Regulatory compliance is a well-studied area, including research on how to model, check, analyse, enact, and verify compliance of software. However, while the theoretical body of knowledge is vast, empirical evidence on challenges with regulatory compliance, as faced by industrial practitioners particularly in the Software Engineering domain, is still lacking. In this paper, we report on an industrial case study which aims at providing insights into common practices and challenges with checking and analysing regulatory compliance, and we discuss our insights in direct relation to the state of reported evidence. Our study is performed at Ericsson AB, a large telecommunications company, which must comply to both locally and internationally governing regulatory entities and standards such as GDPR. The main contributions of this work are empirical evidence on challenges experienced by Ericsson that complement the existing body of knowledge on regulatory compliance.
翻译:监管合规是一个研究周密的领域,包括研究如何对软件的合规情况进行建模、检查、分析、颁布和核查,然而,尽管理论知识体系是庞大的,但关于监管合规方面的挑战的经验证据仍然缺乏,特别是在软件工程领域,工业从业者在监管合规方面尤其面临挑战,在本文件中,我们报告了一项工业案例研究,旨在深入了解检查和分析监管合规方面的共同做法和挑战,我们讨论了与所报告证据状况直接相关的见解。我们的研究是在一家大型电信公司Ericsson AB进行的,该公司必须遵守当地和国际监管监管实体和标准,如GDPR。 这项工作的主要贡献是经验证据,证明Ericsson所经历的挑战是对监管合规方面现有知识体系的补充。