# itemis AG > itemis entwickelt visionäre digitale Lösungen. Wir schaffen innovative und flexible Lösungen für jede Organisation, quer durch alle Branchen. itemis entwickelt visionäre digitale Lösungen. Wir schaffen innovative und flexible Lösungen für jede Organisation, quer durch alle Branchen. itemis ist ein führender Anbieter im Bereich Digital Engineering und bietet ein umfassendes Portfolio an Dienstleistungen und Produkten. Die Kernkompetenzen umfassen Model-Based Systems Engineering (MBSE), Compliance Intelligence (Cyber Resilience Act, Functional Safety, Traceability), individuelle Softwareentwicklung und Künstliche Intelligenz (KI), mit einer starken Basis in der Automobilindustrie und darüber hinaus. Gegründet 2003, Hauptsitz in Dortmund. Mission: „Empowering Digital Success". ## Themen & Leistungen (Deutsch) - [Compliance Intelligence](https://www.itemis.com/compliance-intelligence/): Werkzeuge und Beratung für die zentralen Compliance-Standards moderner Produktentwicklung — Cybersecurity, Funktionale Sicherheit, Requirements Traceability. - [EU Cyber Resilience Act (CRA): Compliance-Roadmap bis 2027](https://www.itemis.com/compliance-intelligence/cyber-resilience-act/): CRA-Fristen 2026 und 2027, Betroffenheit, Roadmap und Umsetzung mit itemis SECURE und der CRAIG-Community. Der Selbstcheck für Hersteller von Produkten mit digitalen Elementen. - [ISO/SAE 21434 & IEC 62443: Cybersecurity für Automotive und Industrie](https://www.itemis.com/compliance-intelligence/cyber-security/): Leitfaden zu ISO/SAE 21434 (TARA, UNECE R155) und IEC 62443 (Zonen, Conduits, Security Level). Umsetzung mit itemis SECURE, einem Tool für beide Standards. - [Industrial & Automotive Functional Safety: ISO 26262 & IEC 61508](https://www.itemis.com/compliance-intelligence/functional-safety/): ISO 26262, IEC 61508 und funktionale Sicherheit für sicherheitskritische Systeme in Automotive und Industrie. - [Requirements Traceability: End-to-End-Traceability für regulierte Industrien](https://www.itemis.com/compliance-intelligence/requirements-traceability/): Durchgängige, auditierbare Requirements Traceability für Automotive, Defence, Industrial und MedTech: von Anforderungen über Architektur bis zu Tests, Validierung und Releases. - [Custom Software Development für Enterprise](https://www.itemis.com/custom-software/): Maßgeschneiderte Software-Entwicklung für Enterprise-Kunden — Full-Stack, KI-gestützt, agil. Für Banken, Versicherungen, Logistik und Industrie. - [AI Enablement: KI, die in Ihrem Unternehmen wirklich ankommt](https://www.itemis.com/custom-software/ki-enablement/): itemis befähigt Unternehmen, KI eigenständig und nachhaltig einzusetzen: Prozessanalyse, Werkzeugwahl, Integration, Datensouveränität und Befähigung der Mitarbeiter. - [Legacy Code Modernization mit KI-Unterstützung](https://www.itemis.com/custom-software/legacy-modernisierung/): Risikominimierte Legacy-Migration: COBOL, PL/I & Mainframe schrittweise und nachweislich gleichwertig nach Java & PostgreSQL überführen. ISO 9001. - [Eingespielte Senior Full-Stack Teams für Cloud-Native Development](https://www.itemis.com/custom-software/full-stack/): Eingespielte Senior-Teams für Full-Stack Development, Cloud-Migration und Microservices: von regulierter Infrastruktur bis Sovereign Cloud nach Gaia-X-Standards. - [Model-Based Systems & Software Engineering — Werkzeuge und Methoden](https://www.itemis.com/model-based-engineering/): Modellbasierte System- und Softwareentwicklung mit itemis CREATE (State Machines) und itemis ANALYZE (Requirements Traceability). - [Model-Based Systems Engineering (MBSE) - Sprachen, Methoden und Werkzeuge](https://www.itemis.com/model-based-engineering/systems-engineering/): Modellbasierte Systementwicklung für cyber-physikalische Produkte in Automotive, Medtech und Aerospace. - [State Machine & Statechart Modeling mit itemis CREATE](https://www.itemis.com/model-based-engineering/model-driven-software-development/): Model-Driven Software Development mit itemis CREATE: Statecharts modellieren, simulieren, Code generieren in C, C++, Java, Python. Deterministisch, auditierbar, plattformunabhängig. - [Custom Tools & Domain-Specific Languages: Xtext, JetBrains MPS](https://www.itemis.com/model-based-engineering/custom-tools/): Domain-Specific Languages, Code-Generierung und domänenspezifische Modellierungs-Workbenches mit Xtext und JetBrains MPS, für Automotive, Medtech, Finance und Embedded. - [Toolchain Integration: Werkzeuge, die perfekt zusammenspielen](https://www.itemis.com/model-based-engineering/toolchain-integration/): itemis ANALYZE als Best-of-Breed-Integrationsplattform, Werkzeugauswahl, individuelle Werkzeuganpassungen und Werkzeugintegration ## Blog (Deutsch) - [Compliance Intelligence – Cyber Resilience Act](https://www.itemis.com/blog/compliance-intelligence/cyber-resilience-act/): Der Cyber Resilience Act in der Praxis: Artikel zu Anforderungen, Fristen und Umsetzung der EU-Verordnung für sichere Produkte – von den Security-Experten der itemis. - [Compliance Intelligence – Functional Safety](https://www.itemis.com/blog/compliance-intelligence/functional-safety/): Funktionale Sicherheit verständlich erklärt: Artikel zu ISO 26262, ASIL, Safety-Nachweisen und sicherer Softwareentwicklung in regulierten Branchen. - [Compliance Intelligence – Cyber Security](https://www.itemis.com/blog/compliance-intelligence/cyber-security/): Cyber Security im Engineering: Artikel zu Bedrohungsanalysen (TARA), Security by Design und ISO/SAE 21434 aus der Praxis der itemis Security-Experten. - [Compliance Intelligence – Requirements Traceability](https://www.itemis.com/blog/compliance-intelligence/requirements-traceability/): Requirements Traceability in der Praxis: Artikel zu Nachverfolgbarkeit von Anforderungen, Traceability-Strategien und Tool-Unterstützung im Engineering. - [Model-Based Engineering – Model-Based Systems Engineering](https://www.itemis.com/blog/model-based-engineering/systems-engineering/): Model-Based Systems Engineering (MBSE): Artikel zu SysML, Systemmodellierung und der Einführung von MBSE in der Produktentwicklung. - [Model-Based Engineering – Model-Driven Software Development](https://www.itemis.com/blog/model-based-engineering/model-driven-software-development/): Modellgetriebene Softwareentwicklung (MDSD): Artikel zu Codegenerierung, Zustandsautomaten, DSLs und Modellierungswerkzeugen aus über 20 Jahren Praxis. - [Model-Based Engineering – Custom Tools & DSLs](https://www.itemis.com/blog/model-based-engineering/custom-tools/): Custom Tools für das Engineering: Artikel zu maßgeschneiderten Entwicklungswerkzeugen, domänenspezifischen Sprachen (DSLs) und Tool-Entwicklung. - [Model-Based Engineering – Toolchain Integration](https://www.itemis.com/blog/model-based-engineering/toolchain-integration/): Toolchain