Perspectives on Regulatory Compliance in Software Engineering

被引:6
|
作者
Kempe, Evelyn [1 ]
Massey, Aaron [1 ]
机构
[1] Univ Maryland Baltimore Cty, Dept Informat Syst, Baltimore, MD 21228 USA
基金
美国国家科学基金会;
关键词
PRIVACY;
D O I
10.1109/RE51729.2021.00012
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Compliance reviews within a software organization are internal attempts to verify regulatory and security requirements during product development before its release. However, these reviews are not enough to adequately assess and address regulatory and security requirements throughout a software's development lifecycle. We believe requirements engineers can benefit from an improved understanding of how software practitioners treat and perceive compliance requirements. This paper describes an interview study seeking to understand how regulatory and security standard requirements are addressed, how burdensome they may be for businesses, and how our participants perceived them in the software development lifecycle. We interviewed 15 software practitioners from 13 organizations with different roles in the software development process and working in various industry domains, including big tech, healthcare, data analysis, finance, and small businesses. Our findings suggest that, for our participants, the software release process is the ultimate focus for regulatory and security compliance reviews. Also, most participants suggested that having a defined process for addressing compliance requirements was freeing rather than burdensome. Finally, participants generally saw compliance requirements as an investment for both employees and customers. These findings may be unintuitive, and we discuss seven lessons this work may hold for requirements engineering.
引用
收藏
页码:46 / 57
页数:12
相关论文
共 50 条
  • [21] Software Engineering Education: Challenges and Perspectives
    Ouhbi, Sofia
    Pombo, Nuno
    PROCEEDINGS OF THE 2020 IEEE GLOBAL ENGINEERING EDUCATION CONFERENCE (EDUCON 2020), 2020, : 202 - 209
  • [22] Current perspectives on the software engineering process
    Biro, Miklos
    Colomo-Palacios, Ricardo
    Messnarz, Richard
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2020, 32 (11)
  • [23] A Framework for Intersectional Perspectives in Software Engineering
    Sanchez-Gordon, Mary
    Colomo-Palacios, Ricardo
    2021 IEEE/ACM 13TH INTERNATIONAL WORKSHOP ON COOPERATIVE AND HUMAN ASPECTS OF SOFTWARE ENGINEERING (CHASE 2021), 2021, : 121 - 122
  • [24] Perspectives of granular computing in software engineering
    Han, Jianchao
    Dong, Jing
    GRC: 2007 IEEE INTERNATIONAL CONFERENCE ON GRANULAR COMPUTING, PROCEEDINGS, 2007, : 66 - 71
  • [25] Perspectives on manufacturing engineering software integration
    McLean, CR
    INFORMATION INFRASTRUCTURE SYSTEMS FOR MANUFACTURING, 1997, : 20 - 31
  • [26] ENGINEERING STUDY PROGRAM COMPLIANCE EVALUATION TO GUIDELINES FOR SOFTWARE ENGINEERING CURRICULUM
    Vitols, Gatis
    Arhipova, Irina
    Paura, Liga
    18TH INTERNATIONAL SCIENTIFIC CONFERENCE ENGINEERING FOR RURAL DEVELOPMENT, 2019, : 1909 - 1914
  • [27] REGULATORY COMPLIANCE TRAINING IN BIO/CHEMICAL ENGINEERING COURSES
    Felse, Arthur
    2012 ASEE ANNUAL CONFERENCE, 2012,
  • [28] Perspectives on the Gap Between the Software Industry and the Software Engineering Education
    Oguz, Damla
    Oguz, Kaya
    IEEE ACCESS, 2019, 7 : 117527 - 117543
  • [29] Regulatory and security standard compliance throughout the software development lifecycle
    Kempe, Evelyn
    Massey, Aaron K.
    Proceedings of the Annual Hawaii International Conference on System Sciences, 2021, 2020-January : 2026 - 2035
  • [30] Modeling Iteration's Perspectives in Software Engineering
    Mumtaz, Mamoona
    Ahmad, Naveed
    Usman Ashraf, M.
    Alshaflut, Ahmed
    Alourani, Abdullah
    Anjum, Hafiz Junaid
    IEEE ACCESS, 2022, 10 : 19333 - 19347