/compliance-intelligence/requirements-traceability/webinar/): Webinare zu Requirements Traceability: Live-Termine und Aufzeichnungen zu Nachverfolgbarkeit von Anforderungen und Traceability-Tools – kostenlos von itemis. - [Domain-Experten stärken: Modellierungstools für alle mit Modelix](https://www.itemis.com/compliance-intelligence/requirements-traceability/webinar/empowering-domain-experts/): Erfahren Sie, wie Modelix domänenspezifische Sprachen für Nicht-Entwickler zugänglich macht und Desktop-Modellierungstools in moderne Web-Applikationen verwandelt. - [Lifecycle Management: Cybersecurity-Herausforderungen nach ISO/SAE 21434](https://www.itemis.com/compliance-intelligence/requirements-traceability/webinar/lifecycle-management-challenges/): Erfahren Sie, welche Lifecycle-Management-Anforderungen ISO/SAE 21434 und UN-Regulation 155 stellen und wie Sie Cybersecurity über den gesamten Fahrzeuglebenszyklus sicherstellen. - [Custom Software Development für Enterprise](https://www.itemis.com/custom-software/): Maßgeschneiderte Software-Entwicklung für Enterprise-Kunden — Full-Stack, KI-gestützt, agil. Für Banken, Versicherungen, Logistik und Industrie. - [Eingespielte Senior Full-Stack Teams für Cloud-Native Development](https://www.itemis.com/custom-software/full-stack/): Eingespielte Senior-Teams für Full-Stack Development, Cloud-Migration und Microservices: von regulierter Infrastruktur bis Sovereign Cloud nach Gaia-X-Standards. - [Webinare](https://www.itemis.com/custom-software/full-stack/webinar/): Webinare zu Full-Stack- und Cloud-native-Entwicklung von itemis: Live-Termine und Aufzeichnungen zu Migration, Enterprise-Java und modernen Architekturen – kostenlos. - [Camunda 7 is over](https://www.itemis.com/custom-software/full-stack/webinar/camunda-7-is-over/): Camunda 7 hat das End of Life erreicht. Aufzeichnung ansehen und Migrationsoptionen mit Experten von itemis und Haulmont bewerten. - [AI Enablement: KI, die in Ihrem Unternehmen wirklich ankommt](https://www.itemis.com/custom-software/ki-enablement/): itemis befähigt Unternehmen, KI eigenständig und nachhaltig einzusetzen: Prozessanalyse, Werkzeugwahl, Integration, Datensouveränität und Befähigung der Mitarbeiter. - [Webinare](https://www.itemis.com/custom-software/ki-enablement/webinar/): Webinare zu KI im Unternehmen: Live-Termine und Aufzeichnungen zu KI-gestützter Softwareentwicklung und AI-Agenten – kostenlos von den itemis Experten. - [Smart Move - KI Anwendungsfälle in Transportation und Mobility](https://www.itemis.com/custom-software/ki-enablement/webinar/smart-move/): Erfahren Sie, welche konkreten KI-Potenziale die Mobilitätsbranche bietet – mit Praxisbeispielen von Deutschen Bahn und itemis. - [Whitepaper: AI Enablement](https://www.itemis.com/custom-software/ki-enablement/whitepaper/): Kostenlose Whitepaper zu lokaler KI, Open-Weight-Modellen, Fine-Tuning und Datensouveränität, geschrieben für Organisationen, die KI produktiv und unter eigener Kontrolle betreiben wollen. - [Local AI That Competes](https://www.itemis.com/custom-software/ki-enablement/whitepaper/local-ai-that-competes/): Wann schlägt ein Open-Weight-Modell in der eigenen Infrastruktur eine Frontier-API? Fünf Engineering-Hebel und ein 90-Tage-Pilotplan. Kostenloses Whitepaper von Christoph Hess. - [Legacy Code Modernization mit KI-Unterstützung](https://www.itemis.com/custom-software/legacy-modernisierung/): Risikominimierte Legacy-Migration: COBOL, PL/I & Mainframe schrittweise und nachweislich gleichwertig nach Java & PostgreSQL überführen. ISO 9001. - [Webinare](https://www.itemis.com/custom-software/legacy-modernisierung/webinar/): Webinare zur Legacy-Modernisierung: Live-Termine und Aufzeichnungen zu Migrationsstrategien und Altsystem-Analyse – kostenlos von itemis. - [Finance und Insurance - Erfolgreiche Migration und Wachstum in der Cloud](https://www.itemis.com/custom-software/legacy-modernisierung/webinar/erfolgreiche-migration-und-wachstum-in-der-cloud/): Erfahren Sie, wie Finanz- und Versicherungsunternehmen Altsysteme erfolgreich in die Cloud migrieren und dabei wachsen. - [Digital Finance and Insurance: Legacy Systeme im Wandel](https://www.itemis.com/custom-software/legacy-modernisierung/webinar/systeme-im-wandel/): Wie modernisieren Finanz- und Versicherungsunternehmen ihre Legacy-Systeme? Erfahren Sie es in dieser Webinar-Aufzeichnung. - [KI-gestützte Modernisierung von Legacy-Kernsystemen](https://www.itemis.com/custom-software/legacy-modernisierung/whitepaper/ki-gestuetzte-modernisierung-von-legacy-kernsystemen/): Das risikobasierte Vorgehensmodell für Legacy-Modernisierung: Discovery, Äquivalenznachweis, Spec-Driven Refactoring und Go-Live für COBOL, PL/I und RPG. Mit Business Case und Entscheider-Checkliste. Kostenlos von itemis. - [Datenschutzerklärung](https://www.itemis.com/datenschutz/): Datenschutzerklärung der itemis AG — Informationen zur Erhebung und Verarbeitung personenbezogener Daten, Ihren Rechten und eingesetzten Diensten. - [Glossar](https://www.itemis.com/glossar/): Fachbegriffe aus Functional Safety, Cybersecurity, Requirements Traceability, Model-Based Engineering und Softwareentwicklung — präzise erklärt von den Experten der itemis. - [ALM (Application Lifecycle Management)](https://www.itemis.com/glossar/alm/): ALM (Application Lifecycle Management) bezeichnet die koordinierte Verwaltung des gesamten Software-Lebenszyklus — von Anforderungen über Entwurf, Implementierung und Test bis zu Release und Wartung — samt der Prozesse und Werkzeuge, die diese Disziplinen verbinden. - [ASIL (Automotive Safety Integrity Level)](https://www.itemis.com/glossar/asil/): ASIL (Automotive Safety Integrity Level) ist die Risikoeinstufung der ISO 26262 für sicherheitsrelevante E/E-Systeme im Fahrzeug. Die vier Stufen ASIL A bis D bestimmen, wie streng Entwicklung, Nachweise und Tests einer Funktion ausfallen müssen. - [Attack Feasibility (Angriffsdurchführbarkeit)](https://www.itemis.com/glossar/attack-feasibility/): Die Attack Feasibility (Angriffsdurchführbarkeit) bewertet nach ISO/SAE 21434, wie leicht sich ein Angriffspfad durchführen lässt. Das Ergebnis ist der Attack Feasibility Level (AFL), der zusammen mit dem Impact Level den Risk Level eines Risikos bestimmt. - [Attack Path (Angriffspfad)](https://www.itemis.com/glossar/attack-path/): Ein Attack Path (Angriffspfad) ist nach ISO/SAE 21434 die Abfolge konkreter Angriffsschritte, mit der ein Angreifer ein Bedrohungsszenario realisieren kann. Die Norm verlangt zu jedem Bedrohungsszenario eine Angriffspfad-Analyse; bewertet werden die Pfade über die Attack Feasibility. - [Attack Tree (Angriffsbaum)](https://www.itemis.com/glossar/attack-tree/): Ein Attack Tree (Angriffsbaum) zerlegt ein Angriffsziel hierarchisch in Teilziele und konkrete Angriffsschritte. In der TARA nach ISO/SAE 21434 dienen Angriffsbäume dazu, Angriffspfade systematisch zu modellieren und ihre Durchführbarkeit nachvollziehbar zu bewerten. - [Automotive SPICE (ASPICE)](https://www.itemis.com/glossar/automotive-spice/): Automotive SPICE (ASPICE) ist das Prozess-Assessment-Modell der Automobilindustrie zur Bewertung der Reife von Entwicklungsprozessen für software-basierte Systeme. Assessments stufen Prozesse auf Capability Levels 0 bis 5 ein — viele OEMs fordern von Zulieferern Level 2 oder 3. - [AUTOSAR (AUTomotive Open System ARchitecture)](https://www.itemis.com/glossar/autosar/): AUTOSAR (AUTomotive Open System ARchitecture) ist eine weltweite Entwicklungspartnerschaft von Fahrzeugherstellern, Zulieferern und Werkzeuganbietern, die eine standardisierte Softwarearchitektur für Fahrzeug-Steuergeräte definiert. Ziel ist, Softwarekomponenten über Hersteller- und Plattformgrenzen hinweg integrierbar zu machen. - [Best-of-Breed](https://www.itemis.com/glossar/best-of-breed/): Best-of-Breed bezeichnet die Werkzeugstrategie, für jede Engineering-Aufgabe das jeweils beste spezialisierte Werkzeug einzusetzen, statt auf die All-in-One-Suite eines einzelnen Anbieters zu setzen. Der Preis der Spezialisierung ist der Integrationsaufwand zwischen den Werkzeugen. - [BPMN (Business Process Model and Notation)](https://www.itemis.com/glossar/bpmn/): BPMN (Business Process Model and Notation) ist der von der OMG standardisierte grafische Notationsstandard zur Modellierung von Geschäftsprozessen. BPMN-2.0-Modelle sind für Fachbereich und IT gleichermaßen lesbar und von Workflow-Engines direkt ausführbar — das Diagramm ist zugleich Dokumentation und ausführbarer Prozess. - [CAL (Cybersecurity Assurance Level)](https://www.itemis.com/glossar/cal/): Der CAL (Cybersecurity Assurance Level) ist das Klassifizierungsschema der ISO/SAE 21434 mit vier Stufen (CAL 1–4). Er legt fest, mit welcher Strenge die Cybersecurity-Aktivitäten eines Items durchgeführt werden — etwa die Tiefe der Verifikation — nicht aber, welche technischen Maßnahmen umzusetzen sind. - [Cloud-Migration](https://www.itemis.com/glossar/cloud-migration/): Cloud-Migration bezeichnet die Verlagerung von Anwendungen, Daten und Infrastruktur aus dem eigenen Rechenzentrum in eine Cloud-Umgebung. Das Spektrum reicht vom unveränderten Umzug (Rehosting) bis zum Cloud-Native-Neuaufbau — welcher Weg trägt, hängt von Anwendung, Regulatorik und Wirtschaftlichkeit ab. - [CSMS (Cyber Security Management System)](https://www.itemis.com/glossar/csms/): Ein CSMS (Cyber Security Management System) bündelt die Prozesse, Rollen und Verantwortlichkeiten, mit denen ein Fahrzeughersteller Cybersecurity-Risiken über den gesamten Lebenszyklus identifiziert, bewertet und behandelt. Die UNECE R155 macht ein geprüftes CSMS zur Voraussetzung für die Typgenehmigung. - [CVD (Coordinated Vulnerability Disclosure)](https://www.itemis.com/glossar/cvd/): CVD (Coordinated Vulnerability Disclosure) ist der koordinierte Prozess, über den Sicherheitsforscher und andere Melder Schwachstellen an den Hersteller melden und Details erst nach Bereitstellung einer Abhilfe veröffentlicht werden. Der EU Cyber Resilience Act macht eine CVD-Policy zur Herstellerpflicht. - [Cyber Resilience Act (CRA)](https://www.itemis.com/glossar/cyber-resilience-act/): Der Cyber Resilience Act (CRA) ist die EU-Verordnung mit verbindlichen Cybersecurity-Mindestanforderungen für Produkte mit digitalen Elementen. Ab dem 11. September 2026 gelten Meldepflichten für aktiv ausgenutzte Schwachstellen, ab dem 11. Dezember 2027 alle Anforderungen inklusive CE-Kennzeichnung. - [Cybersecurity Concept (Cybersecurity-Konzept)](https://www.itemis.com/glossar/cybersecurity-concept/): Das Cybersecurity Concept ist das Arbeitsergebnis, das die Konzeptphase der ISO/SAE 21434 abschließt: die Cybersecurity-Anforderungen des Items und die Anforderungen an seine Betriebsumgebung, abgeleitet aus den Cybersecurity Goals und der Architektur zugeordnet. - [Cybersecurity Goal (Cybersecurity-Ziel)](https://www.itemis.com/glossar/cybersecurity-goal/): Ein Cybersecurity Goal ist eine Sicherheitsanforderung auf oberster Ebene, die in der Konzeptphase nach ISO/SAE 21434 aus der Risikobehandlung der TARA hervorgeht. Es adressiert ein oder mehrere Bedrohungsszenarien und wird in der Entwicklung durch Cybersecurity-Anforderungen umgesetzt. - [Damage Scenario (Schadensszenario)](https://www.itemis.com/glossar/damage-scenario/): Ein Damage Scenario (Schadensszenario) beschreibt nach ISO/SAE 21434 die nachteiligen Folgen, die eintreten, wenn eine Sicherheitseigenschaft eines Assets verletzt wird. Es wird in vier Kategorien bewertet — Safety, Finanzen, Betrieb, Privatsphäre — und liefert den Impact Level für die Risikobestimmung. - [DSL (Domänenspezifische Sprache)](https://www.itemis.com/glossar/dsl/): Eine DSL (Domänenspezifische Sprache) ist eine Programmier- oder Modellierungssprache, die auf ein klar abgegrenztes Fachgebiet zugeschnitten ist. Statt universell einsetzbar zu sein wie Java oder C, bildet sie Konzepte, Regeln und Vokabular genau einer Domäne ab. - [FMEA (Failure Mode and Effects Analysis)](https://www.itemis.com/glossar/fmea/): Die FMEA (Failure Mode and Effects Analysis) ist eine systematische, induktive Analysemethode: Sie identifiziert mögliche Fehlerarten eines Systems, bewertet deren Ursachen und Auswirkungen und priorisiert Gegenmaßnahmen — bevor die Fehler im Produkt auftreten. - [Funktionale Sicherheit](https://www.itemis.com/glossar/funktionale-sicherheit/): Funktionale Sicherheit ist der Teil der Sicherheit eines Systems, der von der korrekten Funktion sicherheitsbezogener E/E-Systeme abhängt. Ziel ist die Abwesenheit unvertretbarer Risiken durch Fehlfunktionen. Grundnorm ist die IEC 61508, im Automobilbereich gilt die ISO 26262. - [HARA (Gefährdungsanalyse und Risikobewertung)](https://www.itemis.com/glossar/hara/): Die HARA (Hazard Analysis and Risk Assessment) ist die Gefährdungsanalyse und Risikobewertung nach ISO 26262-3. Sie bewertet Gefährdungen eines Fahrzeugsystems nach Schwere, Exposition und Beherrschbarkeit, leitet daraus den ASIL ab und definiert die obersten Sicherheitsziele. - [IEC 61508 (Grundnorm der funktionalen Sicherheit)](https://www.itemis.com/glossar/iec-61508/): IEC 61508 ist die branchenübergreifende Grundnorm für die funktionale Sicherheit elektrischer, elektronischer und programmierbar elektronischer (E/E/PE) Systeme. Sie definiert den Sicherheitslebenszyklus und die Stufen SIL 1 bis SIL 4 und ist die Basis zahlreicher Sektornormen wie der ISO 26262. - [IEC 62443](https://www.itemis.com/glossar/iec-62443/): IEC 62443 ist die internationale Normenreihe für die Cybersecurity industrieller Automatisierungs- und Steuerungssysteme (OT). Kernkonzepte sind die Segmentierung in Zonen und Conduits sowie die vier Security Level SL1 bis SL4, die den Schutzbedarf gegen unterschiedlich starke Angreifer abstufen. - [Impact-Analyse (Auswirkungsanalyse)](https://www.itemis.com/glossar/impact-analyse/): Die Impact-Analyse (Auswirkungsanalyse) ermittelt anhand von Trace-Links, welche Artefakte — Anforderungen, Architektur, Code, Tests, Nachweise — von einer Änderung betroffen sind. Sie macht Änderungskosten und -risiken abschätzbar, bevor die Änderung umgesetzt wird. - [ISO 26262 (Funktionale Sicherheit im Fahrzeug)](https://www.itemis.com/glossar/iso-26262/): ISO 26262 ist die internationale Norm für die funktionale Sicherheit elektrischer und elektronischer (E/E) Systeme in Straßenfahrzeugen. Sie leitet sich von der IEC 61508 ab, definiert mit ASIL A bis D ein automobilspezifisches Risikoschema und begleitet den gesamten Sicherheitslebenszyklus. - [ISO/SAE 21434 (Road Vehicles — Cybersecurity Engineering)](https://www.itemis.com/glossar/iso-sae-21434/): ISO/SAE 21434 ist die zentrale Cybersecurity-Norm der Automobilindustrie. Sie beschreibt einen durchgängigen Cybersecurity-Engineering-Prozess über den gesamten Fahrzeug-Lebenszyklus — von Konzept und Entwicklung über Produktion und Betrieb bis zur Außerbetriebnahme. - [Item Definition](https://www.itemis.com/glossar/item-definition/): Die Item Definition ist der erste Schritt der TARA nach ISO/SAE 21434. Sie legt fest, was analysiert wird: das Item mit seinen Funktionen, seiner vorläufigen Architektur und der Item Boundary, dazu die cybersecurity-relevanten Annahmen. - [KerML (Kernel Modeling Language)](https://www.itemis.com/glossar/kerml/): KerML (Kernel Modeling Language) ist die von der OMG standardisierte Basissprache, auf der SysML v2 aufbaut. Sie definiert die Kernkonzepte der Modellierung und die formale Semantik, die