Perspectives on Regulatory Compliance in Software Engineering

被引:6
|
作者
Kempe, Evelyn [1 ]
Massey, Aaron [1 ]
机构
[1] Univ Maryland Baltimore Cty, Dept Informat Syst, Baltimore, MD 21228 USA
基金
美国国家科学基金会;
关键词
PRIVACY;
D O I
10.1109/RE51729.2021.00012
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Compliance reviews within a software organization are internal attempts to verify regulatory and security requirements during product development before its release. However, these reviews are not enough to adequately assess and address regulatory and security requirements throughout a software's development lifecycle. We believe requirements engineers can benefit from an improved understanding of how software practitioners treat and perceive compliance requirements. This paper describes an interview study seeking to understand how regulatory and security standard requirements are addressed, how burdensome they may be for businesses, and how our participants perceived them in the software development lifecycle. We interviewed 15 software practitioners from 13 organizations with different roles in the software development process and working in various industry domains, including big tech, healthcare, data analysis, finance, and small businesses. Our findings suggest that, for our participants, the software release process is the ultimate focus for regulatory and security compliance reviews. Also, most participants suggested that having a defined process for addressing compliance requirements was freeing rather than burdensome. Finally, participants generally saw compliance requirements as an investment for both employees and customers. These findings may be unintuitive, and we discuss seven lessons this work may hold for requirements engineering.
引用
收藏
页码:46 / 57
页数:12
相关论文
共 50 条
  • [41] An Empirical Study of Practitioners' Perspectives on Green Software Engineering
    Manotas, Irene
    Bird, Christian
    Zhang, Rui
    Shepherd, David
    Jaspan, Ciera
    Sadowski, Caitlin
    Pollock, Lori
    Clause, James
    2016 IEEE/ACM 38TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE), 2016, : 237 - 248
  • [42] Advancing software engineering education: New practices and perspectives
    Saiedian, Hossein
    Washizak, Hironori
    JOURNAL OF SYSTEMS AND SOFTWARE, 2019, 147 : 104 - 105
  • [43] Editors' introduction: Comparative software engineering: Review and perspectives
    Wang, YX
    Patel, D
    ANNALS OF SOFTWARE ENGINEERING, 2000, 10 : 1 - 10
  • [44] Automotive software engineering - Current situation, perspectives and challenges
    Schauffele, Jorg
    Zurawka, Thomas
    ATZ Automobiltechnische Zeitschrift, 2002, 104 (SUPPL.) : 10 - 18
  • [45] Providing End-to-End Perspectives in Software Engineering
    Herold, Michael
    Bolinger, Joe
    Ramnath, Rajiv
    Bihari, Thomas
    Ramanathan, Jay
    2011 FRONTIERS IN EDUCATION CONFERENCE (FIE), 2011,
  • [46] Leveraging Taxonomical Engineering for Security Baseline Compliance in International Regulatory Frameworks
    Grigaliunas, Sarunas
    Schmidt, Michael
    Bruzgiene, Rasa
    Smyrli, Panayiota
    Bidikov, Vladislav
    FUTURE INTERNET, 2023, 15 (10):
  • [48] How to Integrate Security Compliance Requirements with Agile Software Engineering at Scale?
    Moyon, Fabiola
    Mendez, Daniel
    Beckers, Kristian
    Klepper, Sebastian
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT (PROFES 2020), 2020, 12562 : 69 - 87
  • [49] Senior management perspectives on ISO/IEC software engineering standards
    Weber, K
    Almeida, R
    FOURTH IEEE INTERNATIONAL SYMPOSIUM AND FORUM ON SOFTWARE ENGINEERING STANDARDS - PROCEEDINGS, 1999, : 244 - 244
  • [50] Social Impact of Smart Environments: Software Engineering Perspectives and Challenges
    McDonald, Stuart
    Towey, Dave
    Brusic, Vladimir
    2022 IEEE 46TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2022), 2022, : 1592 - 1597