메뉴 건너뛰기




Volumn 34, Issue 1, 2008, Pages 5-20

Analyzing regulatory rules for privacy and security requirements

Author keywords

Accountability; Compliance; Information and privacy; Laws and regulations; Requirements engineering

Indexed keywords

DATA PRIVACY; REGULATORY COMPLIANCE; REQUIREMENTS ENGINEERING; SECURITY OF DATA;

EID: 40449096076     PISSN: 00985589     EISSN: None     Source Type: Journal    
DOI: 10.1109/TSE.2007.70746     Document Type: Article
Times cited : (265)

References (44)
  • 3
    • 17744389340 scopus 로고    scopus 로고
    • A Requirements Taxonomy for Reducing Web Site Privacy Vulnerabilities
    • A.I. Antón and J.B. Earp, "A Requirements Taxonomy for Reducing Web Site Privacy Vulnerabilities," Requirements Eng., vol. 9, no. 3, pp. 169-185, 2004.
    • (2004) Requirements Eng , vol.9 , Issue.3 , pp. 169-185
    • Antón, A.I.1    Earp, J.B.2
  • 4
    • 0242624597 scopus 로고    scopus 로고
    • From Privacy Promises to Privacy Management: A New Approach for Enforcing Privacy throughout the Enterprise
    • P. Ashley, C. Powers, and M. Schunter, "From Privacy Promises to Privacy Management: A New Approach for Enforcing Privacy throughout the Enterprise," Proc. 10th New Security Paradigms Workshop, pp. 43-50, 2002.
    • (2002) Proc. 10th New Security Paradigms Workshop , pp. 43-50
    • Ashley, P.1    Powers, C.2    Schunter, M.3
  • 11
    • 40449097419 scopus 로고    scopus 로고
    • T.D. Breaux and A.I. Antón, Semantic Parameterization: A Conceptual Modeling Process for Domain Descriptions, Technical Report TR-2006-35, Dept. of Computer Science, North Carolina State Univ., Oct. 2006, ACM Trans. Software Eng. Methods, to appear.
    • T.D. Breaux and A.I. Antón, "Semantic Parameterization: A Conceptual Modeling Process for Domain Descriptions," Technical Report TR-2006-35, Dept. of Computer Science, North Carolina State Univ., Oct. 2006, ACM Trans. Software Eng. Methods, to appear.
  • 12
    • 78649899740 scopus 로고    scopus 로고
    • A Distributed Requirements Management Framework for Compliance and Accountability,
    • Technical Report TR-2006-14, Dept. of Computer Science, North Carolina State Univ, July
    • T.D. Breaux, A.I. Antón, and E.H. Spafford, "A Distributed Requirements Management Framework for Compliance and Accountability," Technical Report TR-2006-14, Dept. of Computer Science, North Carolina State Univ., July 2006.
    • (2006)
    • Breaux, T.D.1    Antón, A.I.2    Spafford, E.H.3
  • 13
    • 38149018837 scopus 로고    scopus 로고
    • Towards Compliance: Extracting Rights and Obligations to Align Requirements with Regulations
    • T.D. Breaux, M.W. Vail, and A.I. Antón, "Towards Compliance: Extracting Rights and Obligations to Align Requirements with Regulations," Proc. 14th IEEE Int'l Conf. Requirements Eng., pp. 49-58, 2006.
    • (2006) Proc. 14th IEEE Int'l Conf. Requirements Eng , pp. 49-58
    • Breaux, T.D.1    Vail, M.W.2    Antón, A.I.3
  • 14
    • 40449137168 scopus 로고    scopus 로고
    • Impalpable Constraints: Framing Requirements for Formal Methods,
    • Technical Report TR-2007-6, Dept. of Computer Science, North Carolina State Univ, Feb
    • T.D. Breaux and A.I. Antón, "Impalpable Constraints: Framing Requirements for Formal Methods," Technical Report TR-2007-6, Dept. of Computer Science, North Carolina State Univ., Feb. 2007.
    • (2007)
    • Breaux, T.D.1    Antón, A.I.2
  • 16
    • 40449095819 scopus 로고    scopus 로고
    • Health Care
    • Bureau of Labor Statistics, US Dept. of Labor
    • "Health Care," Career Guide to Industries, 2006-2007. Bureau of Labor Statistics, US Dept. of Labor, 2007.
    • (2007) Career Guide to Industries, 2006-2007
  • 18
    • 40449083721 scopus 로고    scopus 로고
    • Choice Point Settles Data Security Breach Charges: To Pay $10 Million in Civil Penalties and $5 Million for Customer Redress
    • Trade Commission
    • C.B. Farrell, "Choice Point Settles Data Security Breach Charges: To Pay $10 Million in Civil Penalties and $5 Million for Customer Redress," FTC File 052-3069, Office of Public Affairs, US Fed. Trade Commission, 2006.
    • (2006) FTC File 052-3069, Office of Public Affairs, US Fed
    • Farrell, C.B.1
  • 19
    • 40449109540 scopus 로고    scopus 로고
    • United States v. ChoicePoint, Inc, Case 1:06-CV-00198-JTC, Northern District of Georgia, Feb. 2006
    • United States v. ChoicePoint, Inc., Case 1:06-CV-00198-JTC, (Northern District of Georgia), Feb. 2006.
  • 20
