Privacy requirements elicitation: a systematic literature review and perception analysis of IT practitioners

被引:10
|
作者
Canedo, Edna Dias [1 ]
Bandeira, Ian Nery [1 ]
Seidel Calazans, Angelica Toffano [2 ]
Teixeira Costa, Pedro Henrique [1 ]
Rodrigues Cancado, Emille Catarine [1 ]
Bonifacio, Rodrigo [1 ]
机构
[1] Univ Brasilia UnB, Dept Comp Sci, POB 4466, BR-70910900 Brasilia, DF, Brazil
[2] Univ Ctr UniCEUB, Brasilia, DF, Brazil
关键词
Privacy requirements elicitation; Systematic literature review; Methodologies; Techniques; Tools; SECURITY REQUIREMENTS;
D O I
10.1007/s00766-022-00382-8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During the software development process and throughout the software lifecycle, organizations must guarantee users' privacy by protecting personal data. There are several studies in the literature proposing methodologies, techniques, and tools for privacy requirements elicitation. These studies report that practitioners must use systematic approaches to specify these requirements during initial software development activities to avoid users' data privacy breaches. The main goal of this study is to identify which methodologies, techniques, and tools are used in privacy requirements elicitation in the literature. We have also investigated Information Technology (IT) practitioners' perceptions regarding the methodologies, techniques, and tools identified in the literature. We have carried out a systematic literature review (SLR) to identify the methodologies, techniques, and tools used for privacy requirements elicitation. Besides, we have surveyed IT practitioners to understand their perception of using these techniques and tools in the software development process. We have found several methodologies, techniques, and tools proposed in the literature to carry out privacy requirements elicitation. Out of 78 studies cataloged within the SLR, most of them did not verify their methodologies and techniques in a practical case study or illustrative contexts (38 studies), and less than 35% of them (26 studies) experimented with their propositions within an industry context. The Privacy Safeguard method (PriS) is the best known among the 198 practitioners in the industry who participated in the survey. Moreover, use cases and user story are their most-used techniques. This qualitative and quantitative study shows a perception of IT practitioners different from those presented in other research papers and suggests that methodologies, techniques, and tools play an important role in IT practitioners' perceptions about privacy requirements elicitation.
引用
收藏
页码:177 / 194
页数:18
相关论文
共 50 条
  • [21] A Systematic Analysis of Requirements Elicitation Problems and Challenges
    Kustelega, Marija
    Mekovec, Renata
    CENTRAL EUROPEAN CONFERENCE ON INFORMATION AND INTELLIGENT SYSTEMS, CECIIS, 2023, : 465 - 471
  • [22] Toward a Holistic Privacy Requirements Engineering Process: Insights From a Systematic Literature Review
    Herwanto, Guntur Budi
    Ekaputra, Fajar J.
    Quirchmayr, Gerald
    Tjoa, A. Min
    IEEE ACCESS, 2024, 12 : 47518 - 47542
  • [23] Information Privacy Concerns in the Use of Social Media Among Healthcare Practitioners: A Systematic Literature Review
    Rahim, Fiza Abdul
    Ismail, Zuraini
    Samy, Ganthan Narayana
    ADVANCED SCIENCE LETTERS, 2014, 20 (10-12) : 2176 - 2179
  • [24] A Systematic Review of Privacy Policy Literature
    Javed, Yousra
    Sajid, Ayesha
    ACM COMPUTING SURVEYS, 2025, 57 (02)
  • [25] Elicitation Techniques for Internet of Things Applications Requirements: A Systematic Review
    Lim, Tek-Yong
    Chua, Fang-Fang
    Tajuddin, Bushra Binti
    PROCEEDINGS OF 2018 VII INTERNATIONAL CONFERENCE ON NETWORK, COMMUNICATION AND COMPUTING (ICNCC 2018), 2018, : 182 - 188
  • [26] A Systematic Review of AI-Enabled Frameworks in Requirements Elicitation
    Siddeshwar, Vaishali
    Alwidian, Sanaa
    Makrehchi, Masoud
    IEEE ACCESS, 2024, 12 : 154310 - 154336
  • [27] Requirements Elicitation and Specification for Educational Technology Development: A Systematic Literature Mapping
    Araujo, Ramon Pontes
    Alencar de Medeiros, Francisco Petronio
    2020 15TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI'2020), 2020,
  • [28] Functional Requirements for Medical Data Integration into Knowledge Management Environments: Requirements Elicitation Approach Based on Systematic Literature Analysis
    Kinast, Benjamin
    Ulrich, Hannes
    Schreiweis, Bjoern
    JOURNAL OF MEDICAL INTERNET RESEARCH, 2023, 25
  • [29] Sustainability requirements for eLearning systems: a systematic literature review and analysis
    Ahmed D. Alharthi
    Maria Spichkova
    Margaret Hamilton
    Requirements Engineering, 2019, 24 : 523 - 543
  • [30] Sustainability requirements for eLearning systems: a systematic literature review and analysis
    Alharthi, Ahmed D.
    Spichkova, Maria
    Hamilton, Margaret
    REQUIREMENTS ENGINEERING, 2019, 24 (04) : 523 - 543