Translating Data Protection into Software Requirements

被引:8
作者
Kneuper, Ralf [1 ]
机构
[1] IUBH Univ Appl Sci Distance Learning, Kaiserpl 1, D-83435 Bad Reichenhall, Germany
来源
ICISSP: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY | 2020年
关键词
Data Protection; Privacy; GDPR; Software Requirements;
D O I
10.5220/0008873902570264
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the growth of data processing and digitalisation in many environments, data protection is also growing more and more important. This is for example reflected by the General Data Protection Regulation (GDPR) which came into effect in May 2018 and defines what organisations need to do to protect individuals and their personal data. This paper provides a summary of the main data protection concepts, using GDPR as an example, and from these derives the resulting software requirements that apply to software systems which process private data within the European Union (and to some extent beyond). This way, the paper supports software developers as well as requirements analysts in their task of identifying and defining the data protection requirements, even though they will have to be adapted and additional detail provided for any specific case.
引用
收藏
页码:257 / 264
页数:8
相关论文
共 11 条
[1]  
[Anonymous], 2011, TECHNICAL REPORT
[2]  
Danezis G., 2014, TECHNICAL REPORT
[3]  
Datatilsynet, 2017, SOFTW DEV DAT PROT D
[4]  
Englehardt Steven., 2018, WEBSITE OPERATORS AR
[5]  
International Requirements Engineering Board (IREB), 2017, TECHNICAL REPORT
[6]   Integrating Data Protection into the Software Life Cycle [J].
Kneuper, Ralf .
PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROFES 2019, 2019, 11915 :417-432
[7]  
Kuhlung J., 2018, DATENSCHUTZ GRUNDVER
[8]  
Pohl K., 2015, REQUIREMENTS ENG FUN, V2nd Editio
[9]  
Reid G., 2017, NAVIGATE SOFTWARE DE
[10]  
Santala A., 2017, WHAT SHOULD SOFTWARE