Integration im Engineering: Artikel zur Anbindung von Enterprise Architect & Co., Datenaustausch und durchgängigen Werkzeugketten. - [Custom Software Development – Legacy-Modernisierung](https://www.itemis.com/blog/custom-software/legacy-modernisierung/): Legacy-Modernisierung ohne Risiko: Artikel zu Strategien, Migrationspfaden und Werkzeugen, um Altsysteme zukunftssicher zu machen. - [Custom Software Development – AI Enablement](https://www.itemis.com/blog/custom-software/ki-enablement/): KI-Enablement für Unternehmen: Artikel zu KI-gestützter Softwareentwicklung, AI-Agenten und dem produktiven Einsatz von Large Language Models. - [Custom Software Development – Full-Stack & Cloud](https://www.itemis.com/blog/custom-software/full-stack/): Full-Stack-Entwicklung in der Praxis: Artikel zu modernen Web-Technologien, Softwarearchitektur und Individualsoftware von den Entwicklern der itemis. ## Referenzen & Fallstudien - [Automotive-SPICE-Toolkette statt Excel-Matrizen](https://www.itemis.com/referenzen/bauerhin/) - [C++-Code aus grafischen Zustandsautomaten](https://www.itemis.com/referenzen/magnotherm/) - [Cross-Plattform-App für Bluetooth-Hygienespülungen](https://www.itemis.com/referenzen/tece/) - [Drei Vollzeitstellen eingespart durch eAU-Automatisierung](https://www.itemis.com/referenzen/avitea/) - [EA-Bridge schließt Lücke in KOSTALs AUTOSAR-Toolkette](https://www.itemis.com/referenzen/kostal/) - [Effiziente Zustandsautomaten für Haushaltsgeräte](https://www.itemis.com/referenzen/bsh/) - [EPS: Sicherheitskritische Systementwicklung für Forvia Hella](https://www.itemis.com/referenzen/forvia-hella/) - [Grafische Zustandsmaschinen nativ in ASCET-DEVELOPER](https://www.itemis.com/referenzen/etas/) - [IoT-Nachrüstung für 20 Hallentore am Hamburger Hafen](https://www.itemis.com/referenzen/blg-logistics/) - [itemis CREATE für fortschrittliche Medizingeräte](https://www.itemis.com/referenzen/draeger/): itemis Erfolgsstory ➡️ Entwicklungsprozess durch effiziente Code-Generierung ✔️ Herangehensweise ✔️ Lösung ➡️ Lesen Sie hier mehr! - [Maßgeschneiderte Software für den Angebotsprozess](https://www.itemis.com/referenzen/remondis/) - [Moderne Vertriebsplattform für die Deutsche Bahn](https://www.itemis.com/referenzen/db-fernverkehr/) - [Offline-App für Felddokumentation zur Erntesaison](https://www.itemis.com/referenzen/odas/) - [Plattformunabhängiger C-Code für Motorsteuerungs-Firmware](https://www.itemis.com/referenzen/man-energy-solutions/) - [Portal-Frontend für die DAM-Plattform von Pixelboxx](https://www.itemis.com/referenzen/pixelboxx/) - [Versicherungslogik direkt in ausführbaren C-Code](https://www.itemis.com/referenzen/zurich/) - [Vom Monolithen zu agilen Self-Contained Systems](https://www.itemis.com/referenzen/thalia/) - [Web-Umstieg für die Banksteuerungssoftware von parcIT](https://www.itemis.com/referenzen/parcit/) - [Xtext-DSL reduziert tausende Codezeilen auf eine](https://www.itemis.com/referenzen/atruvia/) ## Unternehmen - [Über itemis](https://www.itemis.com/ueber-uns/): itemis – seit 2003 Softwareunternehmen mit Herz. Lernen Sie unsere Geschichte, unsere Werte und die Menschen hinter unseren Produkten kennen. - [Karriere bei itemis](https://www.itemis.com/karriere/): Software-Jobs bei itemis: 100% Remote, 4+1 Weiterbildungsmodell, unbefristeter Vertrag. Software Developer, Engineers und Cybersecurity-Experten gesucht. Jetzt bewerben. - [Kontakt](https://www.itemis.com/kontakt/): Nehmen Sie Kontakt mit itemis auf. Wir helfen Ihnen bei Fragen zu unseren Leistungen, Produkten und Projekten — schnell, direkt und ohne Umwege. - [Podiumsdiskussionen über aktuelle IT-Themen | itemis PODIUM](https://www.itemis.com/itemis-podium/): In unseren Podiumsdiskussionen beleuchten Fachleute aus verschiedenen Branchen aktuelle und aufregende Themen der IT-Welt in tiefgründigen Debatten über ihre Fachgebiete. ## Topics & Services (English) - [Compliance Intelligence](https://www.itemis.com/en/compliance-intelligence/): Tools and consulting for the central compliance standards of modern product development — cybersecurity, functional safety, requirements traceability. - [EU Cyber Resilience Act (CRA): Compliance Roadmap to 2027](https://www.itemis.com/en/compliance-intelligence/cyber-resilience-act/): CRA deadlines 2026 and 2027, scope, roadmap and implementation with itemis SECURE and the CRAIG community. The self-assessment for manufacturers of products with digital elements. - [ISO/SAE 21434 & IEC 62443: Cybersecurity for Automotive and Industry](https://www.itemis.com/en/compliance-intelligence/cyber-security/): Guide to ISO/SAE 21434 (TARA, UNECE R155) and IEC 62443 (zones, conduits, security level). Implementation with itemis SECURE, one tool for both standards. - [Industrial & Automotive Functional Safety: ISO 26262 & IEC 61508](https://www.itemis.com/en/compliance-intelligence/functional-safety/): ISO 26262, IEC 61508 and functional safety for safety-critical systems in automotive and industrial applications. - [Requirements Traceability: End-to-End Traceability for Regulated Industries](https://www.itemis.com/en/compliance-intelligence/requirements-traceability/): Comprehensive, auditable requirements traceability for Automotive, Defence, Industrial and MedTech: from requirements through architecture to tests, validation and releases. - [Custom Software Development for Enterprise](https://www.itemis.com/en/custom-software/): Tailored software development for enterprise customers — full-stack, AI-assisted, agile. For banks, insurers, logistics and industry. - [AI Enablement: AI That Actually Works in Your Organisation](https://www.itemis.com/en/custom-software/ai-enablement/): itemis enables organisations to use AI independently and sustainably: process analysis, tool selection, integration, data sovereignty and people enablement. - [Legacy Code Modernization with AI Support](https://www.itemis.com/en/custom-software/legacy-modernization/): Risk-minimised legacy migration: migrate COBOL, PL/I & mainframe step by step, with proven functional equivalence, to Java & PostgreSQL. ISO 9001. - [Seasoned Senior Full-Stack Teams for Cloud-Native Development](https://www.itemis.com/en/custom-software/full-stack/): Seasoned senior teams for full-stack development, cloud migration and microservices: from regulated infrastructure to Sovereign Cloud compliant with Gaia-X standards. - [Model-Based Engineering — Tools and Methods](https://www.itemis.com/en/model-based-engineering/): Model-based systems and software engineering with itemis CREATE (state machines) and itemis ANALYZE (requirements traceability). - [Model-Based Systems Engineering (MBSE) - Languages, Methods, and Tools](https://www.itemis.com/en/model-based-engineering/systems-engineering/): Model-based systems development for cyber-physical products in