Architecture-based regulatory compliance argumentation

被引:1
|
作者
Mihaylov, Boyan [1 ]
Onea, Lucian [1 ]
Hansen, Klaus Marius [1 ]
机构
[1] Univ Copenhagen, Dept Comp Sci DIKU, DK-1168 Copenhagen, Denmark
关键词
Regulatory compliance; Software architecture; Software development; REQUIREMENTS; SECURITY; PRIVACY;
D O I
10.1016/j.jss.2016.04.057
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Standards and regulations are difficult to understand and map to software, which makes compliance with them challenging to argue for software products and development process. This is problematic since lack of compliance may lead to issues with security, safety, and even to economic sanctions. An increasing number of applications (for example in healthcare) are expected to have to live up to regulatory requirements in the future, which will lead to more software development projects having to deal with such requirements. We present an approach that models regulations such that compliance arguments can be made in a principled way based on architectural requirements and architectural decisions. In particular, we discuss how one can form architectural requirements which are linked to regulatory texts. We then argue for completeness and correctness of this bi-directional link. We evaluate the approach on the migration of the telemedicine platform Net4Care to the cloud, where certain regulations (for example privacy) should be concerned. The approach has the potential to support simpler compliance argumentation with the eventual promise of safer and more secure applications. (C) 2016 Published by Elsevier Inc.
引用
收藏
页码:1 / 30
页数:30
相关论文
共 50 条
  • [1] Architecture-Based IT Portfolio Valuation
    Lankhorst, Marc M.
    Quartel, Dick A. C.
    Steen, Maarten W. A.
    PRACTICE-DRIVEN RESEARCH ON ENTERPRISE TRANSFORMATION, 2010, 69 : 78 - 106
  • [2] Architecture-based performance simulation
    Decker, Gero
    Gersabeck, Volker
    Schaffner, Jan
    Seelig, Marcel
    IMECS 2007: INTERNATIONAL MULTICONFERENCE OF ENGINEERS AND COMPUTER SCIENTISTS, VOLS I AND II, 2007, : 1183 - +
  • [3] Architecture-Based Security or UxVs
    Berzins, Valdis
    NAVAL ENGINEERS JOURNAL, 2020, 132 (02) : 95 - 100
  • [4] Architecture-Based Software Testing
    Lee, Jihyun
    Kang, Sungwon
    Keum, Changsup
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2018, 28 (01) : 57 - 77
  • [5] Architecture-based heterogeneous software reliability
    Gokhale, SS
    TENTH ISSAT INTERNATIONAL CONFERENCE ON RELIABILITY AND QUALITY IN DESIGN, PROCEEDINGS, 2004, : 18 - 24
  • [6] Architecture-based visualisation of computer based systems
    Denford, M
    O'Neill, T
    Leaney, J
    NINTH ANNUAL IEEE INTERNATIONAL CONFERENCE AND WORKSHOP ON THE ENGINEERING OF COMPUTER-BASED SYSTEMS, PROCEEDINGS, 2002, : 139 - 146
  • [7] An Architecture-based Enterprise Planning Process
    Martin, James N
    INCOSE International Symposium, 2015, 25 (01) : 948 - 961
  • [8] Architecture-based design of computer based systems
    Denford, M
    O'Neill, T
    Leaney, J
    ECBS 2003: 10TH IEEE INTERNATIONAL CONFERENCE AND WORKSHOP ON THE ENGINEERING OF COMPUTER-BASED SYSTEMS, PROCEEDINGS, 2003, : 39 - 46
  • [9] Analysis and design for architecture-based software
    Jia Xiaolin
    Journal of Systems Engineering and Electronics, 2005, (04) : 924 - 930
  • [10] Towards Secure Architecture-based Adaptations
    Khakpour, Narges
    Skandylas, Charilaos
    Nariman, Goran Saman
    Weyns, Danny
    2019 IEEE/ACM 14TH INTERNATIONAL SYMPOSIUM ON SOFTWARE ENGINEERING FOR ADAPTIVE AND SELF-MANAGING SYSTEMS (SEAMS 2019), 2019, : 114 - 125