About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



17 A.I. & L. 1 (2009)

handle is hein.journals/artinl17 and id is 1 raw text is: Artif Intell Law (2009) 17:1-30
DOI 10.1007/s10506-008-9067-3
How to integrate legal requirements
into a requirements engineering methodology
for the development of security and privacy patterns
Luca Compagna - Paul El Khoury - Alibeta Krausov&P
Fabio Massacci - Nicola Zannone
Published online: 22 November 2008
© Springer Science+Business Media B.V. 2008
Abstract Laws set requirements that force organizations to assess the security and
privacy of their IT systems and impose them to implement minimal precautionary
security measures. Several IT solutions (e.g., Privacy Enhancing Technologies,
Access Control Infrastructure, etc.) have been proposed to address security and
privacy issues. However, understanding why, and when such solutions have to be
adopted is often unanswered because the answer comes only from a broader per-
spective, accounting for legal and organizational issues. Security engineers and
legal experts should analyze the business goals of a company and its organizational
structure and derive from there the points where security and privacy problems may
arise and which solutions best fit such (legal) problems. The paper investigates the
L. Compagna - P. El Khoury
SAP Research, Nice, France
L. Compagna
e-mail: luca.compagna@sap.com
P. El Khoury
University of Lyon I, LIRIS CNRS UMR 5205, Lyon, France
e-mail: paul.el.khoury@sap.com
A. Krausovi
ICRI - K.U. Leuven - IBBT, Leuven, Belgium
e-mail: betty.krausova@law.kuleuven.be
F. Massacci
University of Trento, Trento, Italy
e-mail: fabio.massacci@unitn.it
N. Zannone (E)
University of Toronto, Toronto, ON, Canada
e-mail: zannone@cs.toronto.edu

_ Springer