automotive, medtech and aerospace. - [State Machine & Statechart Modeling with itemis CREATE](https://www.itemis.com/en/model-based-engineering/model-driven-software-development/): Model-Driven Software Development with itemis CREATE: model statecharts, simulate, generate code: C, C++, Java, Python. Deterministic, auditable, platform-independent. - [Custom Tools & Domain-Specific Languages: Xtext, JetBrains MPS](https://www.itemis.com/en/model-based-engineering/custom-tools/): Domain-Specific Languages, code generation and tailor-made modelling workbenches with Xtext and JetBrains MPS: for automotive, medtech, finance and embedded. - [Toolchain Integration: Tools that Work Together](https://www.itemis.com/en/model-based-engineering/toolchain-integration/): Integrating modelling tools into existing development environments: tool selection, EA-Bridge, FMEA tooling and ASPICE tool strategy. ## Blog (English) - [ – Cyber Resilience Act](https://www.itemis.com/en/blog/compliance-intelligence/cyber-resilience-act/): The Cyber Resilience Act in practice: articles on requirements, deadlines and implementation of the EU regulation for secure products – from itemis security experts. - [ – Functional Safety](https://www.itemis.com/en/blog/compliance-intelligence/functional-safety/): Functional safety explained: articles on ISO 26262, ASIL, safety cases and safe software development in regulated industries. - [ – Cyber Security](https://www.itemis.com/en/blog/compliance-intelligence/cyber-security/): Cyber security in engineering: articles on threat analysis (TARA), security by design and ISO/SAE 21434 from the practice of itemis security experts. - [ – Requirements Traceability](https://www.itemis.com/en/blog/compliance-intelligence/requirements-traceability/): Requirements traceability in practice: articles on tracing requirements, traceability strategies and tool support in engineering. - [ – Model-Based Systems Engineering](https://www.itemis.com/en/blog/model-based-engineering/systems-engineering/): Model-based systems engineering (MBSE): articles on SysML, system modeling and introducing MBSE in product development. - [ – Model-Driven Software Development](https://www.itemis.com/en/blog/model-based-engineering/model-driven-software-development/): Model-driven software development (MDSD): articles on code generation, state machines, DSLs and modeling tools from over 20 years of practice. - [ – Custom Tools & DSLs](https://www.itemis.com/en/blog/model-based-engineering/custom-tools/): Custom tools for engineering: articles on tailor-made development tools, domain-specific languages (DSLs) and tool development. - [ – Toolchain Integration](https://www.itemis.com/en/blog/model-based-engineering/toolchain-integration/): Toolchain integration in engineering: articles on connecting Enterprise Architect and other tools, data exchange and end-to-end toolchains. - [ – Legacy Modernization](https://www.itemis.com/en/blog/custom-software/legacy-modernization/): Legacy modernization without risk: articles on strategies, migration paths and tools to make legacy systems future-proof. - [ – AI Enablement](https://www.itemis.com/en/blog/custom-software/ai-enablement/): AI enablement for companies: articles on AI-assisted software development, AI agents and the productive use of large language models. - [ – Full Stack & Cloud](https://www.itemis.com/en/blog/custom-software/full-stack/): Full-stack development in practice: articles on modern web technologies, software architecture and custom software from itemis developers. ## Glossar / Fachbegriffe (Deutsch) - [ALM](https://www.itemis.com/glossar/alm/): ALM (Application Lifecycle Management) bezeichnet die koordinierte Verwaltung des gesamten Software-Lebenszyklus — von Anforderungen über Entwurf, Implementierung und Test bis zu Release und Wartung — samt der Prozesse und Werkzeuge, die diese Disziplinen verbinden. - [ASIL](https://www.itemis.com/glossar/asil/): ASIL (Automotive Safety Integrity Level) ist die Risikoeinstufung der ISO 26262 für sicherheitsrelevante E/E-Systeme im Fahrzeug. Die vier Stufen ASIL A bis D bestimmen, wie streng Entwicklung, Nachweise und Tests einer Funktion ausfallen müssen. - [Attack Tree](https://www.itemis.com/glossar/attack-tree/): Ein Attack Tree (Angriffsbaum) zerlegt ein Angriffsziel hierarchisch in Teilziele und konkrete Angriffsschritte. In der TARA nach ISO/SAE 21434 dienen Angriffsbäume dazu, Angriffspfade systematisch zu modellieren und ihre Durchführbarkeit nachvollziehbar zu bewerten. - [Automotive SPICE](https://www.itemis.com/glossar/automotive-spice/): Automotive SPICE (ASPICE) ist das Prozess-Assessment-Modell der Automobilindustrie zur Bewertung der Reife von Entwicklungsprozessen für software-basierte Systeme. Assessments stufen Prozesse auf Capability Levels 0 bis 5 ein — viele OEMs fordern von Zulieferern Level 2 oder 3. - [AUTOSAR](https://www.itemis.com/glossar/autosar/): AUTOSAR (AUTomotive Open System ARchitecture) ist eine weltweite Entwicklungspartnerschaft von Fahrzeugherstellern, Zulieferern und Werkzeuganbietern, die eine standardisierte Softwarearchitektur für Fahrzeug-Steuergeräte definiert. Ziel ist, Softwarekomponenten über Hersteller- und Plattformgrenzen hinweg integrierbar zu machen. - [Best-of-Breed](https://www.itemis.com/glossar/best-of-breed/): Best-of-Breed bezeichnet die Werkzeugstrategie, für jede Engineering-Aufgabe das jeweils beste spezialisierte Werkzeug einzusetzen, statt auf die All-in-One-Suite eines einzelnen Anbieters zu setzen. Der Preis der Spezialisierung ist der Integrationsaufwand zwischen den Werkzeugen. - [BPMN](https://www.itemis.com/glossar/bpmn/): BPMN (Business Process Model and Notation) ist der von der OMG standardisierte grafische Notationsstandard zur Modellierung von Geschäftsprozessen. BPMN-2.0-Modelle sind für Fachbereich und IT gleichermaßen lesbar und von Workflow-Engines direkt ausführbar — das Diagramm ist zugleich Dokumentation und ausführbarer Prozess. - [Cloud-Migration](https://www.itemis.com/glossar/cloud-migration/): Cloud-Migration bezeichnet die Verlagerung von Anwendungen, Daten und Infrastruktur aus dem eigenen Rechenzentrum in eine Cloud-Umgebung. Das Spektrum reicht vom unveränderten Umzug (Rehosting) bis zum Cloud-Native-Neuaufbau — welcher Weg trägt, hängt von Anwendung, Regulatorik und Wirtschaftlichkeit ab. - [CSMS](https://www.itemis.com/glossar/csms/): Ein CSMS (Cyber Security Management System) bündelt die Prozesse, Rollen und Verantwortlichkeiten, mit denen ein Fahrzeughersteller Cybersecurity-Risiken über den gesamten Lebenszyklus identifiziert, bewertet und behandelt. Die UNECE R155 macht ein geprüftes CSMS zur Voraussetzung für die Typgenehmigung. - [CVD](https://www.itemis.com/glossar/cvd/): CVD (Coordinated Vulnerability Disclosure) ist der koordinierte