메뉴 건너뛰기




Volumn 28, Issue 1-2, 2009, Pages 8-17

A distributed requirements management framework for legal compliance and accountability

Author keywords

Accountability; Compliance; Policy; regulation; Requirements engineering

Indexed keywords

COMPUTER SOFTWARE PORTABILITY; HEALTH INSURANCE; INFORMATION SYSTEMS; REQUIREMENTS ENGINEERING;

EID: 57849159727     PISSN: 01674048     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.cose.2008.08.001     Document Type: Article
Times cited : (35)

References (40)
  • 4
    • 57849162858 scopus 로고    scopus 로고
    • Antón AI, Goal identification and refinement in the specification of software-based information systems. Ph.D. thesis, Georgia Institute of Technology, Atlanta, GA, USA; 1997.
    • Antón AI, Goal identification and refinement in the specification of software-based information systems. Ph.D. thesis, Georgia Institute of Technology, Atlanta, GA, USA; 1997.
  • 5
    • 49649127497 scopus 로고    scopus 로고
    • Antón AI, McCracken WM, Potts C. Goal decomposition and scenario analysis in business process engineering. In: Advanced information systems engineering, sixth international conference, Utrecht, Netherlands; 1994. p. 94-104, 6-10.
    • Antón AI, McCracken WM, Potts C. Goal decomposition and scenario analysis in business process engineering. In: Advanced information systems engineering, sixth international conference, Utrecht, Netherlands; 1994. p. 94-104, 6-10.
  • 8
    • 84892711302 scopus 로고    scopus 로고
    • Barka E, Sandhu R, Framework for role-based delegation models. In: Sixteenth annual conference on computer security application; 2000. p. 168-76.
    • Barka E, Sandhu R, Framework for role-based delegation models. In: Sixteenth annual conference on computer security application; 2000. p. 168-76.
  • 9
    • 27644461562 scopus 로고    scopus 로고
    • Breaux TD, Antón AI, Analyzing goal semantics for rights, permissions, and obligations. In: IEEE 13th requirements engineering conference, Paris, France; 2005. p. 177-86.
    • Breaux TD, Antón AI, Analyzing goal semantics for rights, permissions, and obligations. In: IEEE 13th requirements engineering conference, Paris, France; 2005. p. 177-86.
  • 10
    • 40449096076 scopus 로고    scopus 로고
    • Analyzing regulatory rules for privacy and security requirements
    • Special Issue on Software Engineering for Secure Systems
    • Breaux T.D., and Antón A.I. Analyzing regulatory rules for privacy and security requirements. Special Issue on Software Engineering for Secure Systems. IEEE Transactions on Software Engineering 34 1 (January/February 2008) 5-20
    • (2008) IEEE Transactions on Software Engineering , vol.34 , Issue.1 , pp. 5-20
    • Breaux, T.D.1    Antón, A.I.2
  • 11
    • 58049178595 scopus 로고    scopus 로고
    • Breaux TD, Antón AI, Boucher K, Dorfman M, Legal requirements, compliance and practice: an industry case study in accessibility. In: Sixteenth IEEE International requirements engineering conference, Barcelona, Spain; 2008.
    • Breaux TD, Antón AI, Boucher K, Dorfman M, Legal requirements, compliance and practice: an industry case study in accessibility. In: Sixteenth IEEE International requirements engineering conference, Barcelona, Spain; 2008.
  • 12
    • 33845392001 scopus 로고    scopus 로고
    • Breaux TD, Antón AI, Karat CM, Karat J, Enforceability vs. accountability in electronic policies. In: IEEE seventh workshop on policies for distributed systems and networks, London, Ontario; 2006a. p. 227-30.
    • Breaux TD, Antón AI, Karat CM, Karat J, Enforceability vs. accountability in electronic policies. In: IEEE seventh workshop on policies for distributed systems and networks, London, Ontario; 2006a. p. 227-30.
  • 13
    • 38149018837 scopus 로고    scopus 로고
