Compliance Requirements in Large-Scale Software Development: An Industrial Case Study

Muhammad Usman,Michael Felderer,Michael Unterkalmsteiner,Eriks Klotins,Daniel Mendez,Emil Alegroth
DOI: https://doi.org/10.48550/arXiv.2103.01821
2021-03-02
Software Engineering
Abstract:Regulatory compliance is a well-studied area, including research on how to model, check, analyse, enact, and verify compliance of software. However, while the theoretical body of knowledge is vast, empirical evidence on challenges with regulatory compliance, as faced by industrial practitioners particularly in the Software Engineering domain, is still lacking. In this paper, we report on an industrial case study which aims at providing insights into common practices and challenges with checking and analysing regulatory compliance, and we discuss our insights in direct relation to the state of reported evidence. Our study is performed at Ericsson AB, a large telecommunications company, which must comply to both locally and internationally governing regulatory entities and standards such as GDPR. The main contributions of this work are empirical evidence on challenges experienced by Ericsson that complement the existing body of knowledge on regulatory compliance.
What problem does this paper attempt to address?