Prozess, über den Sicherheitsforscher und andere Melder Schwachstellen an den Hersteller melden und Details erst nach Bereitstellung einer Abhilfe veröffentlicht werden. Der EU Cyber Resilience Act macht eine CVD-Policy zur Herstellerpflicht. - [CRA](https://www.itemis.com/glossar/cyber-resilience-act/): Der Cyber Resilience Act (CRA) ist die EU-Verordnung mit verbindlichen Cybersecurity-Mindestanforderungen für Produkte mit digitalen Elementen. Ab dem 11. September 2026 gelten Meldepflichten für aktiv ausgenutzte Schwachstellen, ab dem 11. Dezember 2027 alle Anforderungen inklusive CE-Kennzeichnung. - [DSL](https://www.itemis.com/glossar/dsl/): Eine DSL (Domänenspezifische Sprache) ist eine Programmier- oder Modellierungssprache, die auf ein klar abgegrenztes Fachgebiet zugeschnitten ist. Statt universell einsetzbar zu sein wie Java oder C, bildet sie Konzepte, Regeln und Vokabular genau einer Domäne ab. - [FMEA](https://www.itemis.com/glossar/fmea/): Die FMEA (Failure Mode and Effects Analysis) ist eine systematische, induktive Analysemethode: Sie identifiziert mögliche Fehlerarten eines Systems, bewertet deren Ursachen und Auswirkungen und priorisiert Gegenmaßnahmen — bevor die Fehler im Produkt auftreten. - [Funktionale Sicherheit](https://www.itemis.com/glossar/funktionale-sicherheit/): Funktionale Sicherheit ist der Teil der Sicherheit eines Systems, der von der korrekten Funktion sicherheitsbezogener E/E-Systeme abhängt. Ziel ist die Abwesenheit unvertretbarer Risiken durch Fehlfunktionen. Grundnorm ist die IEC 61508, im Automobilbereich gilt die ISO 26262. - [HARA](https://www.itemis.com/glossar/hara/): Die HARA (Hazard Analysis and Risk Assessment) ist die Gefährdungsanalyse und Risikobewertung nach ISO 26262-3. Sie bewertet Gefährdungen eines Fahrzeugsystems nach Schwere, Exposition und Beherrschbarkeit, leitet daraus den ASIL ab und definiert die obersten Sicherheitsziele. - [IEC 61508](https://www.itemis.com/glossar/iec-61508/): IEC 61508 ist die branchenübergreifende Grundnorm für die funktionale Sicherheit elektrischer, elektronischer und programmierbar elektronischer (E/E/PE) Systeme. Sie definiert den Sicherheitslebenszyklus und die Stufen SIL 1 bis SIL 4 und ist die Basis zahlreicher Sektornormen wie der ISO 26262. - [IEC 62443](https://www.itemis.com/glossar/iec-62443/): IEC 62443 ist die internationale Normenreihe für die Cybersecurity industrieller Automatisierungs- und Steuerungssysteme (OT). Kernkonzepte sind die Segmentierung in Zonen und Conduits sowie die vier Security Level SL1 bis SL4, die den Schutzbedarf gegen unterschiedlich starke Angreifer abstufen. - [Impact-Analyse](https://www.itemis.com/glossar/impact-analyse/): Die Impact-Analyse (Auswirkungsanalyse) ermittelt anhand von Trace-Links, welche Artefakte — Anforderungen, Architektur, Code, Tests, Nachweise — von einer Änderung betroffen sind. Sie macht Änderungskosten und -risiken abschätzbar, bevor die Änderung umgesetzt wird. - [ISO 26262](https://www.itemis.com/glossar/iso-26262/): ISO 26262 ist die internationale Norm für die funktionale Sicherheit elektrischer und elektronischer (E/E) Systeme in Straßenfahrzeugen. Sie leitet sich von der IEC 61508 ab, definiert mit ASIL A bis D ein automobilspezifisches Risikoschema und begleitet den gesamten Sicherheitslebenszyklus. - [ISO/SAE 21434](https://www.itemis.com/glossar/iso-sae-21434/): ISO/SAE 21434 ist die zentrale Cybersecurity-Norm der Automobilindustrie. Sie beschreibt einen durchgängigen Cybersecurity-Engineering-Prozess über den gesamten Fahrzeug-Lebenszyklus — von Konzept und Entwicklung über Produktion und Betrieb bis zur Außerbetriebnahme. - [KI-Agent](https://www.itemis.com/glossar/ki-agent/): Ein KI-Agent ist ein Softwaresystem, das auf Basis eines LLM mehrstufige Aufgaben eigenständig plant und ausführt: Es nutzt Werkzeuge wie Dateisysteme, Datenbanken oder APIs, bewertet Zwischenergebnisse und arbeitet iterativ auf ein vorgegebenes Ziel hin — unter menschlicher Aufsicht. - [Language Workbench](https://www.itemis.com/glossar/language-workbench/): Eine Language Workbench ist eine Entwicklungsumgebung für den Bau eigener, meist domänenspezifischer Sprachen (DSLs). Sie liefert alles, was eine Sprache praktisch nutzbar macht: Sprachdefinition, Editor mit Code-Completion, Validierung sowie Codegenerierung oder Interpretation. - [Legacy-Modernisierung](https://www.itemis.com/glossar/legacy-modernisierung/): Legacy-Modernisierung bezeichnet die Überführung gewachsener Altsysteme — etwa COBOL- oder Mainframe-Anwendungen — in moderne Technologien und Architekturen. Ziel ist, die bewährte Geschäftslogik zu erhalten und zugleich Wartbarkeit, Betriebskosten und Release-Fähigkeit zu verbessern. - [Living TARA](https://www.itemis.com/glossar/living-tara/): Eine Living TARA (auch Dynamic TARA) ist eine Bedrohungsanalyse und Risikobewertung, die über den gesamten Produktlebenszyklus aktuell gehalten wird. Neue Schwachstellen, geänderte Komponenten und neue Angriffstechniken fließen fortlaufend in die Risikobewertung ein, statt nur einmalig in der Konzeptphase. - [LLM](https://www.itemis.com/glossar/llm/): Ein LLM (Large Language Model) ist ein mit sehr großen Textmengen trainiertes neuronales Netz, das Sprache statistisch modelliert und damit Texte versteht, zusammenfasst, übersetzt und erzeugt. LLMs sind die technische Grundlage von Chatbots, KI-Assistenten und KI-Agenten. - [MBSE](https://www.itemis.com/glossar/mbse/): MBSE (Model-Based Systems Engineering) ist ein Ansatz des Systems Engineering, bei dem ein formales, maschinenlesbares Systemmodell — nicht Dokumente — das zentrale Artefakt der Entwicklung ist. Anforderungen, Architektur und Verhalten werden in einem konsistenten Modell zusammengeführt. - [MCP](https://www.itemis.com/glossar/mcp/): MCP (Model Context Protocol) ist ein offener Standard, der KI-Anwendungen wie LLMs und KI-Agenten mit externen Datenquellen und Werkzeugen verbindet. Statt für jede Kombination aus Modell und System eine eigene Integration zu bauen, genügt ein MCP-Server je System. - [MDSD](https://www.itemis.com/glossar/mdsd/): MDSD (Modellgetriebene Softwareentwicklung) ist ein Entwicklungsansatz, bei dem formale Modelle die primären Artefakte der Softwareentwicklung sind. Aus den Modellen wird Quellcode automatisiert generiert, statt ihn von Hand zu schreiben — reproduzierbar, konsistent und unabhängig von der Zielplattform. - [Metamodell](https://www.itemis.com/glossar/metamodell/): Ein Metamodell ist das Modell eines Modells: Es definiert, welche Elemente, Beziehungen und Regeln in einem Modell erlaubt sind. Metamodelle spielen für Modelle dieselbe Rolle wie eine Grammatik für Sprachen — sie machen Modelle formal eindeutig und maschinell verarbeitbar. - [Microservices](https://www.itemis.com/glossar/microservices/): Microservices sind ein