DocumentCode
1726938
Title
An Integrated Method for Pattern-Based Elicitation of Legal Requirements Applied to a Cloud Computing Example
Author
Beckers, Kristian ; Fassbender, Stephan ; Schmidt, Holger
Author_Institution
Ruhr Inst. for Software Technol., Univ. of Duisburg-Essen, Duisburg, Germany
fYear
2012
Firstpage
463
Lastpage
472
Abstract
Considering legal aspects during software development is a challenging problem, due to the cross-disciplinary expertise required. The problem is even more complex for cloud computing systems, because of the international distribution, huge amounts of processed data, and a large number of stakeholders that own or process the data. Approaches exist to deal with parts of the problem, but they are isolated from each other. We present an integrated method for elicitation of legal requirements. A cloud computing online banking scenario illustrates the application of our methods. The running example deals with the problem of storing personal information in the cloud and based upon the BDSG (German Federal Data Protection Act). We describe the structure of the online banking cloud system using an existing pattern-based approach. The elicited information is further refined and processed into functional requirements for software development. Moreover, our method covers the analysis of security-relevant concepts such as assets and attackers particularly with regard to laws. The requirements artifacts then serve as inputs for existing patterns for the identification of laws relevant for the online banking cloud system. Finally, our method helps to systematically derive functional as well as security requirements that realize the previously identified laws.
Keywords
bank data processing; cloud computing; data privacy; law; software engineering; BDSG; German Federal Data Protection Act; cloud computing online banking scenario; data processing; functional requirements; integrated method; international distribution; law identification; legal requirement elicitation; pattern-based information elicitation; personal information storage; security-relevant concept analysis; software development; stakeholders; Availability; Cloud computing; Law; Online banking; Security; law; requirements engineering; security; software architecture;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2012 Seventh International Conference on
Conference_Location
Prague
Print_ISBN
978-1-4673-2244-7
Type
conf
DOI
10.1109/ARES.2012.25
Filename
6329218
Link To Document