• DocumentCode
    3102227
  • Title

    A Method for Identifying Software Requirements Based on Policy Commitments

  • Author

    Young, Jessica D. ; Antón, Annie I.

  • Author_Institution
    Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
  • fYear
    2010
  • fDate
    Sept. 27 2010-Oct. 1 2010
  • Firstpage
    47
  • Lastpage
    56
  • Abstract
    Online policy documents-such as privacy policies, notices of privacy practices, and terms of use-describe organizations´ information practices for collecting, storing, and using consumers´ personal information. Organizations need to ensure that the commitments they express in their policy documents reflect their actual business practices. This compliance is significant in the United States where the Federal Trade Commission regulates fair business practices. Therefore, the requirements engineers developing systems for organizations need to understand the policy documents in order to know the information practices with which the software must comply. The requirements engineers also must ensure that the commitments expressed in these policy documents are incorporated into the software requirements. In this paper, we present a summative case study of a commitment analysis approach. The approach was developed during a formative case study of four healthcare organizations´ policy documents. Within this approach, we obtain requirements from policy documents based on our theory of commitments, privileges, and rights. During our summative case study we applied our commitment analysis approach to eight healthcare organizations´ policy documents in order to validate the methodology. We discuss the results of the summative study, in which we found that most of the statements express organizational practices or procedures. The top seen classification conveys pledges made by the organization based on organizational practices. The second most seen classification expresses actions that the user is entitled to perform based on organizational practices.
  • Keywords
    business data processing; data privacy; document handling; organisational aspects; systems analysis; United States; commitment analysis approach; consumers personal information; fair business practice; federal trade commission; online policy document; policy commitment; software requirements identification; Google; Law; Medical services; Organizations; Privacy; Software; commitment; compliance; policy document; privacy aware; privilege; requirement; right;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Requirements Engineering Conference (RE), 2010 18th IEEE International
  • Conference_Location
    Sydney, NSW
  • ISSN
    1090-705X
  • Print_ISBN
    978-1-4244-8022-7
  • Type

    conf

  • DOI
    10.1109/RE.2010.17
  • Filename
    5636634