Regulatory requirements traceability and analysis using semi-formal specifications

  • Authors:
  • Travis D. Breaux;David G. Gordon

  • Affiliations:
  • Institute for Software Research, Carnegie Mellon University, Pittsburgh, PA;Engineering and Public Policy, Carnegie Mellon University, Pittsburgh, PA

  • Venue:
  • REFSQ'13 Proceedings of the 19th international conference on Requirements Engineering: Foundation for Software Quality
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Information systems are increasingly distributed and pervasive, enabling organizations to deliver remote services and share personal information, worldwide. However, developers face significant challenges in managing the many laws that govern their systems in this multi-jurisdictional environment. In this paper, we report on a computational requirements document expressible using a legal requirements specification language (LRSL). The purpose is to make legal requirements open and available to policy makers, business analysts and software developers, alike. We show how requirements engineers can codify policy and law using the LRSL and design, debug, analyze, trace, and visualize relationships among regulatory requirements. The LRSL provides new constructs for expressing distributed constraints, making regulatory specification patterns visually salient, and enabling metrics to quantitatively measure different styles for writing legal and policy documents. We discovered and validated the LRSL using thirteen U.S. state data breach notification laws.