Architekturstil, bei dem eine Anwendung aus vielen kleinen, fachlich geschnittenen Diensten besteht, die unabhängig voneinander entwickelt, deployt und skaliert werden und über Schnittstellen kommunizieren. Sie erhöhen Flexibilität und Skalierbarkeit — um den Preis höherer Betriebskomplexität. - [NIS2](https://www.itemis.com/glossar/nis2/): NIS2 (Richtlinie (EU) 2022/2555) ist die EU-Richtlinie zur Cybersicherheit wesentlicher und wichtiger Einrichtungen. Sie verpflichtet Unternehmen in 18 Sektoren zu Risikomanagement, Meldeprozessen und Management-Verantwortung — anders als der CRA regelt sie Organisationen, nicht Produkte. - [Prozessautomatisierung](https://www.itemis.com/glossar/prozessautomatisierung/): Prozessautomatisierung bezeichnet die Ausführung wiederkehrender Geschäftsprozesse durch Software — vom regelbasierten Workflow über BPM-Plattformen mit Workflow-Engines bis zur KI-gestützten Automatisierung. Ziel ist, manuelle Routineschritte zu reduzieren und Prozesse schneller, nachvollziehbarer und weniger fehleranfällig zu machen. - [RAG](https://www.itemis.com/glossar/rag/): RAG (Retrieval-Augmented Generation) ist ein Architekturmuster, das ein LLM zur Antwortzeit mit Inhalten aus externen Wissensquellen versorgt: Erst werden zur Anfrage passende Dokumente gesucht (Retrieval), dann erzeugt das Modell die Antwort auf dieser Grundlage (Generation). - [ReqIF](https://www.itemis.com/glossar/reqif/): ReqIF (Requirements Interchange Format) ist ein XML-basierter OMG-Standard zum werkzeugübergreifenden Austausch von Anforderungen samt Attributen, Struktur und Verknüpfungen — etwa zwischen OEM und Zulieferer oder zwischen unterschiedlichen RM-Tools. - [Requirements Coverage](https://www.itemis.com/glossar/requirements-coverage/): Requirements Coverage bezeichnet den Grad, zu dem Anforderungen durch andere Entwicklungsartefakte — typischerweise Testfälle — abgedeckt sind. Prozessstandards wie Automotive SPICE fordern die Messung, der Begriff ist jedoch nicht einheitlich definiert. - [Requirements Engineering](https://www.itemis.com/glossar/requirements-engineering/): Requirements Engineering ist die systematische Disziplin, Anforderungen an ein System zu ermitteln, zu dokumentieren, zu prüfen und über den gesamten Lebenszyklus zu verwalten. Ziel ist ein gemeinsames, prüfbares Verständnis davon, was das System leisten soll. - [Requirements Traceability](https://www.itemis.com/glossar/requirements-traceability/): Requirements Traceability ist die Fähigkeit, jede Anforderung von ihrem Ursprung über Architektur, Implementierung und Tests bis zur Validierung nachzuverfolgen — in beide Richtungen. Normen wie ASPICE, ISO 26262 und der Cyber Resilience Act setzen sie voraus. - [Safety Case](https://www.itemis.com/glossar/safety-case/): Ein Safety Case (Sicherheitsnachweis) ist die strukturierte Argumentation, dass ein System in seinem Einsatzkontext hinreichend sicher ist — gestützt auf nachvollziehbare Evidenzen aus dem Entwicklungsprozess. Die ISO 26262 fordert ihn als zentrales Arbeitsergebnis für sicherheitsrelevante E/E-Systeme. - [SBOM](https://www.itemis.com/glossar/sbom/): Eine SBOM (Software Bill of Materials) ist die maschinenlesbare Stückliste aller Softwarekomponenten eines Produkts, inklusive Open-Source-Bibliotheken. Der EU Cyber Resilience Act verlangt sie als Teil der technischen Dokumentation — gängige Formate sind SPDX und CycloneDX. - [Security by Design](https://www.itemis.com/glossar/security-by-design/): Security by Design ist das Prinzip, Sicherheit von der ersten Konzeptphase an in ein Produkt hineinzuentwickeln, statt sie nachträglich über Patches nachzurüsten. Normen wie ISO/SAE 21434 und Gesetze wie der EU Cyber Resilience Act machen das Prinzip verbindlich. - [SIL](https://www.itemis.com/glossar/sil/): SIL (Safety Integrity Level) ist die Risikoeinstufung der IEC 61508 für sicherheitsbezogene E/E/PE-Systeme. Die vier Stufen SIL 1 bis SIL 4 legen fest, wie unwahrscheinlich der gefahrbringende Ausfall einer Sicherheitsfunktion sein muss und wie streng ihre Entwicklung abzusichern ist. - [SOTIF](https://www.itemis.com/glossar/sotif/): SOTIF (Safety of the Intended Functionality, ISO 21448) adressiert Gefährdungen ohne Fehlfunktion: Das System arbeitet exakt wie spezifiziert, aber Spezifikation oder Sensorleistung reichen für die reale Situation nicht aus — zentral für Fahrerassistenz und KI-basierte Funktionen. - [SysML](https://www.itemis.com/glossar/sysml/): SysML (Systems Modeling Language) ist die von der OMG standardisierte grafische Modellierungssprache für das Systems Engineering. Sie beschreibt Anforderungen, Struktur und Verhalten komplexer Systeme und ist die verbreitetste Sprache für Model-Based Systems Engineering (MBSE). - [Systems Engineering](https://www.itemis.com/glossar/systems-engineering/): Systems Engineering ist der interdisziplinäre Ansatz zur Entwicklung komplexer technischer Systeme über den gesamten Lebenszyklus — von den Stakeholder-Anforderungen über Architektur und Integration bis zu Verifikation und Betrieb. Im Fokus steht das Gesamtsystem, nicht die einzelne Disziplin. - [TARA](https://www.itemis.com/glossar/tara/): TARA (Threat Analysis and Risk Assessment) ist die Bedrohungsanalyse und Risikobewertung der ISO/SAE 21434. Sie ermittelt strukturiert, welche Assets eines Fahrzeugs oder einer Komponente schützenswert sind, wie sie angegriffen werden können und wie die Risiken behandelt werden. - [Threat Modeling](https://www.itemis.com/glossar/threat-modeling/): Threat Modeling (Bedrohungsmodellierung) ist die systematische Analyse eines Systems aus Angreifersicht: Welche Werte sind schützenswert, über welche Wege könnte ein Angreifer sie kompromittieren, und welche Gegenmaßnahmen sind angemessen? Es ist die methodische Grundlage normativer Risikoanalysen wie der TARA. - [TIM](https://www.itemis.com/glossar/tim/): Ein Traceability Information Model (TIM) definiert, welche Artefakttypen eines Entwicklungsprozesses durch welche Beziehungstypen verbunden sein müssen — der verbindliche Bauplan für Traceability. TIMs sind versioniert, damit Trace-Links auditierbar gegen eine definierte Modellversion validiert werden können. - [Tool-Qualifizierung](https://www.itemis.com/glossar/tool-qualifizierung/): Tool-Qualifizierung ist der Nachweis nach ISO 26262-8, dass ein Softwarewerkzeug für den Einsatz in der sicherheitsrelevanten Entwicklung ausreichend vertrauenswürdig ist. Ob sie nötig ist, bestimmt der Tool Confidence Level (TCL) aus Tool Impact und Tool Error Detection. - [Toolchain Integration](https://www.itemis.com/glossar/toolchain-integration/): Toolchain Integration verbindet die Werkzeuge einer Engineering-Organisation — Requirements Management, Modellierung, Entwicklung, Test — zu einer durchgängigen Werkzeugkette. Sie bricht Datensilos auf und ermöglicht Traceability