Privacy Requirements: Findings and Lessons Learned in Developing a Privacy Platform

被引:18
|
作者
Gharib, Mohamad [1 ]
Salnitri, Mattia [1 ]
Paja, Elda [1 ]
Giorgini, Paolo [1 ]
Mouratidis, Haralambos [2 ]
Pavlidis, Michalis [2 ]
Ruiz, Jose F. [3 ]
Fernandez, Sandra [4 ]
Della Siria, Andrea [5 ]
机构
[1] Univ Trento, Trento, Italy
[2] Univ Brighton, Brighton, E Sussex, England
[3] Atos, Madrid, Spain
[4] Bambino Gesu Pediat Hosp, Rome, Italy
[5] Business E, Rome, Italy
关键词
Privacy requirements; requirements engineering; elicitation; classification; prioritization; validation;
D O I
10.1109/RE.2016.13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information practices and systems that make use of personal and health-related information are governed by European laws and regulations to prevent unauthorized use and disclosure. Failure to comply with these laws and regulations results in huge monetary sanctions, which both private companies and public administrations want to avoid. How to comply with these laws, requires understanding the privacy requirements imposed on information systems. A holistic approach to privacy requirements specification calls for understanding not only the requirements derived from law, but also citizens' needs with respect to privacy. In this paper, we report on our experience in conducting privacy requirements engineering as part of a H2020 European Project, namely VisiOn (Visual Privacy Management in User Centric Open Requirements) for the development of a privacy platform to improve the interaction between Public Administrations (PA) and citizens, while guarding the privacy of the latter. Specifically, we present the process for eliciting, classifying, prioritizing, and validating privacy requirements for the two types of users, namely PA and citizen. The process is applied to different cases spanning from healthcare to other e-governmental initiatives, with the active involvement of the corresponding PAs. We report on findings and lessons learned from this experience.
引用
收藏
页码:256 / 265
页数:10
相关论文
共 50 条
  • [41] Privacy requirements implemented with a Java']JavaCard
    el Kalam, AA
    Deswarte, Y
    21ST ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2005, : 479 - 488
  • [42] TECHNICAL IMPLICATIONS OF PRIVACY PROTECTION REQUIREMENTS
    TURN, R
    INFORMATION PRIVACY, 1980, 2 (01): : 2 - 6
  • [43] Rethinking Privacy Beyond Borders Developing Transnational Rights on Data Privacy
    Lachmayer, Konrad
    TILBURG LAW REVIEW-JOURNAL OF INTERNATIONAL AND COMPARATIVE LAW, 2015, 20 (01): : 78 - 102
  • [44] Comparing Privacy Requirements Engineering Approaches
    Beckers, Kristian
    2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 574 - 581
  • [45] Distilling Privacy Requirements for Mobile Applications
    Thomas, Keerthi
    Bandara, Arosha K.
    Price, Blaine A.
    Nuseibeh, Bashar
    36TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2014), 2014, : 871 - 882
  • [46] Visualising privacy and security for requirements engineering
    Kreeger, MN
    Duncan, I
    SERP'04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING RESEARCH AND PRACTICE, VOLS 1 AND 2, 2004, : 813 - 819
  • [47] Privacy requirements in identity management solutions
    Bhargav-Spantzel, Abhilasha
    Squicciarini, Anna C.
    Young, Matthew
    Bertino, Elisa
    HUMAN INTERFACE AND THE MANAGEMENT OF INFORMATION: INTERACTING IN INFORMATION ENVIRONMENTS, PT 2, PROCEEDINGS, 2007, 4558 : 694 - +
  • [48] Security and privacy requirements in interactive TV
    Dhiah el Diehn I. Abou-Tair
    Ingo Köster
    Kathrin Höfke
    Multimedia Systems, 2011, 17 : 393 - 408
  • [49] A Taxonomy of Requirements for the Privacy Goal Transparency
    Meis, Rene
    Wirtz, Roman
    Heisel, Maritta
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, 2015, 9264 : 195 - 209
  • [50] Managing information privacy - Developing a context for security and privacy standards convergence
    Robbins, Jim
    Sabo, John T.
    IEEE SECURITY & PRIVACY, 2006, 4 (04) : 92 - 95