A legal cross-references taxonomy for identifying conflicting software requirements

A legal cross-references taxonomy for identifying conflicting software requirements
复制标题

用于识别冲突软件需求的法律交叉引用分类法

DOI:
--
复制
发表时间:
2011
期刊:
IEEE International Requirements Engineering Conference
影响因子:
--
通讯作者:
Peter P. Swire
Peter P. Swire
中科院分区:
--
文献类型:
--
作者:
J. C. Maxwell;A. Antón;Peter P. Swire

文献摘要

被引文献

相似文献

公司必须确保其软件符合相关法律法规,以避免因违规而遭受高昂处罚、声誉损失和品牌损害的风险。法律和法规包含对同一法律文本各部分的内部交叉引用,以及对外部法律文本的交叉引用。这些交叉引用带来了歧义、例外情况以及其他对监管合规性的挑战。需求工程师需要有关如何处理交叉引用的指导,以便遵守法律的要求。在此,我们分析美国健康保险流通与责任法案 (HIPAA) 隐私规则中的每个外部交叉引用,以确定交叉引用是否:引入冲突的要求、冲突的定义和/或细化现有的要求。在此,我们提出了一种合法的交叉引用分类法,以帮助需求工程师在指定合规性要求时对交叉引用进行分类。分析交叉引用使我们能够解决可能妨碍法律合规性的冲突要求。我们确定了五组相互冲突的合规要求,并提出了解决这些冲突的策略。
Companies must ensure their software complies with relevant laws and regulations to avoid the risk of costly penalties, lost reputation, and brand damage resulting from noncompliance. Laws and regulations contain internal cross-references to portions of the same legal text, as well as cross-references to external legal texts. These cross-references introduce ambiguities, exceptions, as well as other challenges to regulatory compliance. Requirements engineers need guidance as to how to address cross-references in order to comply with the requirements of the law. Herein, we analyze each external cross-reference within the U.S. Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to determine whether a cross-reference either: introduces a conflicting requirement, a conflicting definition, and/or refines an existing requirement. Herein, we propose a legal cross-reference taxonomy to aid requirements engineers in classifying cross-references as they specify compliance requirements. Analyzing cross-references enables us to address conflicting requirements that may otherwise thwart legal compliance. We identify five sets of conflicting compliance requirements and recommend strategies for resolving these conflicts.