    • Breaux TD, Vail MW, Anton AI, Towards compliance: extracting rights and obligations to align requirements and regulations. In: IEEE 14th international conference requirements engineering; 2006b. p. 49-58.
    • Breaux TD, Vail MW, Anton AI, Towards compliance: extracting rights and obligations to align requirements and regulations. In: IEEE 14th international conference requirements engineering; 2006b. p. 49-58.
  • 14
    • 10644245884 scopus 로고    scopus 로고
    • On the role of file system metadata in digital forensics
    • Buchholz F., and Spafford E.H. On the role of file system metadata in digital forensics. Digital Investigation 1 4 (2004) 298-309
    • (2004) Digital Investigation , vol.1 , Issue.4 , pp. 298-309
    • Buchholz, F.1    Spafford, E.H.2
  • 15
    • 57849148709 scopus 로고    scopus 로고
    • Damianou N, Dulay N, Lupu E, Sloman M, The ponder policy language. In: Proceedings of the international workshop on policies for distributed systems and networks, Bristol, UK; 2001. p. 29-31.
    • Damianou N, Dulay N, Lupu E, Sloman M, The ponder policy language. In: Proceedings of the international workshop on policies for distributed systems and networks, Bristol, UK; 2001. p. 29-31.
  • 16
    • 34247092047 scopus 로고    scopus 로고
    • Damian D, Lanubile F, Mallardo T, The role of asynchronous discussions in increasing the effectiveness of remote synchronous requirements negotiations. In: International conference on software engineering, Shanghai, China; 2006. p. 917-20.
    • Damian D, Lanubile F, Mallardo T, The role of asynchronous discussions in increasing the effectiveness of remote synchronous requirements negotiations. In: International conference on software engineering, Shanghai, China; 2006. p. 917-20.
  • 17
    • 0030615545 scopus 로고    scopus 로고
    • Darimont R, Delor E, Massonet P, van Lamsweerde A, GRAIL/KAOS: an environment for goal-driven requirements engineering. In: IEEE 19th international conference on software engineering, Boston, MA; 2005. p. 612-13.
    • Darimont R, Delor E, Massonet P, van Lamsweerde A, GRAIL/KAOS: an environment for goal-driven requirements engineering. In: IEEE 19th international conference on software engineering, Boston, MA; 2005. p. 612-13.
  • 19
    • 84888773622 scopus 로고    scopus 로고
    • Dulay N, Lupu E, Sloman M, Damianou N, A policy deployment model for the ponder language. In: IEEE/IFIP intetnational symposium on integrated network management. Seattle, WA, USA; 2001. p. 529-43.
    • Dulay N, Lupu E, Sloman M, Damianou N, A policy deployment model for the ponder language. In: IEEE/IFIP intetnational symposium on integrated network management. Seattle, WA, USA; 2001. p. 529-43.
  • 20
    • 0032304148 scopus 로고    scopus 로고
    • Adapting traceability environments to project-specific needs
    • Dömges R., and Pohl K. Adapting traceability environments to project-specific needs. Communications of the ACM 41 12 (December 1998) 54-62
    • (1998) Communications of the ACM , vol.41 , Issue.12 , pp. 54-62
    • Dömges, R.1    Pohl, K.2
  • 21
    • 57849143485 scopus 로고    scopus 로고
    • Ernst, Young. In: Tenth annual global information security survey: achieving a balance of risk and performance; 2007.
    • Ernst, Young. In: Tenth annual global information security survey: achieving a balance of risk and performance; 2007.
  • 22
    • 0003706051 scopus 로고    scopus 로고
    • Garner B.A. (Ed), Thompson West, St. Paul, Minnesota
    • In: Garner B.A. (Ed). Blacks law dictionary. 8th ed. (2004), Thompson West, St. Paul, Minnesota
    • (2004) Blacks law dictionary. 8th ed.
  • 23
    • 27644537252 scopus 로고    scopus 로고
    • Giorgini P, Massacci F, Mylopoulos J, Zannone N. Modeling security requirements through ownership, permission and delegation. In: Thirteenth IEEE international conference on requirements engineering, Paris, France; 2005. p. 167-76.
