Commitment analysis to operationalize software requirements from privacy policies

Commitment analysis to operationalize software requirements from privacy policies
复制标题

承诺分析以实施隐私政策中的软件要求

DOI:
10.1007/s00766-010-0108-6
复制
发表时间:
2011
影响因子:
2.8
通讯作者:
Jessica D. Young
Jessica D. Young
中科院分区:
计算机科学2区
文献类型:
--
作者:
Jessica D. Young

文献摘要

被引文献

相似文献

在线隐私政策描述了组织收集、存储、使用和保护消费者个人信息的隐私实践。用户需要了解这些政策,以便了解他们的个人信息是如何被收集,存储,使用和保护的。组织需要确保他们在隐私政策中表达的承诺反映了他们的实际商业惯例,特别是在美国,联邦贸易委员会规范公平的商业惯例。需求工程师需要了解隐私政策,以了解软件必须遵守的隐私惯例,并确保这些隐私政策中表达的承诺被纳入软件需求。在本文中,我们提出了一种方法,从隐私政策的基础上,我们的承诺,特权和权利,这是通过扎根理论的方法开发的理论要求。这种方法是从一个案例研究中,我们从十七个医疗保健隐私政策的软件需求。我们发现,基于法律的方法并没有提供足够的隐私要求的覆盖面,因为隐私政策主要集中在程序的做法,而不是法律的做法。
Online privacy policies describe organizations’ privacy practices for collecting, storing, using, and protecting consumers’ personal information. Users need to understand these policies in order to know how their personal information is being collected, stored, used, and protected. Organizations need to ensure that the commitments they express in their privacy policies reflect their actual business practices, especially in the United States where the Federal Trade Commission regulates fair business practices. Requirements engineers need to understand the privacy policies to know the privacy practices with which the software must comply and to ensure that the commitments expressed in these privacy policies are incorporated into the software requirements. In this paper, we present a methodology for obtaining requirements from privacy policies based on our theory of commitments, privileges, and rights, which was developed through a grounded theory approach. This methodology was developed from a case study in which we derived software requirements from seventeen healthcare privacy policies. We found that legal-based approaches do not provide sufficient coverage of privacy requirements because privacy policies focus primarily on procedural practices rather than legal practices.