darauf aufbauende Sprachen wiederverwenden und spezialisieren. - [KI-Agent](https://www.itemis.com/glossar/ki-agent/): Ein KI-Agent ist ein Softwaresystem, das auf Basis eines LLM mehrstufige Aufgaben eigenständig plant und ausführt: Es nutzt Werkzeuge wie Dateisysteme, Datenbanken oder APIs, bewertet Zwischenergebnisse und arbeitet iterativ auf ein vorgegebenes Ziel hin — unter menschlicher Aufsicht. - [Language Workbench](https://www.itemis.com/glossar/language-workbench/): Eine Language Workbench ist eine Entwicklungsumgebung für den Bau eigener, meist domänenspezifischer Sprachen (DSLs). Sie liefert alles, was eine Sprache praktisch nutzbar macht: Sprachdefinition, Editor mit Code-Completion, Validierung sowie Codegenerierung oder Interpretation. - [Legacy-Modernisierung](https://www.itemis.com/glossar/legacy-modernisierung/): Legacy-Modernisierung bezeichnet die Überführung gewachsener Altsysteme — etwa COBOL- oder Mainframe-Anwendungen — in moderne Technologien und Architekturen. Ziel ist, die bewährte Geschäftslogik zu erhalten und zugleich Wartbarkeit, Betriebskosten und Release-Fähigkeit zu verbessern. - [Living TARA (Dynamic TARA)](https://www.itemis.com/glossar/living-tara/): Eine Living TARA (auch Dynamic TARA) ist eine Bedrohungsanalyse und Risikobewertung, die über den gesamten Produktlebenszyklus aktuell gehalten wird. Neue Schwachstellen, geänderte Komponenten und neue Angriffstechniken fließen fortlaufend in die Risikobewertung ein, statt nur einmalig in der Konzeptphase. - [LLM (Large Language Model)](https://www.itemis.com/glossar/llm/): Ein LLM (Large Language Model) ist ein mit sehr großen Textmengen trainiertes neuronales Netz, das Sprache statistisch modelliert und damit Texte versteht, zusammenfasst, übersetzt und erzeugt. LLMs sind die technische Grundlage von Chatbots, KI-Assistenten und KI-Agenten. - [MBSE (Model-Based Systems Engineering)](https://www.itemis.com/glossar/mbse/): MBSE (Model-Based Systems Engineering) ist ein Ansatz des Systems Engineering, bei dem ein formales, maschinenlesbares Systemmodell — nicht Dokumente — das zentrale Artefakt der Entwicklung ist. Anforderungen, Architektur und Verhalten werden in einem konsistenten Modell zusammengeführt. - [MCP (Model Context Protocol)](https://www.itemis.com/glossar/mcp/): MCP (Model Context Protocol) ist ein offener Standard, der KI-Anwendungen wie LLMs und KI-Agenten mit externen Datenquellen und Werkzeugen verbindet. Statt für jede Kombination aus Modell und System eine eigene Integration zu bauen, genügt ein MCP-Server je System. - [MDSD (Modellgetriebene Softwareentwicklung)](https://www.itemis.com/glossar/mdsd/): MDSD (Modellgetriebene Softwareentwicklung) ist ein Entwicklungsansatz, bei dem formale Modelle die primären Artefakte der Softwareentwicklung sind. Aus den Modellen wird Quellcode automatisiert generiert, statt ihn von Hand zu schreiben — reproduzierbar, konsistent und unabhängig von der Zielplattform. - [Metamodell](https://www.itemis.com/glossar/metamodell/): Ein Metamodell ist das Modell eines Modells: Es definiert, welche Elemente, Beziehungen und Regeln in einem Modell erlaubt sind. Metamodelle spielen für Modelle dieselbe Rolle wie eine Grammatik für Sprachen — sie machen Modelle formal eindeutig und maschinell verarbeitbar. - [Microservices](https://www.itemis.com/glossar/microservices/): Microservices sind ein Architekturstil, bei dem eine Anwendung aus vielen kleinen, fachlich geschnittenen Diensten besteht, die unabhängig voneinander entwickelt, deployt und skaliert werden und über Schnittstellen kommunizieren. Sie erhöhen Flexibilität und Skalierbarkeit — um den Preis höherer Betriebskomplexität. - [MoRA (Modular Risk Assessment)](https://www.itemis.com/glossar/mora/): MoRA (Modular Risk Assessment) ist eine am Fraunhofer AISEC entwickelte Methodik für modellbasierte Security-Risikoanalysen. Sie gliedert die Analyse in vier Phasen — System modellieren, Schutzbedarf identifizieren, Bedrohungen analysieren, Risiken analysieren — und trägt damit eine TARA nach ISO/SAE 21434. - [NIS2 (Richtlinie (EU) 2022/2555)](https://www.itemis.com/glossar/nis2/): NIS2 (Richtlinie (EU) 2022/2555) ist die EU-Richtlinie zur Cybersicherheit wesentlicher und wichtiger Einrichtungen. Sie verpflichtet Unternehmen in 18 Sektoren zu Risikomanagement, Meldeprozessen und Management-Verantwortung — anders als der CRA regelt sie Organisationen, nicht Produkte. - [Prozessautomatisierung](https://www.itemis.com/glossar/prozessautomatisierung/): Prozessautomatisierung bezeichnet die Ausführung wiederkehrender Geschäftsprozesse durch Software — vom regelbasierten Workflow über BPM-Plattformen mit Workflow-Engines bis zur KI-gestützten Automatisierung. Ziel ist, manuelle Routineschritte zu reduzieren und Prozesse schneller, nachvollziehbarer und weniger fehleranfällig zu machen. - [RAG (Retrieval-Augmented Generation)](https://www.itemis.com/glossar/rag/): RAG (Retrieval-Augmented Generation) ist ein Architekturmuster, das ein LLM zur Antwortzeit mit Inhalten aus externen Wissensquellen versorgt: Erst werden zur Anfrage passende Dokumente gesucht (Retrieval), dann erzeugt das Modell die Antwort auf dieser Grundlage (Generation). - [ReqIF (Requirements Interchange Format)](https://www.itemis.com/glossar/reqif/): ReqIF (Requirements Interchange Format) ist ein XML-basierter OMG-Standard zum werkzeugübergreifenden Austausch von Anforderungen samt Attributen, Struktur und Verknüpfungen — etwa zwischen OEM und Zulieferer oder zwischen unterschiedlichen RM-Tools. - [Requirements Coverage](https://www.itemis.com/glossar/requirements-coverage/): Requirements Coverage bezeichnet den Grad, zu dem Anforderungen durch andere Entwicklungsartefakte — typischerweise Testfälle — abgedeckt sind. Prozessstandards wie Automotive SPICE fordern die Messung, der Begriff ist jedoch nicht einheitlich definiert. - [Requirements Engineering](https://www.itemis.com/glossar/requirements-engineering/): Requirements Engineering ist die systematische Disziplin, Anforderungen an ein System zu ermitteln, zu dokumentieren, zu prüfen und über den gesamten Lebenszyklus zu verwalten. Ziel ist ein gemeinsames, prüfbares Verständnis davon, was das System leisten soll. - [Requirements Traceability](https://www.itemis.com/glossar/requirements-traceability/): Requirements Traceability ist die Fähigkeit, jede Anforderung von ihrem Ursprung über Architektur, Implementierung und Tests bis zur Validierung nachzuverfolgen — in beide Richtungen. Normen wie ASPICE, ISO 26262 und der Cyber Resilience Act setzen sie voraus. - [Safety Case (Sicherheitsnachweis)](https://www.itemis.com/glossar/safety-case/): Ein Safety Case (Sicherheitsnachweis) ist die strukturierte Argumentation, dass ein System in seinem Einsatzkontext hinreichend sicher ist — gestützt auf nachvollziehbare Evidenzen aus dem Entwicklungsprozess. Die ISO 26262 fordert ihn als zentrales Arbeitsergebnis für sicherheitsrelevante E/E-Systeme. - [SBOM (Software Bill of Materials)](https://www.itemis.com/glossar/sbom/): Eine SBOM (Software Bill of Materials) ist die maschinenlesbare Stückliste aller Softwarekomponenten eines Produkts, inklusive Open-Source-Bibliotheken. Der EU Cyber Resilience Act verlangt sie als Teil der technischen Dokumentation — gängige Formate sind SPDX und CycloneDX. - [Security by Design](https://www.itemis.com/glossar/security-by-design/): Security by Design ist das Prinzip, Sicherheit von der ersten Konzeptphase an in ein Produkt hineinzuentwickeln, statt sie nachträglich über Patches nachzurüsten. Normen wie ISO/SAE 21434 und Gesetze wie der EU Cyber Resilience Act machen das Prinzip verbindlich. - [SIL (Safety Integrity Level)](https://www.itemis.com/glossar/sil/): SIL (Safety Integrity Level) ist die Risikoeinstufung der IEC 61508 für sicherheitsbezogene E/E/PE-Systeme. Die vier Stufen SIL 1 bis SIL 4 legen fest, wie unwahrscheinlich der gefahrbringende Ausfall einer Sicherheitsfunktion sein muss und wie streng ihre Entwicklung abzusichern ist. - [SOTIF (Safety of the Intended Functionality, ISO 21448)](https://www.itemis.com/glossar/sotif/): SOTIF (Safety of the Intended Functionality, ISO 21448) adressiert Gefährdungen ohne Fehlfunktion: Das System arbeitet exakt wie spezifiziert, aber Spezifikation oder Sensorleistung reichen für die reale Situation nicht aus — zentral für Fahrerassistenz und KI-basierte Funktionen. - [SysML v2](https://www.itemis.com/glossar/sysml-v2/): SysML v2 ist der von der OMG standardisierte Nachfolger von SysML v1. Die Sprache basiert auf einem eigenen Metamodell (KerML) statt auf einem UML-Profil, stellt eine textuelle Notation gleichberechtigt neben die grafische und definiert eine standardisierte API für den werkzeugübergreifenden Modellzugriff. - [SysML (Systems Modeling Language)](https://www.itemis.com/glossar/sysml/): SysML (Systems Modeling Language) ist die von der OMG standardisierte grafische Modellierungssprache für das Systems Engineering. Sie beschreibt Anforderungen, Struktur und Verhalten komplexer Systeme und ist die verbreitetste Sprache für Model-Based Systems Engineering (MBSE). - [Systems Engineering](https://www.itemis.com/glossar/systems-engineering/): Systems Engineering ist der interdisziplinäre Ansatz zur Entwicklung komplexer technischer Systeme über den gesamten Lebenszyklus — von den Stakeholder-Anforderungen über Architektur und Integration bis zu Verifikation und Betrieb. Im Fokus steht das Gesamtsystem, nicht die einzelne Disziplin. - [TARA (Threat Analysis and Risk Assessment)](https://www.itemis.com/glossar/tara/): TARA (Threat Analysis and Risk Assessment) ist die Bedrohungsanalyse und Risikobewertung der ISO/SAE 21434. Sie ermittelt strukturiert, welche Assets eines Fahrzeugs oder einer Komponente schützenswert sind, wie sie angegriffen werden können und wie die Risiken behandelt werden. - [Threat Modeling (Bedrohungsmodellierung)](https://www.itemis.com/glossar/threat-modeling/): Threat Modeling (Bedrohungsmodellierung) ist die systematische Analyse eines Systems aus Angreifersicht: Welche Werte sind schützenswert, über welche Wege könnte ein Angreifer sie kompromittieren, und welche Gegenmaßnahmen sind angemessen? Es ist die methodische Grundlage normativer Risikoanalysen wie der TARA. - [TIM (Traceability Information Model)](https://www.itemis.com/glossar/tim/): Ein Traceability Information Model (TIM) definiert, welche Artefakttypen eines Entwicklungsprozesses durch welche Beziehungstypen verbunden sein müssen — der verbindliche Bauplan für Traceability. TIMs sind versioniert, damit Trace-Links auditierbar gegen eine definierte Modellversion validiert werden können. - [Tool-Qualifizierung (ISO 26262)](https://www.itemis.com/glossar/tool-qualifizierung/): Tool-Qualifizierung ist der Nachweis nach ISO 26262-8, dass ein Softwarewerkzeug für den Einsatz in der sicherheitsrelevanten Entwicklung ausreichend vertrauenswürdig ist. Ob sie nötig ist, bestimmt der Tool Confidence Level (TCL) aus Tool Impact und Tool Error Detection. - [Toolchain Integration](https://www.itemis.com/glossar/toolchain-integration/): Toolchain Integration verbindet die Werkzeuge einer Engineering-Organisation — Requirements Management, Modellierung, Entwicklung, Test — zu einer durchgängigen Werkzeugkette. Sie bricht Datensilos auf und ermöglicht Traceability über Tool-Grenzen hinweg. - [Traceability-Matrix (Requirements Traceability Matrix, RTM)](https://www.itemis.com/glossar/traceability-matrix/): Eine Traceability-Matrix (RTM) ist eine Tabelle, die Beziehungen zwischen Entwicklungsartefakten wie Anforderungen und Testfällen über eindeutige IDs abbildet. Sie stellt bidirektionale Nachverfolgbarkeit her und macht Lücken sofort sichtbar. - [UML-Profil](https://www.itemis.com/glossar/uml-profil/): Ein UML-Profil ist der standardisierte Erweiterungsmechanismus der UML: Über Stereotypen, Tagged Values und Constraints erhalten generische Modellelemente eine domänenspezifische Bedeutung, ohne die Sprache selbst zu verändern oder das Modellierungswerkzeug zu ersetzen. - [UML (Unified Modeling Language)](https://www.itemis.com/glossar/uml/): UML (Unified Modeling Language) ist die von der OMG standardisierte grafische Modellierungssprache zur Spezifikation, Visualisierung und Dokumentation von Softwaresystemen. UML 2 definiert 14 Diagrammtypen in den Kategorien Struktur und Verhalten — vom Klassendiagramm bis zum Zustandsdiagramm. - [UNECE R155 (UN-Regelung Nr. 155 — Cybersecurity)](https://www.itemis.com/glossar/unece-r155/): UNECE R155 ist die UN-Regelung Nr. 155 zur Cybersecurity von Straßenfahrzeugen. Sie macht ein geprüftes Cyber Security Management System (CSMS) zur Voraussetzung für die Typgenehmigung: Ohne CSMS-Nachweis erhalten neue Fahrzeugtypen in der EU keine Genehmigung — und damit keinen Marktzugang. - [UNECE R156 (UN-Regelung Nr. 156 — Software-Updates)](https://www.itemis.com/glossar/unece-r156/): UNECE R156 ist die UN-Regelung Nr. 156 zu Software-Updates von Straßenfahrzeugen. Sie macht ein geprüftes Software Update Management System (SUMS) zur Voraussetzung für die Typgenehmigung: Der Hersteller muss jederzeit belegen können, welcher Softwarestand auf welchem Fahrzeugtyp läuft und ob ein Update die Genehmigung berührt. - [V-Modell](https://www.itemis.com/glossar/v-modell/): Das V-Modell ist ein Vorgehensmodell der System- und Softwareentwicklung: Der linke Ast verfeinert Anforderungen schrittweise bis zur Implementierung, der rechte Ast verifiziert jede Ebene gegen ihre Spezifikation. Jeder Entwicklungsstufe steht damit eine eigene Teststufe gegenüber. - [Impressum](https://www.itemis.com/impressum/): Impressum der itemis AG — Angaben gemäß § 5 DDG, Kontakt, Registereintrag und Verantwortliche. - [Podiumsdiskussionen über aktuelle IT-Themen | itemis PODIUM](https://www.itemis.com/itemis-podium/): In unseren Podiumsdiskussionen beleuchten Fachleute aus verschiedenen Branchen aktuelle und aufregende Themen der IT-Welt in tiefgründigen Debatten über ihre Fachgebiete. - [Code ohne Coder](https://www.itemis.com/itemis-podium/code-ohne-coder/): Vibe Coding & KI-Agenten: Erfahren Sie, wie MCP und autonome Agenten die Softwareentwicklung revolutionieren und welche Skills Entwickler morgen wirklich brauchen. - [Den ersten CRA Meilenstein gemeinsam meistern](https://www.itemis.com/itemis-podium/cra-meilenstein-gemeinsam-meistern/): Ab 2026 fordert der Cyber Resilience Act (CRA) Meldungen binnen 24h. Experten-Insights zu PSOC-Aufbau, Triage-Prozessen und der CRAIG-Community. - [Dr. Smartphone übernimmt](https://www.itemis.com/itemis-podium/dr-smartphone-%C3%BCbernimmt/): Ob Symptom-Checker oder Wearables: KI ist in unserem Gesundheitsalltag längst angekommen. - [The Future of Systems Engineering](https://www.itemis.com/itemis-podium/future-of-systems-engineering/): Experten-Talk zur Zukunft des Systems Engineering: Erfahren Sie, wie SysML v2, MBSE und KI den Engineering-Prozess revolutionieren und Effizienz steigern. - [Ihr Produkt! Bald illegal?](https://www.itemis.com/itemis-podium/ihr-produkt-bald-illegal/): Experten diskutieren die Auswirkungen des EU Cyber Resilience Act (CRA) auf Unternehmen, Fristen und notwendige Security-Prozesse. - [Kampf der Giganten](https://www.itemis.com/itemis-podium/kampf-der-giganten/): Kampf der Giganten: Wo steht Europa bei KI-Agenten? Experten von itemis und academy4.ai über DSGVO-konforme LLMs, LangDock und digitale Souveränität. - [KI ist