Perspectives on Regulatory Compliance in Software Engineering

被引:6
|
作者
Kempe, Evelyn [1 ]
Massey, Aaron [1 ]
机构
[1] Univ Maryland Baltimore Cty, Dept Informat Syst, Baltimore, MD 21228 USA
基金
美国国家科学基金会;
关键词
PRIVACY;
D O I
10.1109/RE51729.2021.00012
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Compliance reviews within a software organization are internal attempts to verify regulatory and security requirements during product development before its release. However, these reviews are not enough to adequately assess and address regulatory and security requirements throughout a software's development lifecycle. We believe requirements engineers can benefit from an improved understanding of how software practitioners treat and perceive compliance requirements. This paper describes an interview study seeking to understand how regulatory and security standard requirements are addressed, how burdensome they may be for businesses, and how our participants perceived them in the software development lifecycle. We interviewed 15 software practitioners from 13 organizations with different roles in the software development process and working in various industry domains, including big tech, healthcare, data analysis, finance, and small businesses. Our findings suggest that, for our participants, the software release process is the ultimate focus for regulatory and security compliance reviews. Also, most participants suggested that having a defined process for addressing compliance requirements was freeing rather than burdensome. Finally, participants generally saw compliance requirements as an investment for both employees and customers. These findings may be unintuitive, and we discuss seven lessons this work may hold for requirements engineering.
引用
收藏
页码:46 / 57
页数:12
相关论文
共 50 条
  • [1] Systematic mapping study on requirements engineering for regulatory compliance of software systems
    Kosenkov, Oleksandr
    Elahidoost, Parisa
    Gorschek, Tony
    Fischbach, Jannik
    Mendez, Daniel
    Unterkalmsteiner, Michael
    Fucci, Davide
    Mohanani, Rahul
    INFORMATION AND SOFTWARE TECHNOLOGY, 2025, 178
  • [2] Software Engineering for Compliance
    Zdun, Uwe
    Bener, Ayse
    Olalia-Carin, Erlinda L.
    IEEE SOFTWARE, 2012, 29 (03) : 24 - 27
  • [3] PERSPECTIVES ON SOFTWARE ENGINEERING
    ZELKOWITZ, MV
    COMPUTING SURVEYS, 1978, 10 (02) : 197 - 216
  • [4] SOFTWARE FOR REGULATORY COMPLIANCE OF CHEMICAL HAZARDS
    KUMAR, A
    RAO, HG
    ENVIRONMENTAL PROGRESS, 1990, 9 (04): : N7 - N9
  • [5] Establishing Regulatory Compliance for Software Requirements
    Ingolfo, Silvia
    Siena, Alberto
    Mylopoulos, John
    CONCEPTUAL MODELING - ER 2011, 2011, 6998 : 47 - 61
  • [6] Arguing regulatory compliance of software requirements
    Ingolfo, Silvia
    Siena, Alberto
    Mylopoulos, John
    Susi, Angelo
    Perini, Anna
    DATA & KNOWLEDGE ENGINEERING, 2013, 87 : 279 - 296
  • [7] Taxing Collaborative Software Engineering: The Challenges for Tax Compliance in Software Engineering
    Dorner, Michael
    Capraro, Maximilian
    Treidler, Oliver
    Kunz, Tom-Eric
    Smite, Darja
    Zabardast, Ehsan
    Mendez, Daniel
    Wnuk, Krzysztof
    IEEE SOFTWARE, 2024, 41 (04) : 143 - 150
  • [8] Modeling Regulatory Compliance in Requirements Engineering
    Ingolfo, Silvia
    Siena, Alberto
    Mylopoulos, John
    ADVANCES IN CONCEPTUAL MODELING, 2014, 8823 : 127 - 132
  • [9] SOFTWARE ENGINEERING - PROBLEMS AND PERSPECTIVES
    RAMAMOORTHY, CV
    PRAKASH, A
    TSAI, WT
    USUDA, Y
    COMPUTER, 1984, 17 (10) : 191 - &
  • [10] Panel: Perspectives on software engineering
    Notkin, D
    Donner, M
    Ernst, MD
    Gorlick, M
    Whitehead, EJ
    PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, 2001, : 699 - 702