SoD: Collaborative Research: Transparency and Legal Compliance in Software Systems

SoD:协作研究:软件系统的透明度和法律合规性

基本信息

  • 批准号:
    0725152
  • 负责人:
  • 金额:
    $ 22.96万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2007
  • 资助国家:
    美国
  • 起止时间:
    2007-08-01 至 2011-07-31
  • 项目状态:
    已结题

项目摘要

This project, involving collaboration between North Carolina State University and Purdue University, addresses the design of Healthcare information systems. Such systems are becoming ubiquitous and thus increasingly subject to attack, misuse and abuse. Specifications and designs of these systems often neglect security and privacy concerns. Moreover, regulations such as HIPAA (Health Insurance Portability and Accountability Act) as well as security and privacy policies are difficult for users to understand and complex for software engineers to use as guides when designing and implementing systems. This project defines mechanisms that are needed to help analysts disambiguate regulations so that they may be clearly specified as software requirements. In addition, regulations are increasingly requiring organizations to comply with the law and account for their actions. Individuals responsible for ensuring compliance and accountability currently lack sufficient guidance and support to manage their legal obligations within relevant information systems. Software controls are needed to provide assurances that business processes adhere to specific requirements, especially those derived from government regulations. To address these challenges, the proposed work takes a holistic view of the design of transparent and legally compliant software systems. Key research questions that are addressed include: -How should system requirements be specified so they may be realized in design and implementation to ensure legal and regulatory compliance? -Given that software designs need to satisfy multiple stakeholders (organizations, law/policy makers, government agencies, public citizens, etc.) having contradictory, inconsistent and difficult to understand objectives, how can the design process of these systems be improved to lead to convergence and satisfaction of these requirements in a transparent and auditable fashion? This project articulates a requirements management framework that enables executives, business managers, software developers and auditors to distribute legal obligations across business units and/or personnel with different roles and technical capabilities. This framework improves accountability by integrating traceability throughout the policy and requirements lifecycle. The broader impacts of this project are expected to be far reaching as law and regulations govern the collection, use, transfer and removal of information from software systems in many spheres of society.
该项目涉及北卡罗来纳州州立大学和普渡大学之间的合作,涉及医疗保健信息系统的设计。这种系统正变得无处不在,因此越来越容易受到攻击、误用和滥用。这些系统的规格和设计往往忽视安全和隐私问题。此外,诸如HIPAA(健康保险可携性和责任法案)以及安全和隐私政策等法规对于用户来说难以理解,并且对于软件工程师来说在设计和实现系统时用作指南是复杂的。该项目定义了帮助分析师消除法规歧义所需的机制,以便将法规明确指定为软件需求。此外,法规越来越多地要求各组织遵守法律并对其行为负责。负责确保合规和问责的个人目前缺乏足够的指导和支持,无法在相关信息系统内管理其法律的义务。需要软件控制来保证业务流程符合特定要求,特别是来自政府法规的要求。为了应对这些挑战,拟议的工作需要一个透明的和合法的软件系统的设计的整体视图。解决的关键研究问题包括:-应如何指定系统的要求,使他们可以实现在设计和实施,以确保法律的和法规的遵守?- 鉴于软件设计需要满足多个利益相关者(组织、法律/政策制定者、政府机构、公众公民等)由于这些系统的目标相互矛盾、不一致和难以理解,如何改进这些系统的设计过程,以透明和可审计的方式使这些要求趋于一致并得到满足?该项目阐明了一个需求管理框架,使执行人员、业务经理、软件开发人员和审计人员能够在具有不同角色和技术能力的业务单位和/或人员之间分配法律的义务。该框架通过在整个策略和需求生命周期中集成可追溯性来提高可问责性。由于社会许多领域的软件系统中信息的收集、使用、转移和删除受到法律和条例的制约,预计该项目的广泛影响将是深远的。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Eugene Spafford其他文献

Eugene Spafford的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Eugene Spafford', 18)}}的其他基金

EAGER: Exploring the Use of Deception to Enhance Cyber Security
EAGER:探索利用欺骗手段增强网络安全
  • 批准号:
    1548114
  • 财政年份:
    2015
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Preparing Cyber Security Leaders
培养网络安全领导者
  • 批准号:
    1027493
  • 财政年份:
    2011
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Continuing Grant
A Dual-Track Masters Degree Program for Information Security Specialists
信息安全专家双轨硕士学位课程
  • 批准号:
    0965780
  • 财政年份:
    2010
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
CT-ISG: Designing Next-Generation, Reliable Internet Servers
CT-ISG:设计下一代可靠的互联网服务器
  • 批准号:
    0523243
  • 财政年份:
    2005
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Exposing Grand Challenges in Information Security & Assurance
暴露信息安全的巨大挑战
  • 批准号:
    0335324
  • 财政年份:
    2003
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Continuing Grant
A Dual-Track Masters Degree Program for Information Security Specialists
信息安全专家双轨硕士学位课程
  • 批准号:
    0113730
  • 财政年份:
    2001
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Continuing Grant
CISE Experimental Partnerships: Audit Trails: Content, Storage and Processing
CISE 实验合作伙伴:审核跟踪:内容、存储和处理
  • 批准号:
    9903545
  • 财政年份:
    1999
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
RIA: Debugging with Test-Based Information
RIA:使用基于测试的信息进行调试
  • 批准号:
    8910306
  • 财政年份:
    1989
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant

相似海外基金

Collaborative Research: SoD-TEAM: Designing Tests for Evolving Software Systems
协作研究:SoD-TEAM:为不断发展的软件系统设计测试
  • 批准号:
    0725190
  • 财政年份:
    2008
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: 'Values at Play: Integrating Ethical and Political Factors into System Design'
合作研究:SoD-TEAM:“发挥价值:将道德和政治因素融入系统设计”
  • 批准号:
    0924088
  • 财政年份:
    2008
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: Designing Tests for Evolving Software Systems
协作研究:SoD-TEAM:为不断发展的软件系统设计测试
  • 批准号:
    0725202
  • 财政年份:
    2008
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
SoD: Collaborative Research: Transparency and Legal Compliance in Software Systems
SoD:协作研究:软件系统的透明度和法律合规性
  • 批准号:
    0725144
  • 财政年份:
    2007
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: A Feedback-Based Architecture for Highly Reliable Embedded Software
合作研究:SoD-TEAM:基于反馈的高度可靠嵌入式软件架构
  • 批准号:
    0613308
  • 财政年份:
    2006
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: A Feedback-Based Architecture for Highly Reliable Embdedded Software
合作研究:SoD-TEAM:基于反馈的高可靠性嵌入式软件架构
  • 批准号:
    0613665
  • 财政年份:
    2006
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: Values at Play - Integrating Social Factors into Design
协作研究:SoD-TEAM:发挥价值 - 将社会因素融入设计
  • 批准号:
    0613893
  • 财政年份:
    2006
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: "Values at Play: Integrating Ethical and Political Factors into System Design
合作研究:SoD-TEAM:“发挥价值:将伦理和政治因素融入系统设计
  • 批准号:
    0613867
  • 财政年份:
    2006
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: A Feedback-Based Architecture for Highly Reliable Embedded Software
合作研究:SoD-TEAM:基于反馈的高度可靠嵌入式软件架构
  • 批准号:
    0650049
  • 财政年份:
    2006
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
Collaborative Research: SoD-TEAM: A Feedback-Based Architecture for Highly Reliable Embedded Software
合作研究:SoD-TEAM:基于反馈的高度可靠嵌入式软件架构
  • 批准号:
    0613655
  • 财政年份:
    2006
  • 资助金额:
    $ 22.96万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了