über Tool-Grenzen hinweg. - [Traceability-Matrix](https://www.itemis.com/glossar/traceability-matrix/): Eine Traceability-Matrix (RTM) ist eine Tabelle, die Beziehungen zwischen Entwicklungsartefakten wie Anforderungen und Testfällen über eindeutige IDs abbildet. Sie stellt bidirektionale Nachverfolgbarkeit her und macht Lücken sofort sichtbar. - [UML](https://www.itemis.com/glossar/uml/): UML (Unified Modeling Language) ist die von der OMG standardisierte grafische Modellierungssprache zur Spezifikation, Visualisierung und Dokumentation von Softwaresystemen. UML 2 definiert 14 Diagrammtypen in den Kategorien Struktur und Verhalten — vom Klassendiagramm bis zum Zustandsdiagramm. - [UML-Profil](https://www.itemis.com/glossar/uml-profil/): Ein UML-Profil ist der standardisierte Erweiterungsmechanismus der UML: Über Stereotypen, Tagged Values und Constraints erhalten generische Modellelemente eine domänenspezifische Bedeutung, ohne die Sprache selbst zu verändern oder das Modellierungswerkzeug zu ersetzen. - [UNECE R155](https://www.itemis.com/glossar/unece-r155/): UNECE R155 ist die UN-Regelung Nr. 155 zur Cybersecurity von Straßenfahrzeugen. Sie macht ein geprüftes Cyber Security Management System (CSMS) zur Voraussetzung für die Typgenehmigung: Ohne CSMS-Nachweis erhalten neue Fahrzeugtypen in der EU keine Genehmigung — und damit keinen Marktzugang. - [UNECE R156](https://www.itemis.com/glossar/unece-r156/): UNECE R156 ist die UN-Regelung Nr. 156 zu Software-Updates von Straßenfahrzeugen. Sie macht ein geprüftes Software Update Management System (SUMS) zur Voraussetzung für die Typgenehmigung: Der Hersteller muss jederzeit belegen können, welcher Softwarestand auf welchem Fahrzeugtyp läuft und ob ein Update die Genehmigung berührt. - [V-Modell](https://www.itemis.com/glossar/v-modell/): Das V-Modell ist ein Vorgehensmodell der System- und Softwareentwicklung: Der linke Ast verfeinert Anforderungen schrittweise bis zur Implementierung, der rechte Ast verifiziert jede Ebene gegen ihre Spezifikation. Jeder Entwicklungsstufe steht damit eine eigene Teststufe gegenüber. ## Glossary / Technical Terms (English) - [AI Agent](https://www.itemis.com/en/glossary/ai-agent/): An AI agent is a software system that, based on an LLM, autonomously plans and executes multi-step tasks: it uses tools such as file systems, databases or APIs, evaluates intermediate results and works iteratively towards a given goal — under human oversight. - [ALM](https://www.itemis.com/en/glossary/alm/): ALM (Application Lifecycle Management) refers to the coordinated management of the entire software lifecycle — from requirements through design, implementation and testing to release and maintenance — including the processes and tools that connect these disciplines. - [ASIL](https://www.itemis.com/en/glossary/asil/): ASIL (Automotive Safety Integrity Level) is the risk classification of ISO 26262 for safety-related E/E systems in vehicles. The four levels ASIL A to D determine how rigorous the development, evidence and testing of a function must be. - [Attack Tree](https://www.itemis.com/en/glossary/attack-tree/): An attack tree decomposes an attacker’s goal hierarchically into sub-goals and concrete attack steps. In the TARA according to ISO/SAE 21434, attack trees are used to model attack paths systematically and to rate their feasibility in a traceable way. - [Automotive SPICE](https://www.itemis.com/en/glossary/automotive-spice/): Automotive SPICE (ASPICE) is the automotive industry’s process assessment model for evaluating the maturity of development processes for cyber physical systems. Assessments rate processes on capability levels 0 to 5 — many OEMs require level 2 or 3 from their suppliers. - [AUTOSAR](https://www.itemis.com/en/glossary/autosar/): AUTOSAR (AUTomotive Open System ARchitecture) is a worldwide development partnership of vehicle manufacturers, suppliers and tool vendors that defines a standardized software architecture for automotive ECUs. Its goal is to make software components reusable across manufacturer and platform boundaries. - [Best of Breed](https://www.itemis.com/en/glossary/best-of-breed/): Best of breed refers to the tool strategy of using the best specialized tool for each engineering task instead of relying on the all-in-one suite of a single vendor. The price of specialization is the integration effort between the tools. - [BPMN](https://www.itemis.com/en/glossary/bpmn/): BPMN (Business Process Model and Notation) is the graphical notation standard for modeling business processes standardized by the OMG. BPMN 2.0 models are equally readable for business and IT and directly executable by workflow engines — the diagram is both documentation and executable process. - [Cloud Migration](https://www.itemis.com/en/glossary/cloud-migration/): Cloud migration refers to moving applications, data and infrastructure from your own data center to a cloud environment. The spectrum ranges from an unchanged move (rehosting) to a cloud-native rebuild — which path is viable depends on the application, regulation and economics. - [CSMS](https://www.itemis.com/en/glossary/csms/): A CSMS (Cyber Security Management System) bundles the processes, roles and responsibilities with which a vehicle manufacturer identifies, assesses and treats cybersecurity risks across the entire lifecycle. UNECE R155 makes an audited CSMS a prerequisite for type approval. - [CVD](https://www.itemis.com/en/glossary/cvd/): CVD (Coordinated Vulnerability Disclosure) is the coordinated process through which security researchers and other reporters report vulnerabilities to the manufacturer, with details published only after a remedy is available. The EU Cyber Resilience Act makes a CVD policy a manufacturer obligation. - [CRA](https://www.itemis.com/en/glossary/cyber-resilience-act/): The Cyber Resilience Act (CRA) is the EU regulation with binding cybersecurity minimum requirements for products with digital elements. From 11 September 2026, reporting obligations apply for actively exploited vulnerabilities; from 11 December 2027, all requirements apply, including CE marking. - [DSL](https://www.itemis.com/en/glossary/dsl/): A DSL (Domain-Specific Language) is a programming or modeling language tailored to a clearly delimited subject area. Instead of being universally applicable like Java or C, it captures the concepts, rules and vocabulary of exactly one domain. - [FMEA](https://www.itemis.com/en/glossary/fmea/): FMEA (Failure Mode and Effects Analysis) is a systematic, inductive analysis method: it identifies possible failure modes of a system, evaluates their causes and effects and prioritises countermeasures — before the failures occur in the product. - [Functional Safety](https://www.itemis.com/en/glossary/functional-safety/): Functional safety is the