Addressing privacy requirements in system design: the PriS method

C Kalloniatis, E Kavakli, S Gritzalis - Requirements Engineering, 2008 - Springer
Requirements Engineering, 2008Springer
A major challenge in the field of software engineering is to make users trust the software that
they use in their every day activities for professional or recreational reasons. Trusting
software depends on various elements, one of which is the protection of user privacy.
Protecting privacy is about complying with user's desires when it comes to handling
personal information. Users' privacy can also be defined as the right to determine when, how
and to what extend information about them is communicated to others. Current research …
Abstract
A major challenge in the field of software engineering is to make users trust the software that they use in their every day activities for professional or recreational reasons. Trusting software depends on various elements, one of which is the protection of user privacy. Protecting privacy is about complying with user’s desires when it comes to handling personal information. Users’ privacy can also be defined as the right to determine when, how and to what extend information about them is communicated to others. Current research stresses the need for addressing privacy issues during the system design rather than during the system implementation phase. To this end, this paper describes PriS, a security requirements engineering method, which incorporates privacy requirements early in the system development process. PriS considers privacy requirements as organisational goals that need to be satisfied and adopts the use of privacy-process patterns as a way to: (1) describe the effect of privacy requirements on business processes; and (2) facilitate the identification of the system architecture that best supports the privacy-related business processes. In this way, PriS provides a holistic approach from ‘high-level’ goals to ‘privacy-compliant’ IT systems. The PriS way-of-working is formally defined thus, enabling the development of automated tools for assisting its application.
Springer
以上显示的是最相近的搜索结果。 查看全部搜索结果