VLDB 2026 Research / reviewers in the wild / expert
Tomás San Feliu Gilabert
dblp:02/5492 · also Tomás San Feliu
· DBLP profile ↗
30ranked-venue papers
0as first author
4since 2021 · last 2025
0000-0002-6104-7430ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 29 · 3 since 2021Artificial intelligence and machine learning · 1Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Cybersecurity Vulnerabilities Management for Small and Medium Enterprises
José Antonio Calvo-Manzano, Tomás San Feliu Gilabert, Ángel Herranz-Nieva, Julio Mariño-Carballo, Lars-Åke Fredlund, Ricardo Colomo-Palacios, Ana M. Moreno |
EuroSPI (1) | 2 |
| 2025 | CyberESP: An Integrated Cybersecurity Framework for SMEsabstractABSTRACT Cybersecurity is a critical global concern, particularly for small‐ and medium‐sized enterprises (SMEs) with limited resources and expertise. The authors are developing CyberESP, a tailored cybersecurity framework supported by a semi‐automated tool to ensure Spanish SMEs' cybersecurity management. Following the Design Science Research (DSR) methodology and grounded in international standards, the authors identified six requirements to be satisfied by a cybersecurity framework for SMEs, which should support the identification of assets, vulnerabilities, threats, and risks. This paper presents the first part of the CyberESP framework dealing with asset management, particularly their identification and analysis of dimensions and cost. A prototype supporting these activities was developed and validated through a case study in a retail SME, showing the solution's potential and identifying particular improvements. The paper also addresses threats to validity and limitations, noting the framework's focus on hardware, software, and networks. Future work includes vulnerability management and will explore the use of cloud and IoT deployment, positioning CyberESP as a practical solution to enhance SMEs' cybersecurity resilience. José Antonio Calvo-Manzano, Tomás San Feliu Gilabert, Ángel Herranz-Nieva, Julio Mariño-Carballo, Lars-Åke Fredlund, Ana María Moreno 0001 |
J. Softw. Evol. Process. | 2 |
| 2024 | Towards an Integrated Cybersecurity Framework for Small and Medium Enterprises
José Antonio Calvo-Manzano, Tomás San Feliu Gilabert, Ángel Herranz-Nieva, Julio Mariño-Carballo, Lars-Åke Fredlund, Ricardo Colomo-Palacios, Ana María Moreno 0001 |
EuroSPI (1) | 2 |
| 2023 | Countermeasures and their taxonomies for risk treatment in cybersecurity: A systematic mapping reviewabstractCybersecurity continues to be one of the principal issues in the computing environment. Organizations and researchers have made various efforts to mitigate the risks of cyberspace. The treatment of cyber risk is a fundamental stage in risk management. In the risk treatment stage, countermeasures are carried out to reduce the probability of risk materialization. This article presents a systematic mapping review of the principal catalogues/taxonomies of countermeasures applied in cybersecurity, involving studies between 2010 and 2021. Seventy-four (74) studies were assessed, and 25 studies were selected for further analysis. We identified 26 catalogues/taxonomies used to address cybersecurity-related risks. After analyzing these 26 catalogues/taxonomies, we identified: (1) the related trends, (2) the type of risks and sectors that these catalogues/taxonomies focus on, (3) the complexity of these taxonomies, and (4) what mentions they make about residual risk. We have identified that institutional taxonomies, which were not created for cybersecurity risks, are fitted for this purpose. The predominant risks in these taxonomies are those related to awareness and cyber-attacks. We note that the complexity of the catalogues/taxonomies is defined by the number of taxa and the number of countermeasures. Another relevant result is the lack of complexity in non-institutional catalogues/taxonomies. Finally, we have identified a lack of relevant information on residual risk in the studies. Isaac D. Sánchez-García, Tomás San Feliu Gilabert, José Antonio Calvo-Manzano |
Comput. Secur. | 2 |
| 2017 | Comparative Study of Cybersecurity Capability Maturity Models
Angel Marcelo Rea-Guaman, Tomás San Feliu Gilabert, José Antonio Calvo-Manzano, Isaac Daniel Sanchez-Garcia |
SPICE | 2 |
| 2016 | Analysis of Tools for Assessing the Implementation and Use of Agile Methodologies in SMEs
Mirna Muñoz 0001, Jezreel Mejia, Brisia Corona, José Antonio Calvo-Manzano, Tomás San Feliu Gilabert, Juan Miramontes |
SPICE | 5 |