dumm!](https://www.itemis.com/itemis-podium/ki-ist-dumm/): Warum KI ohne Semantik rät: Erfahren Sie, wie Knowledge Graphs & Ontologien die Basis für verlässliche KI-Systeme bilden. Experten-Talk der itemis AG. - [Legacy-Migration mit KI](https://www.itemis.com/itemis-podium/legacy-migration-mit-ki/): Erfahren Sie, wie KI jahrzehntealte COBOL-Logik zukunftsfähig macht. Experten von itemis und der SDK diskutieren Strategien für die Legacy-Migration. - [Master vs. Meister](https://www.itemis.com/itemis-podium/master-vs-meister/): Erfahren Sie, wie KI Berufe verändert und welche Kompetenzen für Software-Architekten und IT-Entscheider 2026 wirklich zählen. - [Mensch oder Maschine](https://www.itemis.com/itemis-podium/mensch-oder-maschine/): Mensch oder Maschine? Erfahren Sie, wie KI & MBSE die Produktentwicklung verändern. Experten von RWTH Aachen, Canon & itemis über die neue Rolle des Ingenieurs. - [Camunda 7 ist tot – lang lebe Operaton!](https://www.itemis.com/itemis-podium/operaton/): Camunda 7 ist End of Life? OPERATON ist der neue Open-Source-Fork für stabile Prozessautomatisierung. Erfahren Sie alles über Migration, Governance und Modernisierung. - [Politik per Prompt](https://www.itemis.com/itemis-podium/politik-per-prompt/): Macht KI Politik überflüssig? Experten diskutieren über LLMs in der Verwaltung, digitale Souveränität und warum Verantwortung nicht automatisierbar ist. - [Sicherheit oder Sicherheit](https://www.itemis.com/itemis-podium/sicherheit-oder-sicherheit/): Safety & Cybersecurity im Fokus: Erfahren Sie, wie Sie ISO 26262 und ISO 21434 harmonisieren, Silos aufbrechen und Compliance als Wettbewerbsvorteil nutzen. - [Steigende Bedrohungen. Sinkende Resilienz.](https://www.itemis.com/itemis-podium/steigende-bedrohungen/): IT-Security ist Chefsache: Experten-Talk über menschliche Resilienz, Change Management und den Cyber Resilience Act (CRA) vom IT-Sicherheitstag NRW. - [Unchain AI](https://www.itemis.com/itemis-podium/unchain-ai/): KI in Medizin und Recht: Experten diskutieren bei itemis PODIUM über Effizienzgewinne, Datenschutzhürden und den Weg zur digitalen Souveränität in Europa. - [Vision & Challenges](https://www.itemis.com/itemis-podium/vision-and-challenges/) - [Die Zukunft der Mobilität](https://www.itemis.com/itemis-podium/zukunft-der-mobilit%C3%A4t/) - [Karriere bei itemis](https://www.itemis.com/karriere/): Software-Jobs bei itemis: 100% Remote, 4+1 Weiterbildungsmodell, unbefristeter Vertrag. Software Developer, Engineers und Cybersecurity-Experten gesucht. Jetzt bewerben. - [Kontakt](https://www.itemis.com/kontakt/): Nehmen Sie Kontakt mit itemis auf. Wir helfen Ihnen bei Fragen zu unseren Leistungen, Produkten und Projekten — schnell, direkt und ohne Umwege. - [Model-Based Systems & Software Engineering — Werkzeuge und Methoden](https://www.itemis.com/model-based-engineering/): Modellbasierte System- und Softwareentwicklung mit itemis CREATE (State Machines) und itemis ANALYZE (Requirements Traceability). - [Custom Tools & Domain-Specific Languages: Xtext, JetBrains MPS](https://www.itemis.com/model-based-engineering/custom-tools/): Domain-Specific Languages, Code-Generierung und domänenspezifische Modellierungs-Workbenches mit Xtext und JetBrains MPS, für Automotive, Medtech, Finance und Embedded. - [Webinare](https://www.itemis.com/model-based-engineering/custom-tools/webinar/): Webinare zu Custom Tools: Live-Termine und Aufzeichnungen zu maßgeschneiderten Entwicklungswerkzeugen und DSLs – kostenlos von itemis. - [Whitepaper: Custom Tooling & DSLs](https://www.itemis.com/model-based-engineering/custom-tools/whitepaper/): Kostenlose Whitepaper zu Domain-Specific Languages, Code-Generierung und maßgeschneiderten Modellierungs-Workbenches. - [Custom Tool oder Standard?](https://www.itemis.com/model-based-engineering/custom-tools/whitepaper/custom-tool-oder-standard/): Wann lohnt sich eine eigene DSL, wann ist ein UML/SysML-Profil die klügere Wahl? Entscheidungshilfe aus 20 Jahren Custom-Tool-Projekten bei itemis. Kostenlos von Dr. Patrick Könemann und Dr. Klaus Birken. - [State Machine & Statechart Modeling mit itemis CREATE](https://www.itemis.com/model-based-engineering/model-driven-software-development/): Model-Driven Software Development mit itemis CREATE: Statecharts modellieren, simulieren, Code generieren in C, C++, Java, Python. Deterministisch, auditierbar, plattformunabhängig. - [Webinare](https://www.itemis.com/model-based-engineering/model-driven-software-development/webinar/): Webinare zu modellgetriebener Softwareentwicklung: Live-Termine und Aufzeichnungen zu Codegenerierung und Modellierung – kostenlos von itemis. - [Rapid State Machine Development und Unit Testing für Embedded Systems](https://www.itemis.com/model-based-engineering/model-driven-software-development/webinar/rapid-state-machine-development-and-unit-testing/): Lernen Sie, wie itemis CREATE die Entwicklung und das Testen von Zustandsautomaten in Embedded Systems beschleunigt. - [Rapid State Machine Development in der Cloud mit KI-Co-Piloting](https://www.itemis.com/model-based-engineering/model-driven-software-development/webinar/rapid-state-machine-development-in-the-cloud-with-ai-co-piloting/): Erfahren Sie, wie Sie Zustandsautomaten in der Cloud mit KI-Unterstützung schnell entwickeln und verwalten. - [Model-Based Systems Engineering (MBSE) - Sprachen, Methoden und Werkzeuge](https://www.itemis.com/model-based-engineering/systems-engineering/): Modellbasierte Systementwicklung für cyber-physikalische Produkte in Automotive, Medtech und Aerospace. - [itemis auf dem TdSE 2026](https://www.itemis.com/model-based-engineering/systems-engineering/tdse/): itemis ist Platin-Sponsor des TdSE 2026 in Dortmund: Stand 2 und zwei Vorträge zu Continuous Compliance, MBSE und KI-gestützter ASPICE-Bewertung. - [Webinare](https://www.itemis.com/model-based-engineering/systems-engineering/webinar/): Webinare zu Model-Based Systems Engineering: Live-Termine und Aufzeichnungen zu SysML und MBSE-Einführung – kostenlos von itemis. - [AI meets MBSE](https://www.itemis.com/model-based-engineering/systems-engineering/webinar/ai-meets-mbse/): Erfahren Sie, wie KI und modellbasiertes Systems Engineering die Transportbranche revolutionieren. - [Systems Engineering mit KI – konkretes Potenzial, das wir heute nutzen können!](https://www.itemis.com/model-based-engineering/systems-engineering/webinar/systems-engineering-with-ai/): Erfahren Sie, welche KI-Technologien heute schon im MBSE-Alltag eingesetzt werden können. - [Whitepaper: Systems Engineering](https://www.itemis.com/model-based-engineering/systems-engineering/whitepaper/): Kostenlose Whitepapers zu modellbasiertem Systems Engineering, SysML v2, FMEA-Automatisierung und SE-Best-Practices — für Ingenieure in Automotive, Aerospace und Defence. - [10 Ways to Improve Systems Engineering](https://www.itemis.com/model-based-engineering/systems-engineering/whitepaper/10-ways-to-improve-systems-engineering/): Zehn evidenzbasierte Praktiken für Systems Engineers, die bessere Produkte liefern wollen — von Einstellung und Anforderungsdisziplin bis zu modellbasierten Ansätzen, Tooling und kontinuierlicher Verbesserung. Kostenloses Whitepaper von Dr. David Akehurst. - [AI-Assisted ASPICE Compliance](https://www.itemis.com/model-based-engineering/systems-engineering/whitepaper/ai-assisted-aspice-compliance/): Wie Knowledge Graphs und LLM Agenten die ASPICE-Prozessbewertung automatisieren: zweistufige Konsistenzprüfung, fünf spezialisierte Agent-Skills und eine Kosten-Nutzen-Analyse mit dem Ergebnis: von 23 Wochen auf 6. Kostenlos von Benjamin Alders, itemis. - [From SysML v1 to SysML v2](https://www.itemis.com/model-based-engineering/systems-engineering/whitepaper/from-sysml-v1-to-sysml-v2/): Konzeptioneller Migrationsleitfaden für MBSE-Praktiker: das Definition/Usage-Prinzip, Ports und Pins, Beziehungen, Konnektoren, n-äre Verbindungen und praktische Migrationsempfehlungen. Kostenlos von Benjamin Alders, itemis. - [MBSE with Natural Language](https://www.itemis.com/model-based-engineering/systems-engineering/whitepaper/mbse-with-natural-language/): Wie Natural Language Processing ermöglicht, MBSE ohne Erlernen der SysML-v2-Syntax zu betreiben — formale Modelle aus Requirements-Management-Tools, INCOSE- und ASPICE-4.0-konform. Kostenloses Whitepaper. - [Toolchain Integration: Werkzeuge, die perfekt zusammenspielen](https://www.itemis.com/model-based-engineering/toolchain-integration/): itemis ANALYZE als Best-of-Breed-Integrationsplattform, Werkzeugauswahl, individuelle Werkzeuganpassungen und Werkzeugintegration - [Webinare](https://www.itemis.com/model-based-engineering/toolchain-integration/webinar/): Webinare zur Toolchain Integration: Live-Termine und Aufzeichnungen zu Enterprise-Architect-Anbindung und Werkzeugketten – kostenlos von itemis. - [Connecting the Dots](https://www.itemis.com/model-based-engineering/toolchain-integration/webinar/connecting-the-dots/): Erfahren Sie, wie dynamische TARAs und verknüpfte Threat Intelligence das Risikomanagement in der Cybersicherheit verbessern. - [Referenzen](https://www.itemis.com/referenzen/): Vom Mittelständler bis zum Großkonzern – itemis schafft auf besondere Weise Mehrwert für Projekte und Teams, weit über den beauftragten Scope hinaus. - [Xtext-DSL reduziert tausende Codezeilen auf eine](https://www.itemis.com/referenzen/atruvia/) - [Drei Vollzeitstellen eingespart durch eAU-Automatisierung](https://www.itemis.com/referenzen/avitea/) - [Automotive-SPICE-Toolkette statt Excel-Matrizen](https://www.itemis.com/referenzen/bauerhin/) - [IoT-Nachrüstung für 20 Hallentore am Hamburger Hafen](https://www.itemis.com/referenzen/blg-logistics/) - [Effiziente Zustandsautomaten für Haushaltsgeräte](https://www.itemis.com/referenzen/bsh/) - [Moderne Vertriebsplattform für die Deutsche Bahn](https://www.itemis.com/referenzen/db-fernverkehr/) - [itemis CREATE für fortschrittliche Medizingeräte](https://www.itemis.com/referenzen/draeger/): itemis Erfolgsstory ➡️ Entwicklungsprozess durch effiziente Code-Generierung ✔️ Herangehensweise ✔️ Lösung ➡️ Lesen Sie hier mehr! - [Grafische Zustandsmaschinen nativ in ASCET-DEVELOPER](https://www.itemis.com/referenzen/etas/) - [EPS: Sicherheitskritische Systementwicklung für Forvia Hella](https://www.itemis.com/referenzen/forvia-hella/) - [KOSTAL schließt ASPICE-Assessment erfolgreich ab mit itemis ANALYZE](https://www.itemis.com/referenzen/kostal-aspice/): Kostal schließt ASPICE Assessment mit itemis ANALYZE erfolgreich ab. - [EA-Bridge schließt Lücke in KOSTALs AUTOSAR-Toolkette](https://www.itemis.com/referenzen/kostal/): KOSTAL integriert dank itemis bidirektionale UML-Modellierung nahtlos in den bestehenden Enterprise-Architect-Workflow. - [C++-Code aus grafischen Zustandsautomaten](https://www.itemis.com/referenzen/magnotherm/) - [Plattformunabhängiger C-Code für Motorsteuerungs-Firmware](https://www.itemis.com/referenzen/man-energy-solutions/) - [Offline-App für Felddokumentation zur Erntesaison](https://www.itemis.com/referenzen/odas/) - [Web-Umstieg für die Banksteuerungssoftware von parcIT](https://www.itemis.com/referenzen/parcit/) - [Portal-Frontend für die DAM-Plattform von Pixelboxx](https://www.itemis.com/referenzen/pixelboxx/) - [Maßgeschneiderte Software für den Angebotsprozess](https://www.itemis.com/referenzen/remondis/) - [Cross-Plattform-App für Bluetooth-Hygienespülungen](https://www.itemis.com/referenzen/tece/) - [Vom Monolithen zu agilen Self-Contained Systems](https://www.itemis.com/referenzen/thalia/) - [Versicherungslogik direkt in ausführbaren C-Code](https://www.itemis.com/referenzen/zurich/) - [Über itemis](https://www.itemis.com/ueber-uns/): itemis – seit 2003 Softwareunternehmen mit Herz. Lernen Sie unsere Geschichte, unsere Werte und die Menschen hinter unseren Produkten kennen. - [Über Dr. Alexander Nyßen](https://www.itemis.com/ueber-uns/alexander-nyssen/): Dr. Alexander Nyßen ist Executive Vice President Digital Engineering bei itemis. Dr. Alexander Nyßen ist seit 2003 auf Model-Based Systems Engineering… - [Über Andreas Mülder](https://www.itemis.com/ueber-uns/andreas-muelder/): Andreas Mülder ist Principal Software Engineer bei itemis. Andreas Mülder ist Principal Software Engineer bei itemis und als technischer Projektleiter für… - [Über Arne Deutsch](https://www.itemis.com/ueber-uns/arne-deutsch/): Arne Deutsch ist Principal Engineer bei itemis. Mit über 20 Jahren Erfahrung in der Softwareentwicklung, davon 9 bei itemis als Principal Engineer, hat… - [Über Axel Terfloth](https://www.itemis.com/ueber-uns/axel-terfloth/): Axel Terfloth ist Principal Engineer bei itemis. Axel Terfloth ist Principal Engineer bei itemis mit Schwerpunkt auf modellbasierter und modellgetriebener… - [Über Benjamin Alders](https://www.itemis.com/ueber-uns/benjamin-alders/): Benjamin Alders ist Principal Systems Engineer bei itemis. Als Principal Systems Engineer bei itemis fokussiert sich Benjamin Alders auf MBSE, Functional… - [Über Christoph Hess](https://www.itemis.com/ueber-uns/christoph-hess/): Christoph Hess ist Head of Artificial Intelligence bei itemis. Christoph Hess ist Head of Artificial Intelligence bei itemis und seit 2021 auf die… - [Über Dirk Leopold](https://www.itemis.com/ueber-uns/dirk-leopold/): Dirk Leopold ist Head of Compliance Intelligence bei itemis. Dirk Leopold schlägt die Brücke zwischen komplexen Engineering-Anforderungen und… - [Über Florian Antony](https://www.itemis.com/ueber-uns/florian-antony/): Florian Antony ist Principal Software Engineer & IT Consultant bei itemis. Florian Antony ist Principal Software Engineer und IT Consultant bei itemis.