part of a system's safety that depends on the correct functioning of safety-related E/E systems. The goal is the absence of unreasonable risks caused by malfunctions. The basic standard is IEC 61508; in the automotive domain, ISO 26262 applies. - [HARA](https://www.itemis.com/en/glossary/hara/): The HARA (Hazard Analysis and Risk Assessment) is the hazard analysis and risk assessment according to ISO 26262-3. It rates the hazards of a vehicle system by severity, exposure and controllability, derives the ASIL from this and defines the top-level safety goals. - [IEC 61508](https://www.itemis.com/en/glossary/iec-61508/): IEC 61508 is the cross-industry basic standard for the functional safety of electrical, electronic and programmable electronic (E/E/PE) systems. It defines the safety lifecycle and the levels SIL 1 to SIL 4 and is the basis of numerous sector standards such as ISO 26262. - [IEC 62443](https://www.itemis.com/en/glossary/iec-62443/): IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems (OT). Its core concepts are segmentation into zones and conduits and the four security levels SL1 to SL4, which grade the required protection against attackers of varying strength. - [Impact Analysis](https://www.itemis.com/en/glossary/impact-analysis/): Impact analysis uses trace links to determine which artifacts — requirements, architecture, code, tests, evidence — are affected by a change. It makes the costs and risks of a change assessable before the change is implemented. - [ISO 26262](https://www.itemis.com/en/glossary/iso-26262/): ISO 26262 is the international standard for the functional safety of electrical and electronic (E/E) systems in road vehicles. It is derived from IEC 61508, defines an automotive-specific risk scheme with ASIL A to D and covers the entire safety lifecycle. - [ISO/SAE 21434](https://www.itemis.com/en/glossary/iso-sae-21434/): ISO/SAE 21434 is the central cybersecurity standard of the automotive industry. It describes an end-to-end cybersecurity engineering process across the entire vehicle lifecycle — from concept and development through production and operation to decommissioning. - [Language Workbench](https://www.itemis.com/en/glossary/language-workbench/): A language workbench is a development environment for building custom, usually domain-specific languages (DSLs). It provides everything that makes a language practically usable: language definition, an editor with code completion, validation, and code generation or interpretation. - [Legacy Modernization](https://www.itemis.com/en/glossary/legacy-modernization/): Legacy modernization refers to transferring historically grown legacy systems — such as COBOL or mainframe applications — to modern technologies and architectures. The goal is to preserve the proven business logic while improving maintainability, operating costs and release capability. - [Living TARA](https://www.itemis.com/en/glossary/living-tara/): A Living TARA (also Dynamic TARA) is a threat analysis and risk assessment that is kept up to date across the entire product lifecycle. New vulnerabilities, changed components and new attack techniques feed continuously into the risk assessment, instead of only once in the concept phase. - [LLM](https://www.itemis.com/en/glossary/llm/): An LLM (Large Language Model) is a neural network trained on very large amounts of text that models language statistically and thereby understands, summarizes, translates and generates text. LLMs are the technical foundation of chatbots, AI assistants and AI agents. - [MBSE](https://www.itemis.com/en/glossary/mbse/): MBSE (Model-Based Systems Engineering) is a systems engineering approach in which a formal, machine-readable system model — not documents — is the central artefact of development. Requirements, architecture and behaviour are brought together in one consistent model. - [MCP](https://www.itemis.com/en/glossary/mcp/): MCP (Model Context Protocol) is an open standard that connects AI applications such as LLMs and AI agents with external data sources and tools. Instead of building a separate integration for every combination of model and system, one MCP server per system is enough. - [MDSD](https://www.itemis.com/en/glossary/mdsd/): MDSD (Model-Driven Software Development) is a development approach in which formal models are the primary artifacts of software development. Source code is generated automatically from the models instead of being written by hand — reproducibly, consistently and independently of the target platform. - [Metamodel](https://www.itemis.com/en/glossary/metamodel/): A metamodel is the model of a model: it defines which elements, relationships and rules are allowed in a model. Metamodels play the same role for models as a grammar does for languages — they make models formally unambiguous and machine-processable. - [Microservices](https://www.itemis.com/en/glossary/microservices/): Microservices are an architectural style in which an application consists of many small, business-aligned services that are developed, deployed and scaled independently of each other and communicate via interfaces. They increase flexibility and scalability — at the price of higher operational complexity. - [NIS2](https://www.itemis.com/en/glossary/nis2/): NIS2 (Directive (EU) 2022/2555) is the EU directive on the cybersecurity of essential and important entities. It obliges companies in 18 sectors to implement risk management, reporting processes and management accountability — unlike the CRA, it regulates organisations, not products. - [Process Automation](https://www.itemis.com/en/glossary/process-automation/): Process automation refers to the execution of recurring business processes by software — from rule-based workflows through BPM platforms with workflow engines to AI-assisted automation. The goal is to reduce manual routine steps and make processes faster, more traceable and less error-prone. - [RAG](https://www.itemis.com/en/glossary/rag/): RAG (Retrieval-Augmented Generation) is an architectural pattern that supplies an LLM with content from external knowledge sources at answer time: first, documents matching the request are retrieved (retrieval), then the model generates the answer on this basis (generation). - [ReqIF](https://www.itemis.com/en/glossary/reqif/): ReqIF (Requirements Interchange Format) is an XML-based OMG standard for exchanging requirements — including attributes, structure and links — across tools, for example between an OEM and a supplier or between different RM tools. - [Requirements Coverage](https://www.itemis.com/en/glossary/requirements-coverage/): Requirements coverage denotes the degree to which requirements are covered by other development artifacts — typically test cases. Process standards such as Automotive SPICE require it to be