SaTC: CORE: Small: Collaborative: Enabling Regulatory Compliance for Software Engineering
SaTC: CORE: Small: Collaborative: Enabling Regulatory Compliance for Software Engineering
批准号:
1938121
负责人:
Sreedevi Sampath
金额:
$56.05万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-07-01 至 2024-06-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Software systems are ubiquitous in modern society, but engineering systems that are demonstrably compliant with relevant laws and regulations remains both theoretically and practically challenging. Unfortunately, assessing a system for regulatory compliance is challenging and expensive, which ensures existing laws and regulations have low enforcement rates. Further, organizations have no standard approach they can use to document their due diligence and compliance efforts, and the number and types of regulations applicable to software is expected to increase, as software becomes more integrated and central to traditionally non-software domains. This proposed research seeks to create a software development methodology for regulatory compliance. Software engineering professionals using this methodology will be able to both manage the regulatory compliance aspects of their systems under development and also to demonstrate to an outside auditor, to customers, and to the public, their approach towards compliance at each stage of the software development lifecycle (SDLC). This research has the potential to affect every software system developed for use in a regulated domain. In general, society regulates domains first and considers software second. For non-software domains that nevertheless depend on software (e.g., healthcare, automotive, finance, etc.), organizations are left measuring inputs and outputs, and they have no insight into the full engineering process used to develop the software that controls potentially critical elements of the system. This work will transform how organizations think about liability and compliance by providing organizations the tools needed to demonstrate that they attempted to do the right thing, even if a failure occurs. The results of this work will be incorporated in graduate and undergraduate courses on topics such as security and privacy, systems analysis, software testing and software maintenance. The core research problem this award addresses is: How can software engineers incorporate and demonstrate compliance with security and privacy laws, regulations, guidelines, and standards throughout the design, development, and maintenance of software systems? The goal of this project is to develop a full-lifecycle methodology, based on current practice and research, to help software engineers, policy makers, and regulators build and assess software systems. This goal is organized into three phases: (1) the development of a comprehensive core framework of definitions, concepts, models, and templates for security and privacy regulatory compliance based on current practices and new research; (2) the identification and mitigation of gaps in particular phases of the SDLC that research and practice have not fully addressed (in particular testing and maintenance); and (3) a longitudinal mixed-method interaction with a variety of stakeholders to continuously explore current practices of organizations building software in regulated domains, identify gaps between research and practice, and iteratively evaluate this methodology. Upon completion, this framework will address management of intentional and unintentional regulatory ambiguity, improve communication between stakeholders from disparate domains, (e.g., lawyers, policy makers, regulatory agencies, developers, managers, and testers), and ameliorate the dearth of methods for testing and maintaining regulatory compliance of software.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1109/re51729.2021.00012
发表时间:
2021
期刊:
2021 IEEE 29th International Requirements Engineering Conference (RE
影响因子:
--
作者:
[Kempe, Evelyn, Massey, Aaron]
通讯作者:
Massey, Aaron
Regulatory and Security Standard Compliance Throughout the Software Development Lifecycle
整个软件开发生命周期的监管和安全标准合规性
DOI:
--
发表时间:
2021
期刊:
Proceedings of the 54th Hawaii International Conference on System Sciences
影响因子:
--
作者:
[Kempe, Evelyn, Massey, Aaron K.]
通讯作者:
Massey, Aaron K.
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: