A software system complies with a regulation if its operation is consistent with the regulation under all circumstances. The importance of regulatory compliance for software systems has been growing, as regulations are increasingly impacting both the functional and non-functional requirements of legacy and new systems. HIPAA and SOX are recent examples of laws with broad impact on software systems, as attested by the billions of dollars spent in the US alone on compliance. In this paper we propose a framework for establishing regulatory compliance for a given set of software requirements. The framework assumes as inputs models of the requirements (expressed in i*) and the regulations (expressed in Nomos). In addition, we adopt and integrate...
Regulatory compliance is a well-studied area, including research on how to model, check, analyse, en...
Regulatory compliance is a well-studied area, including research on how to model, check, analyse, en...
This paper is intended to persuade the academic community of the value of a standard user-friendly s...
During the requirements elicitation phase, analysts have often to take into consideration laws and r...
In modern societies, both business and private life are deeply pervaded by software and information ...
Laws and regulations are increasingly impacting the design and development of software systems, as l...
During the requirements elicitation phase, analysts have often to take into consideration laws and ...
New laws,such as HIPAA and SOX,are increasingly impacting the design of software systems,as business...
The important tasks in requirement engineering are resolving requirements inconsistencies between r...
This research examines regulatory compliance in information systems from a software assurance perspe...
[Context and motivation] The increasing demand of software systems to process and manage sensitive i...
—For software systems that process and manage sensitive information, compliance with laws has becom...
We identify 74 generic, reusable technical requirements based on the GDPR that can be applied to sof...
. Accretion procedure of crimes and security breaches against the privacy of individual’s informati...
Legal texts, such as regulations and legislation, are increasingly playing an important role in requ...
Regulatory compliance is a well-studied area, including research on how to model, check, analyse, en...
Regulatory compliance is a well-studied area, including research on how to model, check, analyse, en...
This paper is intended to persuade the academic community of the value of a standard user-friendly s...
During the requirements elicitation phase, analysts have often to take into consideration laws and r...
In modern societies, both business and private life are deeply pervaded by software and information ...
Laws and regulations are increasingly impacting the design and development of software systems, as l...
During the requirements elicitation phase, analysts have often to take into consideration laws and ...
New laws,such as HIPAA and SOX,are increasingly impacting the design of software systems,as business...
The important tasks in requirement engineering are resolving requirements inconsistencies between r...
This research examines regulatory compliance in information systems from a software assurance perspe...
[Context and motivation] The increasing demand of software systems to process and manage sensitive i...
—For software systems that process and manage sensitive information, compliance with laws has becom...
We identify 74 generic, reusable technical requirements based on the GDPR that can be applied to sof...
. Accretion procedure of crimes and security breaches against the privacy of individual’s informati...
Legal texts, such as regulations and legislation, are increasingly playing an important role in requ...
Regulatory compliance is a well-studied area, including research on how to model, check, analyse, en...
Regulatory compliance is a well-studied area, including research on how to model, check, analyse, en...
This paper is intended to persuade the academic community of the value of a standard user-friendly s...