• DocumentCode
    2467336
  • Title

    Legal requirements reuse: a critical success factor for requirements quality and personal data protection

  • Author

    Toval, Ambrosio ; Olmos, Alfonso ; Piattini, Mario

  • Author_Institution
    Dept. of Informatics & Syst., Murcia Univ., Spain
  • fYear
    2002
  • fDate
    2002
  • Firstpage
    95
  • Lastpage
    103
  • Abstract
    Information technology misuse has increased the vulnerability of personal data, which has lead to growing concern about issues of personal privacy among political leaders, IT managers, information security consultants and the millions of people currently online. Many countries have developed, or are preparing, laws and regulations to combat the related threats and to guarantee personal data protection. Despite efforts to construct secure systems, few papers have, as yet, focused on security from the very outset of the system development life-cycle. This paper presents a pragmatic proposal to incorporate the legal and regulatory measures to guarantee personal data protection as a part of the requirements engineering process, instead of an addendum to system deployment. The authors investigate how recent efforts in the requirements engineering field can contribute to improving security issues in information systems, in particular those dealing with personal data. A reusable collection of security requirements and, as a novelty, personal data protection requirements (including information on related software components links) are provided. The pre-defined requirements, together with a simple process model based on requirements reuse, provide a strategy that organizations can use to become privacy-compliant.
  • Keywords
    data privacy; formal specification; legislation; security of data; software reusability; information systems; laws; legal requirements reuse; personal data protection; personal privacy; process model; regulations; requirements quality; reusable security requirements; Data engineering; Data privacy; Data security; Information management; Information security; Information technology; Law; Legal factors; Protection; Technology management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Requirements Engineering, 2002. Proceedings. IEEE Joint International Conference on
  • ISSN
    1090-705X
  • Print_ISBN
    0-7695-1465-0
  • Type

    conf

  • DOI
    10.1109/ICRE.2002.1048511
  • Filename
    1048511