    • Giorgini P, Massacci F, Mylopoulos J, Zannone N. Modeling security requirements through ownership, permission and delegation. In: Thirteenth IEEE international conference on requirements engineering, Paris, France; 2005. p. 167-76.
  • 24
    • 57849140896 scopus 로고    scopus 로고
    • ISO/IEC 15408:2005, Information technology - security techniques - evaluation criteria for IT security; 2005.
    • ISO/IEC 15408:2005, Information technology - security techniques - evaluation criteria for IT security; 2005.
  • 25
    • 57849145322 scopus 로고    scopus 로고
    • ISO/IEC 9001:2000, Quality management systems - requirements; 2005.
    • ISO/IEC 9001:2000, Quality management systems - requirements; 2005.
  • 28
    • 0000788149 scopus 로고    scopus 로고
    • Law-governed interaction: a coordination and control mechanism for heterogeneous distributed systems
    • Minksy N.H., and Ungureanu V. Law-governed interaction: a coordination and control mechanism for heterogeneous distributed systems. ACM Transactions on Software Engineering and Methodology 9 3 (2000) 273-305
    • (2000) ACM Transactions on Software Engineering and Methodology , vol.9 , Issue.3 , pp. 273-305
    • Minksy, N.H.1    Ungureanu, V.2
  • 29
    • 57849114508 scopus 로고    scopus 로고
    • Moffett JD, Requirements and policies. In: Workshop on policies for distributed systems and networks, Bristol, UK; 1999.
    • Moffett JD, Requirements and policies. In: Workshop on policies for distributed systems and networks, Bristol, UK; 1999.
  • 30
    • 0345180675 scopus 로고    scopus 로고
    • Moffett JD, Sloman MS, The representation of policies as system objects. In: Conference on Organisational Computer Systems, Atlanta, Georgia, USA; 1991. p. 171-184.
    • Moffett JD, Sloman MS, The representation of policies as system objects. In: Conference on Organisational Computer Systems, Atlanta, Georgia, USA; 1991. p. 171-184.
  • 31
    • 0242491000 scopus 로고    scopus 로고
    • Oh S, Sandhu R, Role administration: a model for role administration using organization structure. In: Seventh ACM symposium on access control models and technology, Monterey, CA, USA; 2002. p. 155-62.
    • Oh S, Sandhu R, Role administration: a model for role administration using organization structure. In: Seventh ACM symposium on access control models and technology, Monterey, CA, USA; 2002. p. 155-62.
  • 35
    • 0032302301 scopus 로고    scopus 로고
    • Factors influencing requirements traceability practice
    • Ramesh B. Factors influencing requirements traceability practice. Communications of the ACM 41 12 (December 1998) 37-44
    • (1998) Communications of the ACM , vol.41 , Issue.12 , pp. 37-44
    • Ramesh, B.1
  • 38
    • 33744961046 scopus 로고    scopus 로고
    • Standards for privacy of individually identifiable health information
    • 45 CFR Part 160, Part 164 Subpart E
    • 45 CFR Part 160, Part 164 Subpart E. U.S. Office of Civil Rights. Standards for privacy of individually identifiable health information. Federal Register 68 34 (Feb. 20, 2003) 8334-8381
    • (2003) Federal Register , vol.68 , Issue.34 , pp. 8334-8381
    • U.S. Office of Civil Rights1
  • 39
    • 33744961046 scopus 로고    scopus 로고
    • Standards for the protection of electronic protected health information
    • 45 CFR Part 164, Subpart C
    • 45 CFR Part 164, Subpart C. U.S. Office of Civil Rights. Standards for the protection of electronic protected health information. Federal Register 68 34 (Feb. 20, 2003) 8334-8381
    • (2003) Federal Register , vol.68 , Issue.34 , pp. 8334-8381
    • U.S. Office of Civil Rights1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.