• DocumentCode
    1904142
  • Title

    Comparing requirements from multiple jurisdictions

  • Author

    Gordon, David G. ; Breaux, Travis D.

  • Author_Institution
    Eng. & Public Policy, Carnegie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2011
  • fDate
    30-30 Aug. 2011
  • Firstpage
    43
  • Lastpage
    49
  • Abstract
    Increasingly, information systems are becoming distributed and pervasive, enabling organizations to deliver services remotely to individuals and to share and store personal information worldwide. However, system developers face significant challenges in identifying and managing the many laws that govern their services and products. To address this challenge, we investigate a method to codify, analyze, and trace relationships among requirements from different regulations that share a common theme of data breach notification. To measure gaps and overlaps between regulations, we applied previously validated requirements metrics. Our findings include a formalization of the legal landscape using operational constructs for high- and low-watermark practices, which business analysts and system developers can use to reason about compliance trade-offs based on perceived businesses costs and risks. We discovered and validated these constructs using five U.S. state data breach notification laws that govern transactions of financial and health information of state residents.
  • Keywords
    business data processing; financial data processing; formal specification; government policies; information systems; transaction processing; ubiquitous computing; watermarking; U.S. state data breach notification laws; business analysts; data breach notification; distributed system; financial information; health information; information systems; legal landscape formalization; perceived businesses costs; perceived businesses risks; pervasive system; requirement metrics; system developers; watermark practice; Law; Measurement; Organizations; Watermarking;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Requirements Engineering and Law (RELAW), 2011 Fourth International Workshop on
  • Conference_Location
    Trento
  • Print_ISBN
    978-1-4577-0947-0
  • Electronic_ISBN
    978-1-4577-0947-0
  • Type

    conf

  • DOI
    10.1109/RELAW.2011.6050272
  • Filename
    6050272