measured, but the term is not uniformly defined. - [Requirements Engineering](https://www.itemis.com/en/glossary/requirements-engineering/): Requirements engineering is the systematic discipline of eliciting, documenting, validating and managing requirements for a system over its entire lifecycle. The goal is a shared, verifiable understanding of what the system is supposed to deliver. - [Requirements Traceability](https://www.itemis.com/en/glossary/requirements-traceability/): Requirements traceability is the ability to trace each requirement from its origin through architecture, implementation and testing to validation — in both directions. Standards such as ASPICE, ISO 26262 and the Cyber Resilience Act require it. - [Safety Case](https://www.itemis.com/en/glossary/safety-case/): A safety case is the structured argument that a system is acceptably safe in its context of use — supported by traceable evidence from the development process. ISO 26262 requires it as a central work product for safety-related E/E systems. - [SBOM](https://www.itemis.com/en/glossary/sbom/): An SBOM (Software Bill of Materials) is the machine-readable inventory of all software components of a product, including open-source libraries. The EU Cyber Resilience Act requires it as part of the technical documentation — common formats are SPDX and CycloneDX. - [Security by Design](https://www.itemis.com/en/glossary/security-by-design/): Security by design is the principle of engineering security into a product from the very first concept phase, instead of retrofitting it afterwards through patches. Standards such as ISO/SAE 21434 and laws such as the EU Cyber Resilience Act make the principle binding. - [SIL](https://www.itemis.com/en/glossary/sil/): SIL (Safety Integrity Level) is the risk classification of IEC 61508 for safety-related E/E/PE systems. The four levels SIL 1 to SIL 4 define how improbable the dangerous failure of a safety function must be and how rigorously its development must be assured. - [SOTIF](https://www.itemis.com/en/glossary/sotif/): SOTIF (Safety of the Intended Functionality, ISO 21448) addresses hazards without malfunction: the system works exactly as specified, but the specification or sensor performance is insufficient for the real-world situation — central for driver assistance and AI-based functions. - [SysML](https://www.itemis.com/en/glossary/sysml/): SysML (Systems Modeling Language) is the graphical modelling language for systems engineering standardised by the OMG. It describes requirements, structure and behaviour of complex systems and is the most widespread language for Model-Based Systems Engineering (MBSE). - [Systems Engineering](https://www.itemis.com/en/glossary/systems-engineering/): Systems engineering is the interdisciplinary approach to developing complex technical systems across the entire lifecycle — from stakeholder requirements through architecture and integration to verification and operation. The focus is on the overall system, not the individual discipline. - [TARA](https://www.itemis.com/en/glossary/tara/): TARA (Threat Analysis and Risk Assessment) is the threat analysis and risk assessment method of ISO/SAE 21434. It systematically determines which assets of a vehicle or component need protection, how they can be attacked and how the risks are treated. - [Threat Modeling](https://www.itemis.com/en/glossary/threat-modeling/): Threat modeling is the systematic analysis of a system from an attacker's perspective: which assets are worth protecting, by which paths could an attacker compromise them, and which countermeasures are appropriate? It is the methodological foundation of normative risk analyses such as the TARA. - [TIM](https://www.itemis.com/en/glossary/tim/): A Traceability Information Model (TIM) defines which artifact types of a development process must be connected by which relationship types — the binding blueprint for traceability. TIMs are versioned so that trace links can be validated auditably against a defined model version. - [Tool Qualification](https://www.itemis.com/en/glossary/tool-qualification/): Tool qualification is the evidence according to ISO 26262-8 that a software tool is sufficiently trustworthy for use in safety-related development. Whether it is necessary is determined by the Tool Confidence Level (TCL), derived from tool impact and tool error detection. - [Toolchain Integration](https://www.itemis.com/en/glossary/toolchain-integration/): Toolchain integration connects the tools of an engineering organization — requirements management, modeling, development, testing — into an end-to-end tool chain. It breaks up data silos and enables traceability across tool boundaries. - [Traceability Matrix](https://www.itemis.com/en/glossary/traceability-matrix/): A traceability matrix (RTM) is a table that maps relationships between development artifacts such as requirements and test cases via unique IDs. It establishes bidirectional traceability and makes gaps immediately visible. - [UML](https://www.itemis.com/en/glossary/uml/): UML (Unified Modeling Language) is the graphical modelling language standardised by the OMG for specifying, visualising and documenting software systems. UML 2 defines 14 diagram types in the categories structure and behaviour — from the class diagram to the state machine diagram. - [UML Profile](https://www.itemis.com/en/glossary/uml-profile/): A UML profile is the standardized extension mechanism of UML: through stereotypes, tagged values and constraints, generic model elements are given a domain-specific meaning without changing the language itself or replacing the modeling tool. - [UNECE R155](https://www.itemis.com/en/glossary/unece-r155/): UNECE R155 is UN Regulation No. 155 on the cybersecurity of road vehicles. It makes an audited Cyber Security Management System (CSMS) a prerequisite for type approval: without CSMS evidence, new vehicle types receive no approval in the EU — and thus no market access. - [UNECE R156](https://www.itemis.com/en/glossary/unece-r156/): UNECE R156 is UN Regulation No. 156 on software updates for road vehicles. It makes an audited Software Update Management System (SUMS) a prerequisite for type approval: the manufacturer must be able to prove at any time which software version runs on which vehicle type and whether an update affects the approval. - [V-Model](https://www.itemis.com/en/glossary/v-model/): The V-model is a development model for systems and software engineering: the left branch refines requirements step by step down to implementation, the right branch verifies each level against its specification. Each development level thus faces its own test level. ## Optional - [Vollständiger Seitenindex / Full site index](https://www.itemis.com/llms-full.txt) - [Sitemap](https://www.itemis.com/sitemap.xml)