• DocumentCode
    2618078
  • Title

    Extracting security requirements from relevant laws and regulations

  • Author

    Jorshari, Fatemeh Zarrabi ; Mouratidis, Haralambos ; Islam, Shareeful

  • Author_Institution
    Sch. of Archit., Comput. & Eng., Univ. of East London, London, UK
  • fYear
    2012
  • fDate
    16-18 May 2012
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    For software systems that process and manage sensitive information, compliance with laws has become not an option but a necessity. Analysing relevant laws and aligning them with the system requirements is necessary for attaining compliance issues. But analyzing laws within the context of software system requirements is a difficult task, mainly because the concepts used in legal texts are different compared to the concepts used in requirements engineering. This paper contributes to that direction. In particular it presents a process to model and analyse laws and regulations and to support the elicitation of security requirements based on the relevant legal and system context. Finally a case study is used to demonstrate the applicability of the proposed approach.
  • Keywords
    law; security of data; systems analysis; compliance issues; legal texts; requirements engineering; security requirements; sensitive information; software system requirements; Analytical models; Context; Law; Object recognition; Security; Smart cards; Duty dependency; Hohfeld; Right dependency; Secure Tropos;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Research Challenges in Information Science (RCIS), 2012 Sixth International Conference on
  • Conference_Location
    Valencia
  • ISSN
    2151-1349
  • Print_ISBN
    978-1-4577-1936-3
  • Electronic_ISBN
    2151-1349
  • Type

    conf

  • DOI
    10.1109/RCIS.2012.6240443
  • Filename
    6240443