Legal requirements reuse: A critical success factor for requirements quality and personal data protection

被引:27
|
作者
Toval, A [1 ]
Olmos, A [1 ]
Piattini, M [1 ]
机构
[1] Univ Murcia, Dept Informat & Syst, E-30071 Murcia, Spain
关键词
D O I
10.1109/ICRE.2002.1048511
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Information Technologies misuse has increased the vulnerability of personal data, which has lead to growing concern about issues of personal privacy among political leaders, IT managers, information security consultants and the millions of people currently online. Many countries have developed, or are preparing, Laws and Regulations to combat the related threats and to guarantee Personal Data Protection. Despite efforts to construct secure systems, few papers have, as yet, focused on security from the very outset of the system development life-cycle. This paper presents a pragmatic proposal to incorporate the legal and regulatory measures to guarantee Personal Data Protection as a part of the requirements engineering process, instead of an addendum to system deployment. The authors investigate how recent efforts in the Requirements Engineering field can contribute to improving security issues in Information Systems, in particular those dealing with Personal Data. A reusable collection of security requirements and, as a novelty, Personal Data Protection requirements (including information on related software components links) are provided. The pre-defined requirements, together with a simple process model based on requirements reuse, provide a strategy that organizations can use to become privacy-compliant.
引用
收藏
页码:95 / 103
页数:9
相关论文
共 50 条
  • [1] Legally regulated teleradiology: implementation of data protection legal requirements
    Schuetz, B.
    Kaemmerer, M.
    [J]. RADIOLOGE, 2019, 59 (07): : 637 - 642
  • [2] Water quality requirements for reuse systems
    Colt, J
    [J]. AQUACULTURAL ENGINEERING, 2006, 34 (03) : 143 - 156
  • [3] Legal framework of data protection. Current requirements in Germany and requirements in planned European Union regulations
    Schuetze, B.
    [J]. RADIOLOGE, 2013, 53 (05): : 437 - 440
  • [4] Ensuring Data Readiness for Quality Requirements with Help from Procedure Reuse
    Chirkova, Rada
    Doyle, Jon
    Reutter, Juan
    [J]. ACM JOURNAL OF DATA AND INFORMATION QUALITY, 2021, 13 (03):
  • [5] Sharing and Reuse of Sensitive Data and Samples: Supporting Researchers in Identifying Ethical and Legal Requirements
    Sariyar, Murat
    Schluender, Irene
    Smee, Carol
    Suhr, Stephanie
    [J]. BIOPRESERVATION AND BIOBANKING, 2015, 13 (04) : 263 - 270
  • [6] MEDICAL REQUIREMENTS FOR DATA PROTECTION
    POMMERENING, K
    [J]. INFORMATION PROCESSING '94, VOL II: APPLICATIONS AND IMPACTS, 1994, 52 : 533 - 540
  • [7] Personal data management inside and out Integrating data protection requirements in the data life cycle
    Labadie, Clement
    Legner, Christine
    [J]. ENTERPRISE MODELLING AND INFORMATION SYSTEMS ARCHITECTURES-AN INTERNATIONAL JOURNAL, 2020, 15
  • [8] The Effect of Requirements Quality and Requirements Volatility on the Success of Information Systems Projects
    Osama, Eman
    Khedr, Ayman
    Abdelsalam, Mohamed
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (09) : 420 - 425
  • [9] Data Protection by Design in Systems Development From legal requirements to technical solutions
    Blix, Fredrik
    Elshekeil, Salah Addin
    Laoyookhong, Saran
    [J]. 2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 98 - 103
  • [10] CONSENT IN THE CURRENT DATA PROTECTION REGULATION: NEW LEGAL LANDSCAPE AND NEW REQUIREMENTS
    Del Castillo Vazquez, Isabel-Cecilia
    [J]. FORO-REVISTA DE CIENCIAS JURIDICAS Y SOCIALES. NUEVAEPOCA, 2020, 23 (02): : 149 - 182