Privacy Requirements: Findings and Lessons Learned in Developing a Privacy Platform

被引:18
|
作者
Gharib, Mohamad [1 ]
Salnitri, Mattia [1 ]
Paja, Elda [1 ]
Giorgini, Paolo [1 ]
Mouratidis, Haralambos [2 ]
Pavlidis, Michalis [2 ]
Ruiz, Jose F. [3 ]
Fernandez, Sandra [4 ]
Della Siria, Andrea [5 ]
机构
[1] Univ Trento, Trento, Italy
[2] Univ Brighton, Brighton, E Sussex, England
[3] Atos, Madrid, Spain
[4] Bambino Gesu Pediat Hosp, Rome, Italy
[5] Business E, Rome, Italy
关键词
Privacy requirements; requirements engineering; elicitation; classification; prioritization; validation;
D O I
10.1109/RE.2016.13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information practices and systems that make use of personal and health-related information are governed by European laws and regulations to prevent unauthorized use and disclosure. Failure to comply with these laws and regulations results in huge monetary sanctions, which both private companies and public administrations want to avoid. How to comply with these laws, requires understanding the privacy requirements imposed on information systems. A holistic approach to privacy requirements specification calls for understanding not only the requirements derived from law, but also citizens' needs with respect to privacy. In this paper, we report on our experience in conducting privacy requirements engineering as part of a H2020 European Project, namely VisiOn (Visual Privacy Management in User Centric Open Requirements) for the development of a privacy platform to improve the interaction between Public Administrations (PA) and citizens, while guarding the privacy of the latter. Specifically, we present the process for eliciting, classifying, prioritizing, and validating privacy requirements for the two types of users, namely PA and citizen. The process is applied to different cases spanning from healthcare to other e-governmental initiatives, with the active involvement of the corresponding PAs. We report on findings and lessons learned from this experience.
引用
收藏
页码:256 / 265
页数:10
相关论文
共 50 条
  • [31] A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements
    Mina Deng
    Kim Wuyts
    Riccardo Scandariato
    Bart Preneel
    Wouter Joosen
    Requirements Engineering, 2011, 16 : 3 - 32
  • [32] Privacy in the Converged Communications Platform
    Radhakrishna, Gita
    INNOVATION AND KNOWLEDGE MANAGEMENT IN BUSINESS GLOBALIZATION: THEORY & PRACTICE, VOLS 1 AND 2, 2008, : 429 - 438
  • [33] Privacy and the Media - A Platform for Change?
    Clarke, Roger
    UNIVERSITY OF WESTERN AUSTRALIA LAW REVIEW, 2012, 36 (1-2):
  • [34] Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platform
    Tsohou, Aggeliki
    Magkos, Emmanouil
    Mouratidis, Haralambos
    Chrysoloras, George
    Piras, Luca
    Pavlidis, Michalis
    Debussche, Julien
    Rotoloni, Marco
    Crespo, Beatriz Gallego-Nicasio
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 531 - 553
  • [35] Using privacy process patterns for incorporating privacy requirements into the system design process
    Kalloniatis, Christos
    Kavakh, Evangelia
    Gritzalis, Stefanos
    ARES 2007: SECOND INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2007, : 1009 - +
  • [36] Early Privacy: Approximating Mental Models in the Definition of Privacy Requirements in Systems Design
    Silva Junior, Deogenes P.
    de Souza, Patricia Cristiane
    de Jesus Goncalves, Thaires A.
    PROCEEDINGS OF THE 17TH BRAZILIAN SYMPOSIUM ON HUMAN FACTORS IN COMPUTING SYSTEMS (IHC 2018), 2015,
  • [37] Learning to Rank Privacy Design Patterns: A Semantic Approach to Meeting Privacy Requirements
    Herwanto, Guntur Budi
    Quirchmayr, Gerald
    Tjoa, A. Min
    REQUIREMENTS ENGINEERING: FOUNDATION FOR SOFTWARE QUALITY, REFSQ 2024, 2024, 14588 : 57 - 73
  • [38] Privacy Policy Specification Framework for Addressing End-Users' Privacy Requirements
    Mohammadi, Nazila Gol
    Leicht, Jens
    Ulfat-Bunyadi, Nelufar
    Heisel, Maritta
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, TRUSTBUS 2019, 2019, 11711 : 46 - 62
  • [39] Privacy Requirements in Cybersecurity Applications of Blockchain
    Axon, Louise
    Goldsmith, Michael
    Creese, Sadie
    BLOCKCHAIN TECHNOLOGY: PLATFORMS, TOOLS AND USE CASES, 2018, 111 : 229 - 278
  • [40] The Importance of Empathy for Analyzing Privacy Requirements
    Levy, Meira
    Hadar, Irit
    2018 IEEE 5TH INTERNATIONAL WORKSHOP ON EVOLVING SECURITY & PRIVACY REQUIREMENTS ENGINEERING (ESPRE 2018), 2018, : 9 - 13