SoD: Collaborative Research: Transparency and Legal Compliance in Software Systems
SoD:协作研究:软件系统的透明度和法律合规性
基本信息
- 批准号:0725152
- 负责人:
- 金额:$ 22.96万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2007
- 资助国家:美国
- 起止时间:2007-08-01 至 2011-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This project, involving collaboration between North Carolina State University and Purdue University, addresses the design of Healthcare information systems. Such systems are becoming ubiquitous and thus increasingly subject to attack, misuse and abuse. Specifications and designs of these systems often neglect security and privacy concerns. Moreover, regulations such as HIPAA (Health Insurance Portability and Accountability Act) as well as security and privacy policies are difficult for users to understand and complex for software engineers to use as guides when designing and implementing systems. This project defines mechanisms that are needed to help analysts disambiguate regulations so that they may be clearly specified as software requirements. In addition, regulations are increasingly requiring organizations to comply with the law and account for their actions. Individuals responsible for ensuring compliance and accountability currently lack sufficient guidance and support to manage their legal obligations within relevant information systems. Software controls are needed to provide assurances that business processes adhere to specific requirements, especially those derived from government regulations. To address these challenges, the proposed work takes a holistic view of the design of transparent and legally compliant software systems. Key research questions that are addressed include: -How should system requirements be specified so they may be realized in design and implementation to ensure legal and regulatory compliance? -Given that software designs need to satisfy multiple stakeholders (organizations, law/policy makers, government agencies, public citizens, etc.) having contradictory, inconsistent and difficult to understand objectives, how can the design process of these systems be improved to lead to convergence and satisfaction of these requirements in a transparent and auditable fashion? This project articulates a requirements management framework that enables executives, business managers, software developers and auditors to distribute legal obligations across business units and/or personnel with different roles and technical capabilities. This framework improves accountability by integrating traceability throughout the policy and requirements lifecycle. The broader impacts of this project are expected to be far reaching as law and regulations govern the collection, use, transfer and removal of information from software systems in many spheres of society.
该项目涉及北卡罗来纳州立大学和普渡大学之间的合作,介绍了医疗保健信息系统的设计。这样的系统变得无处不在,因此越来越受到攻击,滥用和滥用。这些系统的规格和设计通常会忽略安全性和隐私问题。此外,诸如HIPAA(健康保险可移植性和问责制)以及安全性和隐私政策等法规很难理解和复杂,让软件工程师在设计和实施系统时可以用作指南。该项目定义了所需的机制,这些机制可以帮助分析师消除歧义法规,以便可以清楚地将其指定为软件要求。此外,法规越来越多地要求组织遵守法律并说明其行为。负责确保合规性和问责制的个人缺乏足够的指导和支持,无法在相关信息系统中管理其法律义务。需要软件控件来提供保证业务流程符合特定要求,尤其是从政府法规中得出的要求。为了应对这些挑战,拟议的工作对透明且合法合法的软件系统的设计有了整体的看法。解决的关键研究问题包括: - 应如何指定系统要求,以便在设计和实施中实现它们以确保法律和法规合规性? - 赋予软件设计需要满足多个利益相关者(组织,法律/政策制定者,政府机构,公民等),具有矛盾,不一致且难以理解目标,如何改善这些系统的设计过程以在透明和审计的方式中导致这些需求和满足这些需求?该项目阐明了一个要求管理框架,该框架使高管,业务经理,软件开发人员和审计师能够跨业务部门和/或具有不同角色和技术能力的人员分配法律义务。该框架通过在整个政策和需求生命周期中整合可追溯性来提高问责制。随着法律和法规控制着社会许多领域的软件系统的收集,使用,转移和删除信息,预计该项目的更广泛影响将是遥不可及的。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Eugene Spafford其他文献
Eugene Spafford的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Eugene Spafford', 18)}}的其他基金
EAGER: Exploring the Use of Deception to Enhance Cyber Security
EAGER:探索利用欺骗手段增强网络安全
- 批准号:
1548114 - 财政年份:2015
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
A Dual-Track Masters Degree Program for Information Security Specialists
信息安全专家双轨硕士学位课程
- 批准号:
0965780 - 财政年份:2010
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
CT-ISG: Designing Next-Generation, Reliable Internet Servers
CT-ISG:设计下一代可靠的互联网服务器
- 批准号:
0523243 - 财政年份:2005
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
Exposing Grand Challenges in Information Security & Assurance
暴露信息安全的巨大挑战
- 批准号:
0335324 - 财政年份:2003
- 资助金额:
$ 22.96万 - 项目类别:
Continuing Grant
A Dual-Track Masters Degree Program for Information Security Specialists
信息安全专家双轨硕士学位课程
- 批准号:
0113730 - 财政年份:2001
- 资助金额:
$ 22.96万 - 项目类别:
Continuing Grant
CISE Experimental Partnerships: Audit Trails: Content, Storage and Processing
CISE 实验合作伙伴:审核跟踪:内容、存储和处理
- 批准号:
9903545 - 财政年份:1999
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
RIA: Debugging with Test-Based Information
RIA:使用基于测试的信息进行调试
- 批准号:
8910306 - 财政年份:1989
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
相似国自然基金
数智背景下的团队人力资本层级结构类型、团队协作过程与团队效能结果之间关系的研究
- 批准号:72372084
- 批准年份:2023
- 资助金额:40 万元
- 项目类别:面上项目
在线医疗团队协作模式与绩效提升策略研究
- 批准号:72371111
- 批准年份:2023
- 资助金额:41 万元
- 项目类别:面上项目
面向人机接触式协同作业的协作机器人交互控制方法研究
- 批准号:62373044
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
基于数字孪生的颅颌面人机协作智能手术机器人关键技术研究
- 批准号:82372548
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
A-型结晶抗性淀粉调控肠道细菌协作产丁酸机制研究
- 批准号:32302064
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: SoD-TEAM: Designing Tests for Evolving Software Systems
协作研究:SoD-TEAM:为不断发展的软件系统设计测试
- 批准号:
0725190 - 财政年份:2008
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
Collaborative Research: SoD-TEAM: 'Values at Play: Integrating Ethical and Political Factors into System Design'
合作研究:SoD-TEAM:“发挥价值:将道德和政治因素融入系统设计”
- 批准号:
0924088 - 财政年份:2008
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
Collaborative Research: SoD-TEAM: Designing Tests for Evolving Software Systems
协作研究:SoD-TEAM:为不断发展的软件系统设计测试
- 批准号:
0725202 - 财政年份:2008
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
SoD: Collaborative Research: Transparency and Legal Compliance in Software Systems
SoD:协作研究:软件系统的透明度和法律合规性
- 批准号:
0725144 - 财政年份:2007
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant
Collaborative Research: SoD-TEAM: A Feedback-Based Architecture for Highly Reliable Embedded Software
合作研究:SoD-TEAM:基于反馈的高度可靠嵌入式软件架构
- 批准号:
0613308 - 财政年份:2006
- 资助金额:
$ 22.96万 - 项目类别:
Standard Grant