… - [Über Gunther Bachmann](https://www.itemis.com/ueber-uns/gunther-bachmann/): Gunther Bachmann ist Senior Expert & Team Lead bei itemis. Gunther Bachmann ist Senior Expert & Team Lead und seit 2013 bei der itemis AG mit dem Fokus… - [Über Holger Schill](https://www.itemis.com/ueber-uns/holger-schill/): Holger Schill ist Executive Vice President Cloud & Enterprise bei itemis. Holger Schill ist Executive Vice President Cloud & Enterprise bei itemis. Seit… - [Über Jens Bühl](https://www.itemis.com/ueber-uns/jens-buehl/): Jens Bühl ist Product Owner bei itemis. Jens Bühl ist Product Owner bei itemis und ist seit 2019 auf Cyber-Security-Engineering sowie modellbasierte… - [Über Jens Wagener](https://www.itemis.com/ueber-uns/jens-wagener/): Jens Wagener ist Gründer und Vorstandsvorsitzender bei itemis. Jens hat die itemis AG vor über zwanzig Jahren gegründet und führt sie seither als… - [Über Jonathan Mohring](https://www.itemis.com/ueber-uns/jonathan-mohring/): Jonathan Mohring ist Präsident, itemis Inc. bei itemis. Jonathan Möhring ist der Präsident von itemis Inc. in den USA. Vor seiner Zeit bei itemis… - [Über Karsten Thoms](https://www.itemis.com/ueber-uns/karsten-thoms/): Karsten Thoms ist Principal Software Engineer bei itemis. Karsten Thoms ist Principal Software Engineer bei itemis mit mehr als 20 Jahren Erfahrung. Er… - [Über Dr. Klaus Birken](https://www.itemis.com/ueber-uns/klaus-birken/): Dr. Klaus Birken ist Principal Expert bei itemis. Dr. Klaus Birken ist Principal Expert bei itemis mit Fokus auf kundenspezifischen… - [Über Lennart Wilms](https://www.itemis.com/ueber-uns/lennart-wilms/): Lennart Wilms ist Sales Director bei itemis. Als Sales Director ist Lennart die erste Anlaufstelle für Unternehmen, die ihre digitale Zukunft und komplexe… - [Über Dr. Patrick Könemann](https://www.itemis.com/ueber-uns/patrick-koenemann/): Dr. Patrick Könemann ist Principal Engineer & Consultant bei itemis. Dr. Patrick Könemann ist Principal Engineer und Consultant bei itemis und seit 2011… - [Über Prof. Patrick Mäder](https://www.itemis.com/ueber-uns/patrick-maeder/): Prof. Patrick Mäder ist Professor für Software Engineering, TU Ilmenau bei itemis. Patrick Mäder ist Professor für Software Engineering an der Technischen… - [Über Philipp Riegger](https://www.itemis.com/ueber-uns/philipp-riegger/): Philipp Riegger ist Senior Software Developer bei itemis. Philipp Riegger ist Senior Software Developer bei itemis und spezialisiert auf Cloud-native… - [Über Pierre Dammé](https://www.itemis.com/ueber-uns/pierre-damme/): Pierre Dammé ist Principal Automotive Systems Engineer bei itemis. Als Principal Automotive Systems Engineer bei itemis setzt Pierre Dammé seine über… - [Über Rainer Klute](https://www.itemis.com/ueber-uns/rainer-klute/): Rainer Klute ist Qualitätsmanagementbeauftragter & Technical Writer bei itemis. Rainer Klute ist Qualitätsmanagementbeauftragter bei itemis und… - [Über Robin Herrmann](https://www.itemis.com/ueber-uns/robin-herrmann/): Robin Herrmann ist Software Engineer bei itemis. Robin Herrmann arbeitet seit 2018 als Software Engineer bei itemis in Lünen. Er hat einen… - [Über Sandra Wagener](https://www.itemis.com/ueber-uns/sandra-wagener/): Sandra Wagener ist Content & Communication Lead bei itemis. Sandra Wagener ist Content & Communication Lead bei itemis. Sie ist seit 2012 im Unternehmen… - [Über Sebastian Ruppel](https://www.itemis.com/ueber-uns/sebastian-ruppel/): Sebastian Ruppel ist Senior Systems Engineer bei itemis. Sebastian Ruppel ist Senior Systems Engineer bei itemis und blickt auf insgesamt 10 Jahre… - [Über Dr. Stephan Eberle](https://www.itemis.com/ueber-uns/stephan-eberle/): Dr. Stephan Eberle ist CTO/CIO bei itemis. Dr. Stephan Eberle ist CTO/CIO der itemis AG und treibt die Transformation des Unternehmens hin zu einer… - [Webinar-Aufzeichnungs](https://www.itemis.com/webinar-aufzeichnung/) ## English - [itemis – Software Engineering for Compliance, Model-Based Engineering and Enterprise IT](https://www.itemis.com/en/): itemis develops software and tools for compliance engineering (ISO 21434, CRA, ISO 26262), model-based development and custom enterprise applications – for regulated industries in Europe and the USA. - [About itemis](https://www.itemis.com/en/about-us/): itemis – software company with heart since 2003. Learn about our history, our values and the people behind our products. - [About Dr. Alexander Nyßen](https://www.itemis.com/en/about-us/alexander-nyssen/): Dr. Alexander Nyßen is Executive Vice President Digital Engineering at itemis. Dr. Alexander Nyßen has specialised in Model-Based Systems Engineering… - [About Andreas Mülder](https://www.itemis.com/en/about-us/andreas-muelder/): Andreas Mülder is Principal Software Engineer at itemis. Andreas Mülder is Principal Software Engineer at itemis, responsible as technical project lead… - [About Arne Deutsch](https://www.itemis.com/en/about-us/arne-deutsch/): Arne Deutsch is Principal Engineer at itemis. With over 20 years of experience in software development, including 9 at itemis as a Principal Engineer,… - [About Axel Terfloth](https://www.itemis.com/en/about-us/axel-terfloth/): Axel Terfloth is Principal Engineer at itemis. Axel Terfloth is Principal Engineer at itemis AG with a focus on model-based and model-driven development… - [About Benjamin Alders](https://www.itemis.com/en/about-us/benjamin-alders/): Benjamin Alders is Principal Systems Engineer at itemis. As Principal Systems Engineer at itemis, Benjamin Alders focuses on MBSE, Functional Safety,… - [About Christoph Hess](https://www.itemis.com/en/about-us/christoph-hess/): Christoph Hess is Head of Artificial Intelligence at itemis. Christoph Hess is Head of Artificial Intelligence at itemis and has been specialising since… - [About Dirk Leopold](https://www.itemis.com/en/about-us/dirk-leopold/): Dirk Leopold is Head of Compliance Intelligence at itemis. Dirk Leopold bridges complex engineering requirements and cybersecurity standards in the… - [About Florian Antony](https://www.itemis.com/en/about-us/florian-antony/): Florian Antony is Principal Software Engineer & IT Consultant at itemis. Florian Antony is Principal Software Engineer and IT Consultant at itemis. His… - [About Gunther Bachmann](https://www.itemis.com/en/about-us/gunther-bachmann/): Gunther Bachmann is Senior Expert & Team Lead at itemis. Gunther Bachmann is Senior Expert & Team Lead at itemis AG and has been with the company since… - [About Holger Schill](https://www.itemis.com/en/about-us/holger-schill/): Holger Schill is Executive Vice President Cloud & Enterprise at itemis. Holger Schill is Executive Vice President Cloud & Enterprise at itemis. Since… - [About Jens Bühl](https://www.itemis.com/en/about-us/jens-buehl/): Jens Bühl is Product Owner at itemis. Jens Bühl is Product Owner at itemis and has specialised in cyber security engineering and model-based threat and… - [About Jens Wagener](https://www.itemis.com/en/about-us/jens-wagener/): Jens Wagener is Founder and CEO at itemis. Jens founded itemis AG more than twenty years ago and has led the company as its CEO ever since. His… - [About Jonathan Mohring](https://www.itemis.com/en/about-us/jonathan-mohring/): Jonathan Mohring is President, itemis Inc. at itemis. Jonathan Mohring is the President of itemis Inc. in the US. Prior to itemis, he spent over 20 years… - [About Karsten Thoms](https://www.itemis.com/en/about-us/karsten-thoms/): Karsten Thoms is Principal Software Engineer at itemis. Karsten Thoms is Principal Software Engineer at itemis with more than 20 years of experience. He… - [About Dr. Klaus Birken](https://www.itemis.com/en/about-us/klaus-birken/): Dr. Klaus Birken is Principal Expert at itemis. Dr. Klaus Birken is Principal Expert at itemis, focusing on custom modelling tools and variant management.… - [About Lennart Wilms](https://www.itemis.com/en/about-us/lennart-wilms/): Lennart Wilms is Sales Director at itemis. As Sales Director, Lennart is the first point of contact for companies looking to tackle their digital future… - [About Dr. Patrick Könemann](https://www.itemis.com/en/about-us/patrick-koenemann/): Dr. Patrick Könemann is Principal Engineer & Consultant at itemis. Dr. Patrick Könemann is Principal Engineer and Consultant at itemis and has specialised… - [About Prof. Patrick Mäder](https://www.itemis.com/en/about-us/patrick-maeder/): Prof. Patrick Mäder is Professor of Software Engineering, TU Ilmenau at itemis. Patrick Mäder is Professor of Software Engineering at the Technische… - [About Philipp Riegger](https://www.itemis.com/en/about-us/philipp-riegger/): Philipp Riegger is Senior Software Developer at itemis. Philipp Riegger is a Senior Software Developer at itemis, specialising in cloud-native… - [About Pierre Dammé](https://www.itemis.com/en/about-us/pierre-damme/): Pierre Dammé is Principal Automotive Systems Engineer at itemis. As a Principal Automotive Systems Engineer at itemis, Pierre Dammé leverages over 16… - [About Rainer Klute](https://www.itemis.com/en/about-us/rainer-klute/): Rainer Klute is Quality Manager & Technical Writer at itemis. Rainer Klute is Quality Management Officer at itemis, responsible for the company's… - [About Robin Herrmann](https://www.itemis.com/en/about-us/robin-herrmann/): Robin Herrmann is Software Engineer at itemis. Robin Herrmann has been working as a Software Engineer at itemis in Lünen since 2018. He holds a master's… - [About Sandra Wagener](https://www.itemis.com/en/about-us/sandra-wagener/): Sandra Wagener is Content & Communication Lead at itemis. Sandra Wagener is Content & Communication Lead at itemis. She has been with the company since… - [About Sebastian Ruppel](https://www.itemis.com/en/about-us/sebastian-ruppel/): Sebastian Ruppel is Senior Systems Engineer at itemis. Sebastian Ruppel is Senior Systems Engineer at itemis with a total of 10 years of experience in… - [About Dr. Stephan Eberle](https://www.itemis.com/en/about-us/stephan-eberle/): Dr. Stephan Eberle is CTO/CIO at itemis. Dr. Stephan Eberle is CTO/CIO of itemis AG, driving the company's transformation into a product-driven,… - [Blog](https://www.itemis.com/en/blog/): Expert knowledge on Compliance Intelligence, Model-Based Engineering and Custom Software Development. - [](https://www.itemis.com/en/blog/compliance-intelligence/) - [Cyber Resilience Act](https://www.itemis.com/en/blog/compliance-intelligence/cyber-resilience-act/): The Cyber Resilience Act in practice: articles on requirements, deadlines and implementation of the EU regulation for secure products – from itemis security experts. - [The 7-Step Guide to the EU Cyber Resilience Act (CRA)](https://www.itemis.com/en/blog/compliance-intelligence/cyber-resilience-act/7-step-guide-cra/): Will your product still be legally sellable in Europe after December 2027? This guide shows manufacturers how to approach CRA compliance in 7 structured steps and secure EU market access. - [CRA Reporting Obligations: Anatomy of a Notification, from Hour 0 to the Final Report](https://www.itemis.com/en/blog/compliance-intelligence/cyber-resilience-act/cra-article-14-reporting-process/): CRA Article 14 reporting obligations take effect on 11 September 2026. This article walks through the complete notification process chronologically — from the initial assessment to the final report — and identifies the points where reporting processes break down in practice. - [CRA Risk Analysis in Excel: Start, Import, Scale](https://www.itemis.com/en/blog/compliance-intelligence/cyber-resilience-act/cra-risk-analysis-excel-getting-started/): Excel template for CRA risk analysis: TARA in line with ISO 21434 and IEC 62443 — how to start methodically, what you can import, and when Excel becomes the bottleneck. - [Living TARA: Why the Cyber Resilience Act Changes Your Engineering Process, Not Your Documentation](https://www.itemis.com/en/blog/compliance-intelligence/cyber-resilience-act/living-tara-cra-engineering-process/): The CRA doesn't ask for a one-time risk analysis — it demands a permanently demonstrable security engineering process. How a Living TARA and the Security Digital Thread keep your risk picture continuously current and audit-ready. - [Cyber Security](https://www.itemis.com/en/blog/compliance-intelligence/cyber-security/): Cyber security in engineering: articles on threat analysis (TARA), security by design and ISO/SAE 21434 from the practice of itemis security experts. - [Asset Identification and Impact Rating: Whose Damage Are You Actually Counting?](https://www.itemis.com/en/blog/compliance-intelligence/cyber-security/assets-impact-rating-tara/): Asset identification and impact rating supply one half of the risk value: when an element of the item becomes an asset, whose damage a damage scenario describes, why the safety rating is not security's to set alone, and what keeps ratings comparable across projects. - [Secure is Secure?! Automotive Security in the Age of Connected Vehicles](https://www.itemis.com/en/blog/compliance-intelligence/cyber-security/automotive-security-connected-vehicles/): The increased share of software solutions places high demands on Automotive Security. But what changes are coming for the industry and manufacturers? - [Item Definition: Why the First TARA Step Decides All the Others](https://www.itemis.com/en/blog/compliance-intelligence/cyber-security/item-definition-decides-tara/): The Item Definition sets the quality ceiling for the whole TARA — what abstraction level is right, why SBOM mapping forces a minimum resolution, and why a living model is the foundation for API and MCP integrations. - [Why security is one of the biggest engineering challenges ahead](https://www.itemis.com/en/blog/compliance-intelligence/cyber-security/security-biggest-engineering-challenge/): In times of Spectre and Meltdown it's totally clear that security is a big engineering challenge. Learn more about safety and security in this post. - [Security by Design in the Automotive Development Process](https://www.itemis.com/en/blog/compliance-intelligence/cyber-security/security-by-design-automotive/): In the automotive domain, security is becoming more and more important – especially for the new generations of connected, (semi-)autonomous vehicles. Learn how to develop a secure system design and which additional security challenges may arise. - [What Is a TARA? And Why a Spreadsheet Eventually Stops Being Enough](https://www.itemis.com/en/blog/compliance-intelligence/cyber-security/what-is-a-tara/): A TARA is not a threat catalogue — it is an auditable record of risk decisions: what it involves, how the process works, and when Excel reaches its limits. - [Functional Safety](https://www.itemis.com/en/blog/compliance-intelligence/functional-safety/): Functional safety explained: articles on ISO 26262, ASIL, safety cases and safe software development in regulated industries. - [Requirements Traceability](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/): Requirements traceability in practice: articles on tracing requirements, traceability strategies and tool support in engineering. - [Link Coverage 100%, ASPICE Assessment Still at Risk.](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/aspice-traceability-vs-consistency/): 100% link coverage does not mean ASPICE compliance. How a type check, a consistency check and a consistency score expose semantic inconsistencies with LLMs. - [Compliance Was Never About the Document](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/compliance-artifacts-ai/): AI can now produce TARAs, traceability matrices, and safety cases that are structurally complete and terminologically correct. That surfaces a question worth asking: what, exactly, is being verified? The problem is not AI-generated documentation. It is compliance processes that optimize for artifacts instead of the properties those artifacts were supposed to encode. - [What Is Requirements Coverage and How Can It Be Analyzed?](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/requirements-coverage-analysis/): Requirements coverage is demanded by process standards like Automotive SPICE, yet remains poorly defined. Learn what it really means and how to measure it properly. - [Requirements Traceability When Maintaining Software: Measured Benefits](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/requirements-traceability-maintenance/): An empirical study with 71 subjects shows that requirements traceability leads to 24% faster task completion and 50% more correct solutions during software maintenance. - [5 + 1 Questions a Requirements Traceability Matrix Answers](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/requirements-traceability-matrix-questions/): A requirements traceability matrix is not just a bookkeeping tool. Learn the five key questions it answers in day-to-day project work — plus one bonus question. - [How to Create a Requirements Traceability Matrix](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/requirements-traceability-matrix/): A requirements traceability matrix (RTM) is a simple table that establishes bidirectional traceability across your project. Learn what it is and how to build