Privacy Requirements: Findings and Lessons Learned in Developing a Privacy Platform

被引:18
|
作者
Gharib, Mohamad [1 ]
Salnitri, Mattia [1 ]
Paja, Elda [1 ]
Giorgini, Paolo [1 ]
Mouratidis, Haralambos [2 ]
Pavlidis, Michalis [2 ]
Ruiz, Jose F. [3 ]
Fernandez, Sandra [4 ]
Della Siria, Andrea [5 ]
机构
[1] Univ Trento, Trento, Italy
[2] Univ Brighton, Brighton, E Sussex, England
[3] Atos, Madrid, Spain
[4] Bambino Gesu Pediat Hosp, Rome, Italy
[5] Business E, Rome, Italy
关键词
Privacy requirements; requirements engineering; elicitation; classification; prioritization; validation;
D O I
10.1109/RE.2016.13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information practices and systems that make use of personal and health-related information are governed by European laws and regulations to prevent unauthorized use and disclosure. Failure to comply with these laws and regulations results in huge monetary sanctions, which both private companies and public administrations want to avoid. How to comply with these laws, requires understanding the privacy requirements imposed on information systems. A holistic approach to privacy requirements specification calls for understanding not only the requirements derived from law, but also citizens' needs with respect to privacy. In this paper, we report on our experience in conducting privacy requirements engineering as part of a H2020 European Project, namely VisiOn (Visual Privacy Management in User Centric Open Requirements) for the development of a privacy platform to improve the interaction between Public Administrations (PA) and citizens, while guarding the privacy of the latter. Specifically, we present the process for eliciting, classifying, prioritizing, and validating privacy requirements for the two types of users, namely PA and citizen. The process is applied to different cases spanning from healthcare to other e-governmental initiatives, with the active involvement of the corresponding PAs. We report on findings and lessons learned from this experience.
引用
收藏
页码:256 / 265
页数:10
相关论文
共 50 条
  • [1] Developing Privacy-preserving AI Systems: The Lessons learned
    Chen, Huili
    Hussain, Siam Umar
    Boemer, Fabian
    Stapf, Emmanuel
    Sadeghi, Ahmad Reza
    Koushanfar, Farinaz
    Cammarota, Rosario
    PROCEEDINGS OF THE 2020 57TH ACM/EDAC/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2020,
  • [2] Designing a social protocol: Lessons learned from the platform for privacy preferences project
    Cranor, LF
    Reagle, J
    TELEPHONY, THE INTERNET, AND THE MEDIA, 1998, : 215 - 232
  • [3] Lessons Learned From Applying the NIST Privacy Framework
    Carter, Thomas
    Kroll, Joshua A.
    Michael, James Bret
    IT PROFESSIONAL, 2021, 23 (04) : 9 - 13
  • [4] Engineering Privacy Requirements Valuable Lessons from Another
    Martin, Yod-Samuel
    del Alamo, Jose M.
    Yelmo, Juan C.
    2014 IEEE 1ST WORKSHOP ON EVOLVING SECURITY AND PRIVACY REQUIREMENTS ENGINEERING (ESPRE), 2014, : 19 - 24
  • [5] Developing groupware for requirements negotiation:: Lessons learned
    Boehm, B
    Grünbacher, P
    Briggs, RO
    IEEE SOFTWARE, 2001, 18 (03) : 46 - +
  • [6] Developing a requirements management toolset: Lessons learned
    Babar, MA
    Zowghi, D
    2004 AUSTRALIAN SOFTWARE ENGINEERING CONFERENCE, PROCEEDINGS, 2004, : 10 - 19
  • [7] Evaluating a privacy requirements specification method by using a mixed-method approach: results and lessons learned
    Mariana Peixoto
    Carla Silva
    João Araújo
    Tony Gorschek
    Alexandre Vasconcelos
    Jéssyka Vilela
    Requirements Engineering, 2023, 28 : 229 - 255
  • [8] Evaluating a privacy requirements specification method by using a mixed-method approach: results and lessons learned
    Peixoto, Mariana
    Silva, Carla
    Araujo, Joao
    Gorschek, Tony
    Vasconcelos, Alexandre
    Vilela, Jessyka
    REQUIREMENTS ENGINEERING, 2023, 28 (02) : 229 - 255
  • [9] A Platform for Developing Privacy Preserving Diagnosis Mobile Applications
    Ucan, Sanem
    Gu, Huanying
    2014 IEEE-EMBS INTERNATIONAL CONFERENCE ON BIOMEDICAL AND HEALTH INFORMATICS (BHI), 2014, : 509 - 512
  • [10] Enforcement of Privacy Requirements
    Krishnan, Padmanabhan
    Vorobyov, Kostyantyn
    SECURITY AND PRIVACY PROTECTION IN INFORMATION PROCESSING SYSTEMS, 2013, 405 : 272 - 285