Abstract: |
Nowadays, many legislators decided to enact different laws, which all enforce legal and natural persons to deal more carefully with IT systems. Hence, there is a need for techniques to identify and analyze laws, which are relevant for an IT system. But identifying relevant compliance regulations for an IT system and aligning it to be compliant to these regulations is a challenging task. In earlier works of ours we proposed patterns and a structured method to tackle these problems. One of the central crucial steps, while using the patterns and the method, is the transformation of requirements into a structure, allowing the identification of laws. The step is not trivial, as requirements, in most cases, focus on the technical parts of the problem, putting the knowledge about the environment of the system aside. In this work, we propose a method to structure the requirements, elicit the needed domain knowledge and transform requirements into law identification pattern instances. For this purpose, we make use of problem diagrams, problem frames, domain knowledge, and questionnaire. We present our method using a voting system as an example, which was obtained from the ModIWa DFG project and the common criteria profile for voting systems. |