Context: Tracing is a core competence in requirements engineering. Particularly, in safety & security critical domains, tracing is often not only beneficial but even required by industry or government standards. In the tracing process, linked artifacts and the activities that process or create them are essential. To capture trace link candidates and provide recommendations to developers, it is necessary to identify which artifacts and activities exist and how they relate to one another. However, there is currently no comprehensive overview of safety & security-relevant artifacts and activities. Objectives: We aim to compile a collection of all relevant artifacts and activities that employ tracing in security- and safety-critical domains. We would also like to suggest potential trace-link candidates to facilitate tracing. Methods: In our approach, we conduct a literature review and examine the well-documented Corona Warn App as the subject of our investigation. Results: We examined n = 259 publications from safety & security-related traceability research for artifacts and activities. We identified and compiled 437 artifact types and 254 activities into a comprehensive data collection. Our findings include (1) the most frequently appearing artifacts and activities, (2) the most common co-appearing artifacts and activities, and (3) the most frequently appearing artifacts and activities related to specific domains such as military defense, aerospace, and software management and (4) an example how to use our collection on an example to the Corona Warn App. Conclusion: We discuss recommendations for developers, the importance of collaboration and communication in tracing processes, the identification of patterns in artifacts and activities during tracing, and the implications of our findings for industry settings, as well as directions for future work.
Specht et al. (Fri,) studied this question.