| 2014 | MIN-ITs: A Framework for Integration of IT Management Standards in Mature EnvironmentsabstractThe growing interest of software companies for improving their internal processes, not just software development processes, but also processes in other domains such as Information Technology (IT) service management or information security management, has encouraged these companies to implement recognized models or standards. Most of the ISO standards that define models for software quality, IT service management or information security management provide their recommendations, guidelines, requirements or good practices under a process approach. Due to this approach, there are a large number of relations between these models as well as many common elements. From the study of these relations, this paper presents MIN-ITs, a new framework that supports the integration of different ISO standards related to IT management. Antoni-Lluís Mesquida, Antònia Mas Pichaco, Tomás San Feliu Gilabert, Magdalena Arcilla-Cobián |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2014 | High-maturity levels: achieving CMMI ML-5 in a consultancy companyabstractABSTRACT Most organizations that use the Capability Maturity Model Integration (CMMI) stop their process improvement journey at Maturity Level 3 or less. The discussion about CMMI high‐maturity levels has always been controversial, going most of the times through the consideration of return of investment, provider selection, and interpretation issues. Achieving Level 5 is not an easy task; it derives a lot of steps during the way. This article will show an example of the implementation of Level 5 in a consultancy company in two constellations: development and service. It depicts the example in steps, to help the understanding of the whole process. Copyright © 2014 John Wiley & Sons, Ltd. Lucas Grossi, José Antonio Calvo-Manzano, Tomás San Feliu Gilabert |
J. Softw. Evol. Process. | 3 |
| 2014 | An empirically validated simulation for understanding the relationship between process conformance and technology skills
Santiago Matalonga, Martín Solari, Tomás San Feliu Gilabert |
Softw. Qual. J. | 3 |
| 2014 | Critical success factors taxonomy for software process deployment
Sussy Bayona Oré, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
Softw. Qual. J. | 4 |
| 2013 | Review of Critical Success Factors Related to People in Software Process Improvement
Sussy Bayona Oré, José Antonio Calvo-Manzano, Tomás San Feliu Gilabert |
EuroSPI | 3 |
| 2013 | Involvement of Stakeholders in Software Processes Improvement to Reduce Change Resistance
Mirna Muñoz 0001, Jezreel Mejia, José Antonio Calvo-Manzano, Tomás San Feliu Gilabert |
EuroSPI | 4 |
| 2013 | Risk Taxonomy Related to Software Acquisition: a Case StudyabstractCurrently, software acquisition is strategic for organizations. Companies need support to succeed in software acquisition projects because such projects commonly present high failure rates. To solve this problem, it is necessary to design mechanisms for software acquisition, such as risk classification to identify the typical risks that may affect the success of a software acquisition project. Thus, herein, we present a case study, showing the implementation of a risk taxonomy whose structure is designed using a method for its construction, with a mechanism to reduce the risk of acquisition projects that adversely affect their success. Gloria Piedad Gasca-Hurtado, Guillermo González Calderón, José Antonio Calvo-Manzano, Tomás San Feliu Gilabert |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2012 | MEDEPRO: A Method to Deploy Processes Focused on People
Sussy Bayona Oré, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
EuroSPI | 4 |
| 2012 | A Case Study on Process Composition Using Enterprise SPICE Model
Amalia Alvarez, Santiago Matalonga, Tomás San Feliu Gilabert |
SPICE | 3 |
| 2012 | Critical Success Factors in Software Process Improvement: A Systematic Review
Sussy Bayona Oré, José Antonio Calvo-Manzano, Tomás San Feliu Gilabert |
SPICE | 3 |
| 2012 | A State of Art of Software Improvement Implementation Support Tools in SMEs
Mirna Muñoz 0001, Antonio de Amescua Seco, Jezreel Mejia, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
SPICE | 6 |
| 2012 | Methodology for process improvement through basic components and focusing on the resistance to changeabstractSUMMARY This paper describes a multi‐model methodology that implements a smooth and continuous process improvement, depending on the organization's business goals and allowing users to establish their improvement implementation pace. The methodology focuses on basic process components known as ‘best practices’. Besides, it covers following the topics: knowledge management and change management. The methodology description and the results of a case study on project management process are included. Copyright © 2010 John Wiley & Sons, Ltd. José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Gerzón Gómez, Jezreel Mejia, Mirna Muñoz 0001, Tomás San Feliu Gilabert |
J. Softw. Evol. Process. | 6 |
