Journal Title
Title of Journal: Requirements Eng
|
Abbravation: Requirements Engineering
|
Publisher
Springer-Verlag
|
|
|
|
Authors: David G Gordon Travis D Breaux
Publish Date: 2013/04/04
Volume: 18, Issue: 2, Pages: 147-173
Abstract
Companies that own license or maintain personal information face a daunting number of privacy and security regulations Companies are subject to new regulations from one or more governing bodies when companies introduce new or existing products into a jurisdiction when regulations change or when data are transferred across political borders To address this problem we developed a framework called “requirements water marking” that business analysts can use to align and reconcile requirements from multiple jurisdictions municipalities provinces nations to produce a single high or low standard of care We evaluate the framework in two empirical case studies covering a subset of US data breach notification laws and medical record retention laws In these studies applying our framework reduced the number of requirements a company must comply with by 76 across 8 jurisdictions and 15 across 4 jurisdictions respectively We show how the framework surfaces critical requirements tradeoffs and potential regulatory conflicts that companies must address during the reconciliation process We summarize our results including surveys of information technology law experts to contextualize our empirical results in legal practiceWe thank the CMU Requirements Engineering Lab for participating in reviews of our research protocol and early drafts on this manuscript and we thank the International Association of Privacy Professionals IAPP for allowing us to recruit survey participants through their Global Privacy Summit This research was supported by the US Department of Homeland Security Grant Award 2006CS001000001 and HewlettPackard Labs Innovation Research Program Award CW267287The contextfree grammar for an early version of the LRSL is expressed here in the Extended Backus–Naur Form EBNF described in ISO/IEC 14977 1996E The term “string” consists of any combination of letters and digits the term “regex” is a regular expression and the term ref is a string Open image in new window
Keywords:
.
|
Other Papers In This Journal:
|