one in four steps. - [What Is Traceability? Benefits and Challenges in Software Development](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/software-traceability/): Traceability is more than a compliance checkbox. Learn what it means in software and systems engineering, what insights it unlocks, and what challenges come with it. - [Sit, Stay, Fetch: How to Train Your AI for ASPICE](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/train-your-ai-for-aspice/): Six guardrails for AI agents in ASPICE assessments: scripts over prompts, persisted results and progress, batching, closed questions, prohibitions, flagging. - [](https://www.itemis.com/en/blog/custom-software/) - [AI Enablement](https://www.itemis.com/en/blog/custom-software/ai-enablement/): AI enablement for companies: articles on AI-assisted software development, AI agents and the productive use of large language models. - [AI-driven Development: Why Technology Is Only Half the Battle – and How Aimlessness Leads to Failure](https://www.itemis.com/en/blog/custom-software/ai-enablement/ai-driven-development-goallessness/): AI-driven development rarely fails because of the code – it fails because of aimlessness. Why technology is only half the battle and what really determines project success. - [Horizontal Skills and Vertical Agents](https://www.itemis.com/en/blog/custom-software/ai-enablement/horizontal-skills-vertical-agents/): How to hand the bulk of software development to AI agents – and still get a result you can trust. A practitioner's look at vertical agents and horizontal skills for enterprise software teams. - [Full Stack & Cloud](https://www.itemis.com/en/blog/custom-software/full-stack/): Full-stack development in practice: articles on modern web technologies, software architecture and custom software from itemis developers. - [What to Do After Camunda 7 CE End-of-Life?](https://www.itemis.com/en/blog/custom-software/full-stack/operaton-openbpm-camunda-7-end-of-life/): Camunda 7 CE is reaching end-of-life. Operaton and the OpenBPM Platform offer a powerful open alternative – with minimal migration effort and maximum future-proofing. - [Legacy Modernization](https://www.itemis.com/en/blog/custom-software/legacy-modernization/): Legacy modernization without risk: articles on strategies, migration paths and tools to make legacy systems future-proof. - [Can the Modernization of Your Legacy System Be Automated?](https://www.itemis.com/en/blog/custom-software/legacy-modernization/can-legacy-system-modernization-be-automated/): When does automated modernization of legacy systems make sense? An analysis of the opportunities, limits, and appropriate transformation tools. - [Legacy System – Business Logic Buried in the Source Code](https://www.itemis.com/en/blog/custom-software/legacy-modernization/legacy-system-business-logic-buried-in-source-code/): Business logic and technical code in legacy systems mix over the years — with serious consequences. What this means and what you can do about it. - [How to Migrate Legacy Eclipse Applications to the Web and Visual Studio Code](https://www.itemis.com/en/blog/custom-software/legacy-modernization/migrate-legacy-eclipse-to-web-vscode/): Lessons learned from migrating itemis CREATE, a 280K LOC Eclipse-based application, to the web and Visual Studio Code over two years. - [](https://www.itemis.com/en/blog/model-based-engineering/) - [Custom Tools & DSLs](https://www.itemis.com/en/blog/model-based-engineering/custom-tools/): Custom tools for engineering: articles on tailor-made development tools, domain-specific languages (DSLs) and tool development. - [AI Agents Meet Projectional Editing: Portalon for MPS](https://www.itemis.com/en/blog/model-based-engineering/custom-tools/ai-agents-meet-mps-with-portalon/): How the Portalon plugin connects AI coding agents like Claude to the live model of a JetBrains MPS project via MCP — structurally safe edits, validation, and language-engineering skills, on your current MPS version. - [Interfaces with a Behavioral Contract: Protocol State Machines in Practice](https://www.itemis.com/en/blog/model-based-engineering/custom-tools/contract-based-software-development-franca/): Why dynamic behavior belongs in the interface contract: protocol state machines formally specify the allowed order of events – with Franca IDL as an example and a look at Dezyne, P, and session types. - [Custom Tooling on EA Models: From Model to Generated Code](https://www.itemis.com/en/blog/model-based-engineering/custom-tools/ea-bridge-custom-tooling-code-generation/): How the itemis EA Bridge provides Enterprise Architect models as stable, machine-readable data, enabling custom code generation, validation, and documentation tooling. - [Variant Management: More Than Feature Strings](https://www.itemis.com/en/blog/model-based-engineering/custom-tools/product-lines-variant-management-tight-integration/): Loosely coupling feature models to development artifacts is convenient – but it has hidden risks. This article shows the advantages of tight integration: early error detection, implicit variation points, and automatic consistency checks. - [State Machine Origami](https://www.itemis.com/en/blog/model-based-engineering/custom-tools/state-machine-origami/): How Franca IDL and itemis CREATE can be integrated to validate embedded software components against interface contracts interactively during development. - [Model-Driven Software Development](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/): Model-driven software development (MDSD): articles on code generation, state machines, DSLs and modeling tools from over 20 years of practice. - [Finite State Machine Modeling With Entry, Exit & Final States](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/advanced-state-machine-modeling-entry-exit-final-states/): How to use entry points, exit points, and final states in state machine modeling with itemis CREATE. - [Formal Error Detection on State Machines: What Works and What Doesn't](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/formal-methods-error-detection/): An unreachable transition, an unsatisfiable guard, a numeric overflow: these bugs hide in the model long before any test reveals them. A results report from two master's theses on formal error detection for state machines using symbolic execution and SMT solvers. - [An Introduction to Modeling and Language Engineering – Part 1](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/introduction-modeling-language-engineering-part-1/): What are models, abstractions, and meta models? Using LEGO® as an analogy, this article introduces the foundations of modeling and language engineering. - [An Introduction to Modeling and Language Engineering – Part 2](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/introduction-modeling-language-engineering-part-2/): Part 2 explores domain-specific languages, language workbenches such as Xtext and MPS, and the role of the language engineer in modern software development. - [Model-Driven Software Development meets Test-Driven Development](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/mdd-meets-tdd/): How to apply Test-Driven Development to model-driven software development using SCTUnit, itemis CREATE's unit testing framework for statechart models. - [How to Program a MSP430 with State Machines in 5 Minutes](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/msp430-state-machines-itemis-create/): Learn how to program an MSP430 microcontroller with state machines using itemis CREATE, fully integrated in Code Composer Studio – with automatic code generation and a graphical editor. - [Taking SCXML to the next level](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/scxml-itemis-create/): How itemis CREATE adds higher-level modeling, simulation and unit testing on top of the SCXML standard. - [Modeling with State Machines – Part 3: The Big Switch Statement](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/state-machines-big-switch-part-3/): How do modeled state machines become program code? For example with the help of a switch statement. We show how the implementation works. - [Modeling with State Machines – Part 1](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/state-machines-modelling-part-1/): How do state machines work and why should you use them? This post illustrates the modeling of a finite state machine using the example of a blind controller. - [Modeling with State Machines – Part 5: The State Pattern](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/state-machines-state-pattern-part-5/): State machines can not only be modeled. In part 5 we present the State Pattern as an implementation variant. - [Modeling with State Machines – Part 4: The State Machine as a Table](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/state-machines-table-representation-part-4/): State machines can be modeled – but how can they actually be implemented? For example with the help of state tables. - [Modeling with State Machines – Part 2: Time-Controlled Triggering of State Transitions](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/state-machines-time-transitions-part-2/): In part 2 of the series we cover time-controlled triggering of state transitions, orthogonal regions, and composite states with subdiagrams. - [Statechart Tools Compared: MathWorks Stateflow vs. IBM Rhapsody vs. itemis CREATE](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/statechart-tools-comparison-rhapsody-stateflow-itemis-create/): An honest, detailed comparison of three leading statechart tools — MathWorks Stateflow, IBM Rhapsody, and itemis CREATE — covering features, pricing, and which tool fits which team. - [How to Ensure Traceability for itemis CREATE](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/traceability-for-itemis-create/): Learn how to ensure traceability for your itemis CREATE statechart models – with tool support that scales beyond manual trace links. - [Model-Based Systems Engineering](https://www.itemis.com/en/blog/model-based-engineering/systems-engineering/): Model-based systems engineering (MBSE): articles on SysML, system modeling and introducing MBSE in product development. - [It's not MBSE when you use draw.io or Visio](https://www.itemis.com/en/blog/model-based-engineering/systems-engineering/mbse-not-drawio-visio/): Collaborative modeling workshops are valuable — but drawing pictures isn't MBSE. If you can't validate, derive, or generate from your models, you're missing the point. - [From SysML v1 to SysML v2: Is Switching Worth It?](https://www.itemis.com/en/blog/model-based-engineering/systems-engineering/sysml-v1-to-v2-worth-switching/): SysML v2 promises cleaner concepts, a textual notation, and a standard API. But does switching pay off? Pros and cons, an ROI perspective across three starting points, and an honest assessment of who should switch and who is better off staying. - [MathWorks System Composer vs. SysML Tools: Which One Fits Your Project?](https://www.itemis.com/en/blog/model-based-engineering/systems-engineering/system-composer-vs-sysml-tools/): System Composer or a SysML tool for your architecture modeling? A comparison across requirements handling, simulation, onboarding, stakeholder views, AI integration, and cost — and why the answer depends on your project. - [Toolchain Integration](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/): Toolchain integration in engineering: articles on connecting Enterprise Architect and other tools, data exchange and end-to-end toolchains. - [Choosing Your Engineering Toolbox: Best-of-Breed or All-in-One Suite?](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/best-of-breed-vs-all-in-one-engineering-toolchain/): Best-of-breed or all-in-one suite? A look at the real trade-offs in engineering toolchain strategy — and why tool suitability should always come first. - [Enterprise Architect in the Toolchain: Automated Processing of EA Models](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/ea-bridge-enterprise-architect-toolchain/): How the itemis EA Bridge turns Enterprise Architect from an isolated modelling tool into a data supplier: validation, code generation, report generation and AI reasoning, performant and platform-independent. - [Eclipse-based Code Generation for Enterprise Architect Models](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/eclipse-based-code-generation-enterprise-architect/): How Eclipse with Xtend and the Java-based EA-Bridge provides a proven alternative to EA's built-in code generation — and how the AUTOSAR Consortium uses this approach headlessly at scale. - [Eclipse-based UML Validation of Enterprise Architect Models](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/eclipse-based-uml-validation-enterprise-architect/): How the Eclipse-based EA-Bridge loads Enterprise Architect models as Eclipse UML models, reports syntactical errors, and enables custom validation rules with quick fixes. - [How Modeling Enhances Requirements Clarity and Precision](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/how-modeling-enhances-requirements-clarity-and-precision/): Transitioning from static diagrams to executable models in requirements engineering enhances precision and testability in system design. - [Tailoring Enterprise Architect with Add-ins](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/tailoring-enterprise-architect-with-add-ins/): How to extend Enterprise Architect with add-ins: model assistants, integrity checks, and installer-based rollout — and which tasks are better handled by external tools like the EA-Bridge. - [UML Profiles in Enterprise Architect Models – Example Code Generation](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/uml-profiles-enterprise-architect-code-generation/): How to use UML profiles in Enterprise Architect and how to process profiled models with the Eclipse-based EA-Bridge for code generation using Xtend. - [Careers at itemis](https://www.itemis.com/en/careers/): Software jobs at itemis: 100% remote, 4+1 professional development model, permanent contract. Looking for software developers, engineers, and cybersecurity experts. Apply now. - [Compliance Intelligence](https://www.itemis.com/en/compliance-intelligence/): Tools and consulting for the central compliance standards of modern product development — cybersecurity, functional safety, requirements traceability. - [EU Cyber Resilience Act (CRA): Compliance Roadmap to 2027](https://www.itemis.com/en/compliance-intelligence/cyber-resilience-act/): CRA deadlines 2026 and 2027, scope, roadmap and implementation with itemis SECURE and the CRAIG community. The self-assessment for manufacturers of products with digital elements. - [CRA GAP Analysis: Free Online Check](https://www.itemis.com/en/compliance-intelligence/cyber-resilience-act/gap-analyse/): 17 questions to your CRA maturity level: assess your implementation status for the EU Cyber Resilience Act across 7 areas — free, no registration, radar diagram. - [CRA Gap Checklist: 75 Checkpoints as an Excel Template](https://www.itemis.com/en/compliance-intelligence/cyber-resilience-act/gap-checklist/): Free Excel template for the full CRA gap analysis: 75 checkpoints across eight areas, maturity rating based on the ENISA model, an evaluation tab, and an action plan — for manufacturers of digital products. - [TARA Excel Template for CRA Risk