| 2012 | Managing the software process with a software process improvement tool in a small enterpriseabstractSUMMARY Top‐down process improvement approaches provide a high‐level model of what the process of a software development organization should be. Such models are based on the consensus of a designated working group on how software should be developed or maintained. They are very useful in that they provide general guidelines on where to start improving, and in which order. However, the majority of them have only worked in scenarios within large companies. We aim to help small software development organizations to adopt an iterative approach by providing a Process Improvement Web‐based Tool (SysProVal). This paper presents research into the proposal that a small organization may use this tool to define and implement a set of project management practices that can be strengthened using the CMMI‐DEV 1.2 model as reference. Copyright © 2010 John Wiley & Sons, Ltd. Iván A. García, Carla Pacheco 0001, Eloy Mendoza, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
J. Softw. Evol. Process. | 6 |
| 2011 | Introducing Scrum in a Very Small Enterprise: A Productivity and Quality Analysis
Edgar Caballero, José Antonio Calvo-Manzano, Tomás San Feliu Gilabert |
EuroSPI | 3 |
| 2011 | A Multi-model Workflow before Establishing an Acquisition Contract Based on CMMI-ACQ Model
Jezreel Mejia, Mirna Muñoz 0001, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
EuroSPI | 5 |
| 2010 | Implementation of Software Process Improvement through TSPi in Very Small Enterprises
Edgar Caballero, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
EuroSPI | 4 |
| 2010 | Approach to Identify Internal Best Practices in a Software Organization
José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Jezreel Mejia, Mirna Muñoz 0001, Tomás San Feliu Gilabert, Angel Sánchez, Álvaro Rocha 0001 |
EuroSPI | 5 |
| 2008 | Teaching Team Software Process in Graduate Courses to Increase Productivity and Improve Software QualityabstractThis paper presents a case study that describes TSPi teaching (Introduction to the Team Software Process) to 4th year students, grouped by teams, at the Computer Science School, Polytechnic University of Madrid (UPM). The achievements of the teams, due to training and the use of TSPi, were analyzed and discussed. This paper briefly discusses the approach to the teaching and some of the issues that were identified. The teams collected data on the projects developed. They reviewed the schedule and quality status weekly. The metrics selected to analyze the impact on the students were: size, effort, productivity, costs and defects density. These metrics were chosen to analyze teams' performance evolution through project development. This paper also presents a study related to the evolution of estimation, quality and productivity improvements these teams obtained. This study will prove that training in TSPi has a positive impact on getting better estimations, reducing costs, improving productivity, and decreasing defect density. Finally, the teams' performance are analyzed. Sussy Bayona Oré, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
COMPSAC | 4 |
| 2008 | A Solution for Establishing the Information Technology Service Management Processes Implementation Sequence
Magdalena Arcilla-Cobián, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Gerzón Gómez, Elena Ruiz, Tomás San Feliu Gilabert |
EuroSPI | 6 |
| 2008 | A Process Asset Library to Support Software Process Improvement in Small Settings
José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert, Ariel Serrano |
EuroSPI | 3 |
| 2008 | Linking Return on Training Investment with Defects Causal Analysis
Santiago Matalonga, Tomás San Feliu Gilabert |
SEKE | 2 |
| 2008 | Using the TSPi Defined Process and Improving the Project Management ProcessabstractTeam Software Process is an integrated framework that guides development teams in producing high-quality software-intensive systems. This paper analyzes the effects of TSPi training and the improvements achieved by 44 teams, comprising fourth-year students on the software engineering degree programme, corresponding to two academic years. This study shows the benefits of using defined models such as TSPi to improve the students’ skills and knowledge. The metrics of size and effort estimation, defects, productivity and costs are collected to measure the improvements through two development cycles. Sussy Bayona Oré, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
SERA | 4 |
| 2007 | Determining Practice Achievement in Project Management Using a Two-Phase Questionnaire on Small and Medium Enterprises
Iván A. García, José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert |
EuroSPI | 4 |
| 2002 | Experiences in the Application of Software Process Improvement in SMES
José Antonio Calvo-Manzano, Gonzalo Cuevas Agustín, Tomás San Feliu Gilabert, Antonio de Amescua Seco, Luis García Sánchez, Manuel Pérez Cota |
Softw. Qual. J. | 3 |