Research ArticleOpen AccessGoogle Scholar indexed
Interpretation of Information Processing Regulations
- 1
Journal of Software Engineering and Applications·Volume 02 (2009)·Pages 67–76·Published 15 July 2009·DOI10.4236/jsea.2009.22011
Copy link · social · email
Abstract
Laws and policies impose many information handling requirements on business practices. Compliance with such regu-lations requires identification of conflicting interpretations of regulatory conditions. Current software engineering methods extract software requirements by converting legal text into semiformal constraints and rules. In this paper we complement these methods with a state-based model that includes all possibilities of information flow. We show that such a model provides a foundation for the interpretation process.
KeywordsSoftware RequirementLawsRegulationPrivacyPersonal Identifiable Information
- [1] D. Reinsel, C. Chute, W. Schlichting, J. McArthur, I. Xheneti, A. Toncheva, and A. Manfrediz, “A for- ecast of worldwide information growth through 2010.” An IDC White Paper, 2007. http://www.emc.com/about/destina-tion/digital_universe/pdf/Expanding_Digital_Universe_I-DC_WhitePaper_022507.pdf
- [2] Nexsan Technologies Inc, White paper on enabling in-formation lifecycle management, 2005. http://www.me- ganet1.com/pdf/Enabling%20Information%20Lifecycle%20management.pdf
- [3] M. J. May, C. A. Gunter, and I. Lee, “Privacy APIs: Ac-cess control techniques to analyze and verify legal pri-vacy policies,” 19th IEEE Workshop Computer Security Foundations, pp. 85-97, 2006.
- [4] T. D. Breaux and A. I. Antón, “Deriving semantic models from privacy policies,” 6th IEEE International Workshop on Policies for Distributed Systems and Networks, pp. 67-76, 2005.
- [5] S-W. Lee, R. Gandhi, D. Muthurajan, D. Yavagal, and G- J. Ahn, “Building problem domain ontology from secu-rity requirements in regulatory documents,” International Workshop on Software Engineering for Secure Systems, Shanghai, China, pp. 43-50, 2006.
- [6] A. I. Antón, J. B. Earp, Q. He, W. Stufflebeam, D. Bol-chini, and C. Jensen, “Financial privacy policies and the need for standardization,” IEEE Security and Privacy, Vol. 2, No. 2, pp. 36-45, 2004.
- [7] A. I. Antón, “Goal-based requirements analysis,” 2nd IEEE International Conference on Requirements Engi-neering, pp. 136-144, 1996.
- [8] T. D. Breaux and A. I. Antón, “Analyzing goal semantics for rights, permissions and obligations,” 13th IEEE In-ternational Conference on Requirements Engineering, pp. 177-186, 2005.
- [9] P. Giorgini, F. Massacci, J. Mylopoulos, and N. Zannone, “Modeling security requirements through ownership, permission and delegation,” 13th IEEE International Conference on Requirements Engineering, pp. 167-176, 2005.
- [10] T. Breaux and A. I. Antón, “Analyzing regulatory rules for privacy and security requirements,” IEEE Transac-tions on Software Engineering, Vol. 34, No. 1, pp. 5-20, January 2008.
- [11] D. Tindal, “Safety officer’s briefing book,” Civil Air Patrol, United States Air Force Auxiliary, February 1 2000. http://www.iawg.cap.gov/archives/ iawgsafety-manual.pdf.
- [12] S. Al-Fedaghi, “Scrutinizing the rule: Privacy realization in HIPAA,” International Journal of Healthcare Informa-tion Systems and Informatics (IJHISI), Vol. 3, No. 2, 2008.