Analysis](https://www.itemis.com/en/compliance-intelligence/cyber-resilience-act/tara-excel-template/): Free Excel template for cybersecurity risk analysis under the Cyber Resilience Act: assets, damage scenarios, threat catalog, attack steps, and controls — AFL, IL, and RL are calculated automatically. - [ISO/SAE 21434 & IEC 62443: Cybersecurity for Automotive and Industry](https://www.itemis.com/en/compliance-intelligence/cyber-security/): Guide to ISO/SAE 21434 (TARA, UNECE R155) and IEC 62443 (zones, conduits, security level). Implementation with itemis SECURE, one tool for both standards. - [Webinars](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/): Webinars on cyber security in engineering: live sessions and recordings on TARA, ISO/SAE 21434 and security by design – free from itemis. - [Automating CSMS for Type Approvals with Model-Based TARAs and Knowledge-Graphs](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/automating-csms-for-type-approvals/): How model-based TARA tools and knowledge graphs enable CSMS automation for type approvals. The 20-50-90 Rule explained. - [Beyond 2024: Pioneering Risk Management in Vehicle Cybersecurity](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/beyond-2024/): Current challenges in risk management for OEMs and suppliers, best-of-breed toolchains, and the value of traceability and knowledge graphs. - [SECURE & INCYDE - Charging Up Cybersecurity](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/charging-up-cybersecurity/): Cybersecurity challenges of the smart charging infrastructure and TARAs for electric vehicles. Learn how to secure the EV ecosystem. - [Cybersecurity and Risk Management: Best Practices for CFOs and Auditors](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/cybersecurity-and-risk-management/): Best practices for TARA management and cybersecurity risk controls for CFOs, Chief Compliance Officers, and auditors of connected products. - [Reacting to Vulnerabilities via Threat and Control Catalogs for ISO/SAE 21434](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/deep-dive-threat-catalogs-for-iso-21434/): An overview of threat and control catalogs that accelerate your ISO/SAE 21434 compliant TARAs throughout the entire vehicle lifespan. - [ISO/SAE 21434: What Motorcycle and ATV Companies Need to Know](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/iso-sae-21434-what-motorcycle-and-atv-companies-need-to-know/): UN Regulation No. 155 hits motorcycle manufacturers on July 1st 2029. Learn the challenges and compliance strategies that matter most. - [ISO/SAE 21434 and UN R155: Lifecycle Management Challenges](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/iso-sae-21434/): The most important aspects and biggest challenges of UN Regulation 155 and ISO/SAE 21434 regarding product lifecycle management. - [itemis SECURE AI-Powered TARA: From Compliance to Competitive Advantage](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/itemis-secure-ai-powered-tara/): Learn how AI-powered TARA creation with itemis SECURE accelerates your cybersecurity compliance. Watch the recording now. - [itemis SECURE Goes Cloud](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/itemis-secure-goes-cloud/): itemis SECURE is now available as a web version. Collaborate on cybersecurity projects in real time from any device. Watch the recording now. - [Next-Level Vehicle Risk Management: Automated Vulnerability to TARA Process](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/next-level-vehicle-risk-management/): Learn how Dynamic-TARA connects automated vulnerability detection with comprehensive threat analysis. Watch the recording now. - [Summer 2024 Is Coming: Efficiently Managing the Coming TARA Wave](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/summer-2024-managing-the-coming-tara-wave/): How to efficiently manage the TARA process and apply the 20-50-90 Rule to significantly reduce your company's cybersecurity spend. - [TARA Automation for Automotive Cybersecurity](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/tara-automation/): How TARA automation with itemis SECURE (formerly YAKINDU Security Analyst) makes automotive cybersecurity processes fundamentally more efficient. - [TARA Deep Dive: Lifecycle Management Challenges from UN R155 and ISO/SAE 21434](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/tara-deep-dive/): A deep dive into TARA requirements from UN R155 and ISO/SAE 21434 — key aspects and challenges for the entire automotive industry. - [Towards an Integrated Product Security Management for Software-Defined Vehicles](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/towards-an-integrated-product-security-management-for-software-defined-vehicles/): How software-defined vehicles demand a holistic approach to security. Learn about shortened development cycles and secure OTA updates. - [Transitioning Legacy TARAs for ISO/SAE 21434](https://www.itemis.com/en/compliance-intelligence/cyber-security/webinar/transitioning-legacy-taras-for-iso-sae-21434/): Why you should transition your TARAs from spreadsheets to automated processes and how to harmonize your TARA landscape with OEMs and suppliers. - [Whitepaper: Cyber Security](https://www.itemis.com/en/compliance-intelligence/cyber-security/whitepaper/): Free whitepapers on ISO/SAE 21434, IEC 62443 and cybersecurity lifecycle management — for automotive OEMs, Tier-1 suppliers and railway manufacturers. - [Cyber Risk Assessment for Beginners](https://www.itemis.com/en/compliance-intelligence/cyber-security/whitepaper/cyber-risk-assessment-for-beginners/): 7-part guide to systematic cyber risk assessment: risk definition, MoRA methodology, damage and threat scenarios, risk matrix, and living TARA. Free by Dirk Leopold, itemis. - [itemis SECURE Lifecycle Integrations](https://www.itemis.com/en/compliance-intelligence/cyber-security/whitepaper/cybersecurity-lifecycle-integration/): How itemis SECURE and itemis ANALYZE create a Living Digital Thread for automotive cybersecurity — transforming the TARA from a static compliance document into a dynamic steering instrument. Free whitepaper. - [The Future Challenges of ISO SAE 21434](https://www.itemis.com/en/compliance-intelligence/cyber-security/whitepaper/future-challenges-iso-sae-21434/): A comprehensive guide to implementing ISO/SAE 21434 — from organizational cybersecurity management (Clause 5) through TARA (Clause 15), written by itemis and Deloitte. Free whitepaper. - [Industrial & Automotive Functional Safety: ISO 26262 & IEC 61508](https://www.itemis.com/en/compliance-intelligence/functional-safety/): ISO 26262, IEC 61508 and functional safety for safety-critical systems in automotive and industrial applications. - [Webinars](https://www.itemis.com/en/compliance-intelligence/functional-safety/webinar/): Webinars on functional safety: live sessions and recordings on ISO 26262, ASIL and safety cases – free from the itemis experts. - [Automotive SPICE 4.0: Clarifying the Impact on Hard- & Software Development](https://www.itemis.com/en/compliance-intelligence/functional-safety/webinar/automotive-spice-4-0/): Deep dive into Automotive SPICE 4.0 with leading experts. Learn how Version 4.0 impacts your hardware and software development processes. - [itemis ANALYZE ASPICE in 5 Hours instead of 5 Weeks](https://www.itemis.com/en/compliance-intelligence/functional-safety/webinar/itemis-analyze-aspice-in-5-hours-instead-of-5-weeks/): Learn how itemis ANALYZE reduces ASPICE assessments from five weeks to five hours — without compromising quality or compliance. - [itemis ANALYZE Goes Cloud: Agentic Engineering Intelligence](https://www.itemis.com/en/compliance-intelligence/functional-safety/webinar/itemis-analyze-goes-cloud/): Learn how itemis ANALYZE in the cloud breaks down data silos and empowers AI assistants with real engineering context for audit-proof decisions. - [Whitepaper: Functional Safety & Cyber Security](https://www.itemis.com/en/compliance-intelligence/functional-safety/whitepaper/): Free whitepapers on ISO 26262, ISO/SAE 21434 and enterprise-wide compliance — for OEMs and Tier-1 suppliers. - [Automatic Generation of a Design-FMEA](https://www.itemis.com/en/compliance-intelligence/functional-safety/whitepaper/automatic-fmea-generation/): How to automatically generate a complete design FMEA from existing engineering work products — a natural step in model-based systems engineering. Free whitepaper by itemis. - [Cohesion Without Disruption](https://www.itemis.com/en/compliance-intelligence/functional-safety/whitepaper/cohesion-without-disruption/): How leading OEMs and Tier-1 suppliers unite Functional Safety (ISO 26262) and Cyber Security (ISO/SAE 21434) enterprise-wide — without replacing their local best-of-breed toolchains. - [Unabhängigkeit als prüfbare Eigenschaft](https://www.itemis.com/en/compliance-intelligence/functional-safety/whitepaper/unabhaengigkeit-als-pruefbare-eigenschaft/): How independence in ASIL decomposition can be machine-verified: graph-theoretic coupling detection, defeater semantics, and continuous assurance with LLM agents and itemis ANALYZE. Free by Sebastian Ruppel, itemis. - [Requirements Traceability: End-to-End Traceability for Regulated Industries](https://www.itemis.com/en/compliance-intelligence/requirements-traceability/): Comprehensive, auditable requirements traceability for Automotive, Defence, Industrial and MedTech: from requirements through architecture to tests, validation and releases. - [Requirements Traceability Matrix: the Excel Example](https://www.itemis.com/en/compliance-intelligence/requirements-traceability/rtm-excel-template/): Free Excel example of a requirements traceability matrix: three link matrices from customer requirement to test case, an accumulated view, and coverage calculation with realized status. - [Webinars](https://www.itemis.com/en/compliance-intelligence/requirements-traceability/webinar/): Webinars on requirements traceability: live sessions and recordings on tracing requirements and traceability tools – free from itemis. - [Empowering Domain Experts: Web-Based Modeling with Modelix](https://www.itemis.com/en/compliance-intelligence/requirements-traceability/webinar/empowering-domain-experts/): Learn how Modelix makes domain-specific languages accessible to non-developers through modern web applications that integrate with established developer tools. - [Lifecycle Management Challenges under ISO/SAE 21434](https://www.itemis.com/en/compliance-intelligence/requirements-traceability/webinar/lifecycle-management-challenges/): Learn the key lifecycle management requirements of ISO/SAE 21434 and UN Regulation 155 and how to ensure cybersecurity across the entire vehicle lifespan. - [Contact](https://www.itemis.com/en/contact/): Get in touch with itemis. We're happy to help with questions about our services, products, and projects — quickly and directly. - [Custom Software Development for Enterprise](https://www.itemis.com/en/custom-software/): Tailored software development for enterprise customers — full-stack, AI-assisted, agile. For banks, insurers, logistics and industry. - [AI Enablement: AI That Actually Works in Your Organisation](https://www.itemis.com/en/custom-software/ai-enablement/): itemis enables organisations to use AI independently and sustainably: process analysis, tool selection, integration, data sovereignty and people enablement. - [Webinars](https://www.itemis.com/en/custom-software/ai-enablement/webinar/): Webinars on AI in business: live sessions and recordings on AI-assisted software development and AI agents – free from the itemis experts. - [Smart Move - AI Use Cases in Transportation and Mobility](https://www.itemis.com/en/custom-software/ai-enablement/webinar/smart-move/): Discover concrete AI potential in the mobility sector with real-world examples from Deutsche Bahn and itemis experts. - [Whitepapers: AI Enablement](https://www.itemis.com/en/custom-software/ai-enablement/whitepaper/): Free whitepapers on local AI, open-weight models, fine-tuning and data sovereignty, written for organisations that want to run AI productively and under their own control. - [Local AI That Competes](https://www.itemis.com/en/custom-software/ai-enablement/whitepaper/local-ai-that-competes/): When does an open-weight model in your own infrastructure beat a frontier API? Five engineering levers and a 90-day pilot plan. Free whitepaper by Christoph Hess. - [Seasoned Senior Full-Stack Teams for Cloud-Native Development](https://www.itemis.com/en/custom-software/full-stack/): Seasoned senior teams for full-stack development, cloud migration and microservices: from regulated infrastructure to Sovereign Cloud compliant with Gaia-X standards. - [Webinars](https://www.itemis.com/en/custom-software/full-stack/webinar/): Webinars on full-stack and cloud-native development from itemis: live sessions and recordings on migration, enterprise Java and modern architectures – free. - [Camunda 7 is over](https://www.itemis.com/en/custom-software/full-stack/webinar/camunda-7-is-over/): Camunda 7 has reached end of life. Watch the recording and evaluate your migration options with experts from itemis and Haulmont. - [Legacy Code Modernization with AI Support](https://www.itemis.com/en/custom-software/legacy-modernization/): Risk-minimised legacy migration: migrate COBOL, PL/I & mainframe step by step, with proven functional equivalence, to Java & PostgreSQL. ISO 9001. - [Webinars](https://www.itemis.com/en/custom-software/legacy-modernization/webinar/): Webinars on legacy modernization: live sessions and recordings on migration strategies and legacy system analysis – free from itemis. - [Finance and Insurance - Successful Migration and Growth in the Cloud](https://www.itemis.com/en/custom-software/legacy-modernization/webinar/erfolgreiche-migration-und-wachstum-in-der-cloud/): Learn how finance and insurance companies migrate legacy systems to the cloud successfully and achieve significant growth. - [Digital Finance and Insurance: Legacy Systems in Transition](https://www.itemis.com/en/custom-software/legacy-modernization/webinar/systeme-im-wandel/): Discover how finance and insurance companies modernize their legacy systems and build future-proof architectures. - [KI-gestützte Modernisierung von Legacy-Kernsystemen](https://www.itemis.com/en/custom-software/legacy-modernization/whitepaper/ki-gestuetzte-modernisierung-von-legacy-kernsystemen/): The risk-based approach model for legacy modernisation: discovery, equivalence proof, spec-driven refactoring and go-live for COBOL, PL/I and RPG. With business case and decision checklist. Free from itemis. - [Glossary](https://www.itemis.com/en/glossary/): Technical terms from functional safety, cybersecurity, requirements traceability, model-based engineering and software development — explained precisely by the itemis experts. - [AI Agent](https://www.itemis.com/en/glossary/ai-agent/): An AI agent is a software system that, based on an LLM, autonomously plans and executes multi-step tasks: it uses tools such as file systems, databases or APIs, evaluates intermediate results and works iteratively towards a given goal — under human oversight. - [ALM (Application Lifecycle Management)](https://www.itemis.com/en/glossary/alm/): ALM (Application Lifecycle Management) refers to the coordinated management of the entire software