    • 0003706051 scopus 로고    scopus 로고
    • B.A. Garner, ed, eighth ed
    • Black's Law Dictionary, B.A. Garner, ed., eighth ed., 2004.
    • (2004) Black's Law Dictionary
  • 22
    • 27644537252 scopus 로고    scopus 로고
    • Proc. 13th IEEE Int'l Conf. Requirements Eng
    • P. Giorgini, F. Massacci, J. Mylopoulos, and N. Zannone, Modeling Security Requirements through Ownership, Permission and Delegation," Proc. 13th IEEE Int'l Conf. Requirements Eng., pp. 167-176, 2005.
    • (2005) , pp. 167-176
    • Giorgini, P.1    Massacci, F.2    Mylopoulos, J.3    Zannone, N.4
  • 25
    • 33644855528 scopus 로고    scopus 로고
    • HIPAA Administrative Simplification: Enforcement - Parts 160 and 164
    • US Dept. of Health and Human Services, Feb
    • "HIPAA Administrative Simplification: Enforcement - Parts 160 and 164," Federal Register, US Dept. of Health and Human Services, vol. 71, no. 32, pp. 8389-8433, Feb. 2006.
    • (2006) Federal Register , vol.71 , Issue.32 , pp. 8389-8433
  • 30
    • 0037456032 scopus 로고    scopus 로고
    • Standards for Privacy of Individually Identifiable Health Information - Part 164, Subpart E
    • US Dept. of Health and Human Services, Feb
    • "Standards for Privacy of Individually Identifiable Health Information - Part 164, Subpart E," Federal Register, US Dept. of Health and Human Services, vol. 68, no. 34, pp. 8334-8381, Feb. 2003.
    • (2003) Federal Register , vol.68 , Issue.34 , pp. 8334-8381
  • 31
    • 0037456032 scopus 로고    scopus 로고
    • Standards for the Protection of Electronic Protected Health Information - Part 164, Subpart C
    • US Dept. of Health and Human Services, Feb
    • "Standards for the Protection of Electronic Protected Health Information - Part 164, Subpart C," Federal Register, US Dept. of Health and Human Services, vol. 68, no. 34, pp. 8334-8381, Feb. 2003.
    • (2003) Federal Register , vol.68 , Issue.34 , pp. 8334-8381
  • 32
    • 4544255381 scopus 로고    scopus 로고
    • Elaborating Security Requirements by Construction of Intentional Anti-Models
    • A. van Lamsweerde, "Elaborating Security Requirements by Construction of Intentional Anti-Models," Proc. 26th IEEE Int'l Conf. Software Eng., pp. 148-157, 2004.
    • (2004) Proc. 26th IEEE Int'l Conf. Software Eng , pp. 148-157
    • van Lamsweerde, A.1
  • 36
    • 0010920417 scopus 로고    scopus 로고
    • From Object-Oriented to Goal-Oriented Requirements Analysis
    • J. Mylopoulos, L. Chung, and E. Yu, "From Object-Oriented to Goal-Oriented Requirements Analysis," Comm. ACM, vol. 42, no. 1, pp. 31-37, 1999.
    • (1999) Comm. ACM , vol.42 , Issue.1 , pp. 31-37
    • Mylopoulos, J.1    Chung, L.2    Yu, E.3
  • 37
    • 0002265410 scopus 로고    scopus 로고
    • The Platform for Privacy Preferences
    • J. Reagle and L.F. Cranor, "The Platform for Privacy Preferences," Comm. ACM, vol. 42, no. 2, pp. 48-55, 1999.
    • (1999) Comm. ACM , vol.42 , Issue.2 , pp. 48-55
    • Reagle, J.1    Cranor, L.F.2
  • 39
  • 41
    • 34247501334 scopus 로고    scopus 로고
    • D. Xu, V. Goel, and K. Nygard, An Aspect-Oriented Approach to Security Requirements Analysis, Proc. 30th Ann. Int'l Computer Software and Applications Conf, pp. 79-82, 2006
    • D. Xu, V. Goel, and K. Nygard, "An Aspect-Oriented Approach to Security Requirements Analysis," Proc. 30th Ann. Int'l Computer Software and Applications Conf., pp. 79-82, 2006.
  • 42
    • 0030834984 scopus 로고    scopus 로고
    • The Four Dark Corner's of Requirements Engineering
    • P. Zave and M. Jackson, "The Four Dark Corner's of Requirements Engineering," ACM Trans. Software Eng. Methods, vol. 6, no. 1, pp. 1-30, 1997.
    • (1997) ACM Trans. Software Eng. Methods , vol.6 , Issue.1 , pp. 1-30
    • Zave, P.1    Jackson, M.2
  • 43
    • 40449087817 scopus 로고    scopus 로고
    • Overkill or Overdue?, Hearing before the Special Committee on Aging, US Senate
    • HIPAA Medical Privacy and Transition Rules:, 108th Congress, 23 Sept
    • HIPAA Medical Privacy and Transition Rules: Overkill or Overdue?, Hearing before the Special Committee on Aging, US Senate, 108th Congress, Ser. 108-23, 23 Sept. 2003.
    • (2003) Ser , vol.108 -23
  • 44
    • 40449097420 scopus 로고    scopus 로고
    • Extensible Access Control Markup Language (XACML) Version 2.0, Oasis Standards Group, Feb. 2005
    • Extensible Access Control Markup Language (XACML) Version 2.0, Oasis Standards Group, Feb. 2005.


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.