InstaQM: Bridging the Gap between Abstract Quality Models and Actionable Security Practices with Instances
Marco Ehl, Amir Shayan Ahmadian, Katharina Großer, Duaa Adel Ali Elsofi, Marc Herrmann, Alexander Specht, Kurt A. Schneider, Jan Jürjens · 2026
Software engineers (SWEs) need specific and applicable guidance on designing and implementing security throughout the software lifecycle. Existing resources are often generic or lack applicable insights, leaving SWEs to scattered security information in project artifacts. We present InstaQM, a methodology for systematically creating security quality models enriched with textual instances. These models provide a structured representation of security-related concepts and their relations, enabling SWEs to better understand software project artifacts and apply security practices. Our methodology is systematically oriented on the needs of SWEs applying security practices such as STRIDE and LINDDUN, and is based on the standards ISO/IEC 25000 and NIST SP 800-53 so software engineers can use existing knowledge. We populated our quality model by systematically analyzing a large corpus of EU project deliverables. We demonstrate the usefulness of our method on illustrative scenarios in depth based on real project artifacts. To demonstrate usability of our methodology, we provide a tool prototype that uses our quality model to analyze real-world project artifacts.