lifecycle — from requirements through design, implementation and testing to release and maintenance — including the processes and tools that connect these disciplines. - [ASIL (Automotive Safety Integrity Level)](https://www.itemis.com/en/glossary/asil/): ASIL (Automotive Safety Integrity Level) is the risk classification of ISO 26262 for safety-related E/E systems in vehicles. The four levels ASIL A to D determine how rigorous the development, evidence and testing of a function must be. - [Attack Feasibility](https://www.itemis.com/en/glossary/attack-feasibility/): According to ISO/SAE 21434, the attack feasibility rates how easily an attack path can be carried out. The result is the attack feasibility level (AFL), which together with the impact level determines the risk level of a risk. - [Attack Path](https://www.itemis.com/en/glossary/attack-path/): According to ISO/SAE 21434, an attack path is the sequence of concrete attack steps with which an attacker can realise a threat scenario. The standard requires an attack path analysis for every threat scenario; the paths are rated via the attack feasibility. - [Attack Tree](https://www.itemis.com/en/glossary/attack-tree/): An attack tree decomposes an attacker’s goal hierarchically into sub-goals and concrete attack steps. In the TARA according to ISO/SAE 21434, attack trees are used to model attack paths systematically and to rate their feasibility in a traceable way. - [Automotive SPICE (ASPICE)](https://www.itemis.com/en/glossary/automotive-spice/): Automotive SPICE (ASPICE) is the automotive industry’s process assessment model for evaluating the maturity of development processes for cyber physical systems. Assessments rate processes on capability levels 0 to 5 — many OEMs require level 2 or 3 from their suppliers. - [AUTOSAR (AUTomotive Open System ARchitecture)](https://www.itemis.com/en/glossary/autosar/): AUTOSAR (AUTomotive Open System ARchitecture) is a worldwide development partnership of vehicle manufacturers, suppliers and tool vendors that defines a standardized software architecture for automotive ECUs. Its goal is to make software components reusable across manufacturer and platform boundaries. - [Best of Breed](https://www.itemis.com/en/glossary/best-of-breed/): Best of breed refers to the tool strategy of using the best specialized tool for each engineering task instead of relying on the all-in-one suite of a single vendor. The price of specialization is the integration effort between the tools. - [BPMN (Business Process Model and Notation)](https://www.itemis.com/en/glossary/bpmn/): BPMN (Business Process Model and Notation) is the graphical notation standard for modeling business processes standardized by the OMG. BPMN 2.0 models are equally readable for business and IT and directly executable by workflow engines — the diagram is both documentation and executable process. - [CAL (Cybersecurity Assurance Level)](https://www.itemis.com/en/glossary/cal/): The CAL (Cybersecurity Assurance Level) is the classification scheme of ISO/SAE 21434 with four levels (CAL 1–4). It determines the rigour with which the cybersecurity activities of an item are carried out — for example the depth of verification — but not which technical measures are to be implemented. - [Cloud Migration](https://www.itemis.com/en/glossary/cloud-migration/): Cloud migration refers to moving applications, data and infrastructure from your own data center to a cloud environment. The spectrum ranges from an unchanged move (rehosting) to a cloud-native rebuild — which path is viable depends on the application, regulation and economics. - [CSMS (Cyber Security Management System)](https://www.itemis.com/en/glossary/csms/): A CSMS (Cyber Security Management System) bundles the processes, roles and responsibilities with which a vehicle manufacturer identifies, assesses and treats cybersecurity risks across the entire lifecycle. UNECE R155 makes an audited CSMS a prerequisite for type approval. - [CVD (Coordinated Vulnerability Disclosure)](https://www.itemis.com/en/glossary/cvd/): CVD (Coordinated Vulnerability Disclosure) is the coordinated process through which security researchers and other reporters report vulnerabilities to the manufacturer, with details published only after a remedy is available. The EU Cyber Resilience Act makes a CVD policy a manufacturer obligation. - [Cyber Resilience Act (CRA)](https://www.itemis.com/en/glossary/cyber-resilience-act/): The Cyber Resilience Act (CRA) is the EU regulation with binding cybersecurity minimum requirements for products with digital elements. From 11 September 2026, reporting obligations apply for actively exploited vulnerabilities; from 11 December 2027, all requirements apply, including CE marking. - [Cybersecurity Concept](https://www.itemis.com/en/glossary/cybersecurity-concept/): The cybersecurity concept is the work product that concludes the concept phase of ISO/SAE 21434: the cybersecurity requirements of the item and the requirements for its operational environment, derived from the cybersecurity goals and allocated to the architecture. - [Cybersecurity Goal](https://www.itemis.com/en/glossary/cybersecurity-goal/): A cybersecurity goal is a top-level security requirement that results from the risk treatment of the TARA in the concept phase according to ISO/SAE 21434. It addresses one or more threat scenarios and is implemented during development through cybersecurity requirements. - [Damage Scenario](https://www.itemis.com/en/glossary/damage-scenario/): According to ISO/SAE 21434, a damage scenario describes the adverse consequences that occur when a security property of an asset is violated. It is rated in four categories — safety, financial, operational, privacy — and provides the impact level for risk determination. - [DSL (Domain-Specific Language)](https://www.itemis.com/en/glossary/dsl/): A DSL (Domain-Specific Language) is a programming or modeling language tailored to a clearly delimited subject area. Instead of being universally applicable like Java or C, it captures the concepts, rules and vocabulary of exactly one domain. - [FMEA (Failure Mode and Effects Analysis)](https://www.itemis.com/en/glossary/fmea/): FMEA (Failure Mode and Effects Analysis) is a systematic, inductive analysis method: it identifies possible failure modes of a system, evaluates their causes and effects and prioritises countermeasures — before the failures occur in the product. - [Functional Safety](https://www.itemis.com/en/glossary/functional-safety/): Functional safety is the part of a system's safety that depends on the correct functioning of safety-related E/E systems. The goal is the absence of unreasonable risks caused by malfunctions. The basic standard is IEC 61508; in the automotive domain, ISO 26262 applies. - [HARA (Hazard Analysis and Risk Assessment)](https://www.itemis.com/en/glossary/hara/): The HARA (Hazard Analysis and Risk Assessment) is the hazard analysis and risk assessment according to ISO 26262-3. It rates the hazards of a vehicle system by severity, exposure and controllability, derives the ASIL from this and defines the top-level safety goals. - [IEC 61508 (Basic Standard for Functional Safety)](https://www.itemis.com/en/glossary/iec-61508/): IEC 61508 is the cross-industry basic standard for the functional safety of electrical, electronic and programmable electronic (E/E/PE) systems. It defines the safety lifecycle and the levels SIL 1 to SIL 4 and is the basis of numerous sector standards such as ISO 26262. - [IEC 62443](https://www.itemis.com/en/glossary/iec-62443/): IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems (OT). Its core concepts are segmentation into zones and conduits and the four security levels SL1 to SL4, which grade the required protection against attackers of varying strength. - [Impact Analysis](https://www.itemis.com/en/glossary/impact-analysis/): Impact analysis uses trace links to determine which artifacts — requirements, architecture, code, tests, evidence — are affected by a change. It makes the costs and risks of a change assessable before the change is implemented. - [ISO 26262 (Functional Safety for Road Vehicles)](https://www.itemis.com/en/glossary/iso-26262/): ISO 26262 is the international standard for the functional safety of electrical and electronic (E/E) systems in road vehicles. It is derived from IEC 61508, defines an automotive-specific risk scheme with ASIL A to D and covers the entire safety lifecycle. - [ISO/SAE 21434 (Road Vehicles — Cybersecurity Engineering)](https://www.itemis.com/en/glossary/iso-sae-21434/): ISO/SAE 21434 is the central cybersecurity standard of the automotive industry. It describes an end-to-end cybersecurity engineering process across the entire vehicle lifecycle — from concept and development through production and operation to decommissioning. - [Item Definition](https://www.itemis.com/en/glossary/item-definition/): The Item Definition is the first step of the TARA according to ISO/SAE 21434. It defines what is analysed: the item with its functions, its preliminary architecture and the item boundary, plus the cybersecurity-relevant assumptions. - [KerML (Kernel Modeling Language)](https://www.itemis.com/en/glossary/kerml/): KerML (Kernel Modeling Language) is the foundation language standardised by the OMG on which SysML v2 is built. It defines core modelling concepts and formal semantics that languages built on top of it reuse and specialise. - [Language Workbench](https://www.itemis.com/en/glossary/language-workbench/): A language workbench is a development environment for building custom, usually domain-specific languages (DSLs). It provides everything that makes a language practically usable: language definition, an editor with code completion, validation, and code generation or interpretation. - [Legacy Modernization](https://www.itemis.com/en/glossary/legacy-modernization/): Legacy modernization refers to transferring historically grown legacy systems — such as COBOL or mainframe applications — to modern technologies and architectures. The goal is to preserve the proven business logic while improving maintainability, operating costs and release capability. - [Living TARA (Dynamic TARA)](https://www.itemis.com/en/glossary/living-tara/): A Living TARA (also Dynamic TARA) is a threat analysis and risk assessment that is kept up to date across the entire product lifecycle. New vulnerabilities, changed components and new attack techniques feed continuously into the risk assessment, instead of only once in the concept phase. - [LLM (Large Language Model)](https://www.itemis.com/en/glossary/llm/): An LLM (Large Language Model) is a neural network trained on very large amounts of text that models language statistically and thereby understands, summarizes, translates and generates text. LLMs are the technical foundation of chatbots, AI assistants and AI agents. - [MBSE (Model-Based Systems Engineering)](https://www.itemis.com/en/glossary/mbse/): MBSE (Model-Based Systems Engineering) is a systems engineering approach in which a formal, machine-readable system model — not documents — is the central artefact of development. Requirements, architecture and behaviour are brought together in one consistent model. - [MCP (Model Context Protocol)](https://www.itemis.com/en/glossary/mcp/): MCP (Model Context Protocol) is an open standard that connects AI applications such as LLMs and AI agents with external data sources and tools. Instead of building a separate integration for every combination of model and system, one MCP server per system is enough. - [MDSD (Model-Driven Software Development)](https://www.itemis.com/en/glossary/mdsd/): MDSD (Model-Driven Software Development) is a development approach in which formal models are the primary artifacts of software development. Source code is generated automatically from the models instead of being written by hand — reproducibly, consistently and independently of the target platform. - [Metamodel](https://www.itemis.com/en/glossary/metamodel/): A metamodel is the model of a model: it defines which elements, relationships and rules are allowed in a model. Metamodels play the same role for models as a grammar does for languages — they make models formally unambiguous and machine-processable. - [Microservices](https://www.itemis.com/en/glossary/microservices/): Microservices are an architectural style in which an application consists of many small, business-aligned services that are developed, deployed and scaled independently of each other and communicate via interfaces. They increase flexibility and scalability — at the price of higher operational complexity. - [MoRA (Modular Risk Assessment)](https://www.itemis.com/en/glossary/mora/): MoRA (Modular Risk Assessment) is a methodology for model-based security risk analyses developed at Fraunhofer AISEC. It structures the analysis into four phases — model the system, identify protection needs, analyse threats, analyse risks — and thus carries a TARA according to ISO/SAE 21434. - [NIS2 (Directive (EU) 2022/2555)](https://www.itemis.com/en/glossary/nis2/): NIS2 (Directive (EU) 2022/2555) is the EU directive on the cybersecurity of essential and important entities. It obliges companies in 18 sectors to implement risk management, reporting processes and management accountability — unlike the CRA, it regulates organisations, not products. - [Process Automation](https://www.itemis.com/en/glossary/process-automation/): Process automation refers to the execution of recurring business processes by software — from rule-based workflows through BPM platforms with workflow engines to AI-assisted automation. The goal is to reduce manual routine steps and make processes faster, more traceable and less error-prone. - [RAG (Retrieval-Augmented Generation)](https://www.itemis.com/en/glossary/rag/): RAG (Retrieval-Augmented Generation) is an architectural pattern that supplies an LLM with content from external knowledge sources at answer time: first, documents matching the request are retrieved (retrieval), then the model generates the answer on this basis (generation). - [ReqIF (Requirements Interchange Format)](https://www.itemis.com/en/glossary/reqif/): ReqIF (Requirements Interchange Format) is an XML-based OMG standard for exchanging requirements — including attributes, structure and links — across tools, for example between an OEM and a supplier or between different RM tools. - [Requirements Coverage](https://www.itemis.com/en/glossary/requirements-coverage/): Requirements coverage denotes the degree to which requirements are covered by other development artifacts — typically test cases. Process standards such as Automotive SPICE require it to be measured, but the term is not uniformly defined. - [Requirements Engineering](https://www.itemis.com/en/glossary/requirements-engineering/): Requirements engineering is the systematic discipline of eliciting, documenting, validating and managing requirements for a system over its entire lifecycle. The goal is a shared, verifiable understanding of what the system is supposed to deliver. - [Requirements Traceability](https://www.itemis.com/en/glossary/requirements-traceability/): Requirements traceability is the ability to trace each requirement from its origin through architecture, implementation and testing to validation — in both directions. Standards such