Jasser, StefanieStefanieJasserTuma, KatjaKatjaTumaScandariato, RiccardoRiccardoScandariatoRiebisch, MatthiasMatthiasRiebisch2021-09-032021-09-032018-01International Conference on Information Systems Security and Privacy (ICISSP 2018)http://hdl.handle.net/11420/10263Today, security is still poorly considered in early phases of software engineering. Architects and software engineers still lack knowledge about architectural security design as well as implementing it compliantly. However, a software system that is not designed for security or does not adhere to this design can hardly meet its security requirements. In this paper, we present an approach we are working on. The approach consists of two parts: Firstly, we improve the architecture’s security level through model transformation. Secondly, we derive rules and constraints from the secured architecture in order to check the implementation’s conformance. Through these activities we aim to support architects and software developers in building a secure software system. We plan to evaluate our approach in industrial case studies.enArchitectural DecayArchitecture Compliance CheckingArchitecture Conformance CheckingArchitecture ErosionArchitecture ViolationsPrivacy by DesignSecure Software ArchitectureSecurity by DesignSecurity ConstraintsSoftware ArchitectureBack to the drawing board bringing security constraints in an architecture-centric software development processConference Paper10.5220/0006659904380446Other