as ASPICE, ISO 26262 and the Cyber Resilience Act require it. - [Safety Case](https://www.itemis.com/en/glossary/safety-case/): A safety case is the structured argument that a system is acceptably safe in its context of use — supported by traceable evidence from the development process. ISO 26262 requires it as a central work product for safety-related E/E systems. - [SBOM (Software Bill of Materials)](https://www.itemis.com/en/glossary/sbom/): An SBOM (Software Bill of Materials) is the machine-readable inventory of all software components of a product, including open-source libraries. The EU Cyber Resilience Act requires it as part of the technical documentation — common formats are SPDX and CycloneDX. - [Security by Design](https://www.itemis.com/en/glossary/security-by-design/): Security by design is the principle of engineering security into a product from the very first concept phase, instead of retrofitting it afterwards through patches. Standards such as ISO/SAE 21434 and laws such as the EU Cyber Resilience Act make the principle binding. - [SIL (Safety Integrity Level)](https://www.itemis.com/en/glossary/sil/): SIL (Safety Integrity Level) is the risk classification of IEC 61508 for safety-related E/E/PE systems. The four levels SIL 1 to SIL 4 define how improbable the dangerous failure of a safety function must be and how rigorously its development must be assured. - [SOTIF (Safety of the Intended Functionality, ISO 21448)](https://www.itemis.com/en/glossary/sotif/): SOTIF (Safety of the Intended Functionality, ISO 21448) addresses hazards without malfunction: the system works exactly as specified, but the specification or sensor performance is insufficient for the real-world situation — central for driver assistance and AI-based functions. - [SysML v2](https://www.itemis.com/en/glossary/sysml-v2/): SysML v2 is the successor to SysML v1 standardised by the OMG. It is based on its own metamodel (KerML) instead of a UML profile, places a textual notation on equal footing with the graphical one, and defines a standardised API for cross-tool model access. - [SysML (Systems Modeling Language)](https://www.itemis.com/en/glossary/sysml/): SysML (Systems Modeling Language) is the graphical modelling language for systems engineering standardised by the OMG. It describes requirements, structure and behaviour of complex systems and is the most widespread language for Model-Based Systems Engineering (MBSE). - [Systems Engineering](https://www.itemis.com/en/glossary/systems-engineering/): Systems engineering is the interdisciplinary approach to developing complex technical systems across the entire lifecycle — from stakeholder requirements through architecture and integration to verification and operation. The focus is on the overall system, not the individual discipline. - [TARA (Threat Analysis and Risk Assessment)](https://www.itemis.com/en/glossary/tara/): TARA (Threat Analysis and Risk Assessment) is the threat analysis and risk assessment method of ISO/SAE 21434. It systematically determines which assets of a vehicle or component need protection, how they can be attacked and how the risks are treated. - [Threat Modeling](https://www.itemis.com/en/glossary/threat-modeling/): Threat modeling is the systematic analysis of a system from an attacker's perspective: which assets are worth protecting, by which paths could an attacker compromise them, and which countermeasures are appropriate? It is the methodological foundation of normative risk analyses such as the TARA. - [TIM (Traceability Information Model)](https://www.itemis.com/en/glossary/tim/): A Traceability Information Model (TIM) defines which artifact types of a development process must be connected by which relationship types — the binding blueprint for traceability. TIMs are versioned so that trace links can be validated auditably against a defined model version. - [Tool Qualification (ISO 26262)](https://www.itemis.com/en/glossary/tool-qualification/): Tool qualification is the evidence according to ISO 26262-8 that a software tool is sufficiently trustworthy for use in safety-related development. Whether it is necessary is determined by the Tool Confidence Level (TCL), derived from tool impact and tool error detection. - [Toolchain Integration](https://www.itemis.com/en/glossary/toolchain-integration/): Toolchain integration connects the tools of an engineering organization — requirements management, modeling, development, testing — into an end-to-end tool chain. It breaks up data silos and enables traceability across tool boundaries. - [Traceability Matrix (Requirements Traceability Matrix, RTM)](https://www.itemis.com/en/glossary/traceability-matrix/): A traceability matrix (RTM) is a table that maps relationships between development artifacts such as requirements and test cases via unique IDs. It establishes bidirectional traceability and makes gaps immediately visible. - [UML Profile](https://www.itemis.com/en/glossary/uml-profile/): A UML profile is the standardized extension mechanism of UML: through stereotypes, tagged values and constraints, generic model elements are given a domain-specific meaning without changing the language itself or replacing the modeling tool. - [UML (Unified Modeling Language)](https://www.itemis.com/en/glossary/uml/): UML (Unified Modeling Language) is the graphical modelling language standardised by the OMG for specifying, visualising and documenting software systems. UML 2 defines 14 diagram types in the categories structure and behaviour — from the class diagram to the state machine diagram. - [UNECE R155 (UN Regulation No. 155 — Cybersecurity)](https://www.itemis.com/en/glossary/unece-r155/): UNECE R155 is UN Regulation No. 155 on the cybersecurity of road vehicles. It makes an audited Cyber Security Management System (CSMS) a prerequisite for type approval: without CSMS evidence, new vehicle types receive no approval in the EU — and thus no market access. - [UNECE R156 (UN Regulation No. 156 — Software Updates)](https://www.itemis.com/en/glossary/unece-r156/): UNECE R156 is UN Regulation No. 156 on software updates for road vehicles. It makes an audited Software Update Management System (SUMS) a prerequisite for type approval: the manufacturer must be able to prove at any time which software version runs on which vehicle type and whether an update affects the approval. - [V-Model](https://www.itemis.com/en/glossary/v-model/): The V-model is a development model for systems and software engineering: the left branch refines requirements step by step down to implementation, the right branch verifies each level against its specification. Each development level thus faces its own test level. - [Imprint](https://www.itemis.com/en/imprint/): Imprint of itemis AG — information provided according to Sec. 5 DDG, contact, register entry and responsible persons. - [Model-Based Engineering — Tools and Methods](https://www.itemis.com/en/model-based-engineering/): Model-based systems and software engineering with itemis CREATE (state machines) and itemis ANALYZE (requirements traceability). - [Custom Tools & Domain-Specific Languages: Xtext, JetBrains MPS](https://www.itemis.com/en/model-based-engineering/custom-tools/): Domain-Specific Languages, code generation and tailor-made modelling workbenches with Xtext and JetBrains MPS: for automotive, medtech, finance and embedded. - [Webinars](https://www.itemis.com/en/model-based-engineering/custom-tools/webinar/): Webinars on custom tools: live sessions and recordings on tailor-made development tools and DSLs – free from itemis. - [Whitepapers: Custom Tooling & DSLs](https://www.itemis.com/en/model-based-engineering/custom-tools/whitepaper/): Free whitepapers on domain-specific languages, code generation and custom modelling workbenches. - [Custom Tool or Standard?](https://www.itemis.com/en/model-based-engineering/custom-tools/whitepaper/custom-tool-or-standard/): When does a custom DSL pay off, and when is a UML/SysML profile the smarter choice? Decision guidance from 20 years of custom tool projects at itemis. Free by Dr. Patrick Könemann and Dr. Klaus Birken. - [State Machine & Statechart Modeling with itemis CREATE](https://www.itemis.com/en/model-based-engineering/model-driven-software-development/): Model-Driven Software Development with itemis CREATE: model statecharts, simulate, generate code: C, C++, Java, Python. Deterministic, auditable, platform-independent. - [Webinars](https://www.itemis.com/en/model-based-engineering/model-driven-software-development/webinar/): Webinars on model-driven software development: live sessions and recordings on code generation and modeling – free from itemis. - [Rapid State Machine Development and Unit Testing for Embedded Systems](https://www.itemis.com/en/model-based-engineering/model-driven-software-development/webinar/rapid-state-machine-development-and-unit-testing/): Learn how itemis CREATE accelerates state machine development and unit testing for embedded systems. - [Rapid State Machine Development in the Cloud with AI Co-Piloting](https://www.itemis.com/en/model-based-engineering/model-driven-software-development/webinar/rapid-state-machine-development-in-the-cloud-with-ai-co-piloting/): Learn how to rapidly develop and manage state machines in the cloud using AI co-piloting with itemis CREATE. - [Model-Based Systems Engineering (MBSE) - Languages, Methods, and Tools](https://www.itemis.com/en/model-based-engineering/systems-engineering/): Model-based systems development for cyber-physical products in automotive, medtech and aerospace. - [Webinars](https://www.itemis.com/en/model-based-engineering/systems-engineering/webinar/): Webinars on model-based systems engineering: live sessions and recordings on SysML and MBSE adoption – free from itemis. - [AI meets MBSE](https://www.itemis.com/en/model-based-engineering/systems-engineering/webinar/ai-meets-mbse/): Learn how AI and model-based systems engineering are setting new standards in the transportation industry. - [Systems Engineering with AI – Specific Potential We Can Leverage Right Now!](https://www.itemis.com/en/model-based-engineering/systems-engineering/webinar/systems-engineering-with-ai/): Discover which AI technologies are already improving MBSE workflows today — no hype, just practical insights. - [Whitepaper: Systems Engineering](https://www.itemis.com/en/model-based-engineering/systems-engineering/whitepaper/): Free whitepapers on model-based systems engineering, SysML v2, FMEA automation and practical SE best practices — for engineers in automotive, aerospace and defence. - [10 Ways to Improve Systems Engineering](https://www.itemis.com/en/model-based-engineering/systems-engineering/whitepaper/10-ways-to-improve-systems-engineering/): Ten evidence-based practices for systems engineers who want to ship better products — from hiring and requirements discipline to model-based approaches, tooling, and continuous improvement. Free whitepaper by Dr. David Akehurst. - [AI-Assisted ASPICE Compliance](https://www.itemis.com/en/model-based-engineering/systems-engineering/whitepaper/ai-assisted-aspice-compliance/): How knowledge graphs and LLM agents automate ASPICE process assessment: two-pass consistency check, five specialized agent skills, and a cost-benefit analysis showing 23 weeks down to 6. Free by Benjamin Alders, itemis. - [From SysML v1 to SysML v2](https://www.itemis.com/en/model-based-engineering/systems-engineering/whitepaper/from-sysml-v1-to-sysml-v2/): A conceptual translation guide for MBSE practitioners: the definition/usage principle, ports and pins, relationships, connectors, n-ary connections, and practical migration recommendations. Free by Benjamin Alders, itemis. - [MBSE with Natural Language](https://www.itemis.com/en/model-based-engineering/systems-engineering/whitepaper/mbse-with-natural-language/): How natural language processing enables engineers to do MBSE without learning SysML v2 syntax — formal models generated from requirements management tools, INCOSE and ASPICE 4.0 compliant. Free whitepaper. - [Toolchain Integration: Tools that Work Together](https://www.itemis.com/en/model-based-engineering/toolchain-integration/): Integrating modelling tools into existing development environments: tool selection, EA-Bridge, FMEA tooling and ASPICE tool strategy. - [Webinars](https://www.itemis.com/en/model-based-engineering/toolchain-integration/webinar/): Webinars on toolchain integration: live sessions and recordings on Enterprise Architect integration and toolchains – free from itemis. - [Connecting the Dots](https://www.itemis.com/en/model-based-engineering/toolchain-integration/webinar/connecting-the-dots/): Learn how to link threat intelligence with TARA and build dynamic risk management systems in cybersecurity. - [Privacy Policy](https://www.itemis.com/en/privacy-policy/): Privacy policy of itemis AG — information on the collection and processing of personal data, your rights and the services we use. - [References](https://www.itemis.com/en/references/): From SMEs to large corporations – itemis creates value for projects and teams in a distinctive way, far beyond the assigned scope. - [Xtext DSL Collapses Thousands of Lines into One](https://www.itemis.com/en/references/atruvia/) - [Three Full-Time Positions Saved with eAU Automation](https://www.itemis.com/en/references/avitea/) - [Automotive SPICE Toolchain Replaces Excel Matrices](https://www.itemis.com/en/references/bauerhin/) - [IoT Retrofit for 20 Loading Bay Doors at Hamburg Port](https://www.itemis.com/en/references/blg-logistics/) - [Efficient State Machines for Home Appliances](https://www.itemis.com/en/references/bsh/) - [Modern Sales Platform for Deutsche Bahn](https://www.itemis.com/en/references/db-fernverkehr/) - [Advanced Medical Devices Built with CREATE](https://www.itemis.com/en/references/draeger/) - [Graphical State Machines Built Into ASCET-DEVELOPER](https://www.itemis.com/en/references/etas/) - [EPS: Safety-Critical Systems Engineering for Forvia Hella](https://www.itemis.com/en/references/forvia-hella/) - [KOSTAL Finalizes ASPICE Assessment Successfully With itemis ANALYZE](https://www.itemis.com/en/references/kostal-aspice/): Kostal finalises ASPICE Assessment successfully with itemis ANALYZE. - [EA-Bridge Closes Gap in KOSTAL's AUTOSAR Toolchain](https://www.itemis.com/en/references/kostal/): KOSTAL now integrates bidirectional UML modeling seamlessly into its existing Enterprise Architect workflow, thanks to itemis. - [C++ Code Generated from Visual State Machines](https://www.itemis.com/en/references/magnotherm/) - [Cross-Platform C Code for Engine Control Firmware](https://www.itemis.com/en/references/man-energy-solutions/) - [Offline-First App for Crop Documentation at Harvest](https://www.itemis.com/en/references/odas/) - [Web Migration for parcIT's Banking Software](https://www.itemis.com/en/references/parcit/) - [Portal Frontend for the Pixelboxx DAM Platform](https://www.itemis.com/en/references/pixelboxx/) - [Custom Software for a Streamlined Proposal Process](https://www.itemis.com/en/references/remondis/) - [Cross-Platform App for Bluetooth Hygiene Flushes](https://www.itemis.com/en/references/tece/) - [From Monolith to Agile Self-Contained Systems](https://www.itemis.com/en/references/thalia/) - [Insurance Logic Compiled Directly to C Code](https://www.itemis.com/en/references/zurich/)