Enabling Continuous Compliance with Product-Repository Integrated Traceability Management Tool

Hämtar...
Bild (thumbnail)

Publicerad

Författare

Typ

Examensarbete för masterexamen
Master's Thesis

Modellbyggare

Tidskriftstitel

ISSN

Volymtitel

Utgivare

Sammanfattning

Continuous compliance is becoming increasingly important as software-intensive systems are developed in regulated domains, where both systems and regulatory expectations evolve over time. Traditional compliance approaches often rely on manual evidence collection and periodic assessment, making it difficult to maintain compliance during continuous development. This thesis investigates how product repository-integrated traceability management (PRITM) tools can support continuous compliance by managing compliance-relevant artifacts, traceability links and checks within a product repository. The study follows a Design Science Research approach with three iterations. For RQ1, literature review and workshops were used to develop a reference model of continuous compliance. The main finding is that software development activities support continuous compliance by producing and updating artifacts that can serve as evidence of compliance. However, these artifacts only become useful evidence when they are traceable, maintained and connected to compliance requirements and compliance checks. For RQ2, the reference model was instantiated via a TReqs plugin prototype named treqs-compliance. The prototype uses ISO 26262 Part 8 Clauses 7 and 8 as an example to demonstrate how standards, clauses, compliance requirements, and work products can be represented and maintained in a product repository. The prototype implements rule-based structural checks, lifecycle status handling, change-review detection, and compliance report generation. The main finding is that PRITM tools can support continuous compliance by keeping compliance artifacts close to development artifacts, managing traceability, and enabling lightweight automated checks. For RQ3, the prototype and final reference model were used to reflect on where effort could be reduced compared to traditional compliance approaches. The results suggest that PRITM tools can mainly reduce effort for structural and traceability related tasks, such as checking artifact existence, identifying required fields, and locating missing links. However, semantic content evaluation, runtime context checks, and structured compliance argumentation remain outside the implemented scope and still require human judgment or more advanced tool support. This thesis contributes a reference model for understanding continuous compliance across activities and artifacts, with a particular focus on the DevOps lifecycle. It also provides a prototype demonstration showing how selected concepts can be implemented in a PRITM tool.

Beskrivning

Ämne/nyckelord

continuous compliance, compliance as code, traceability, Requirements Engineering (RE), ISO 26262

Citation

Arkitekt (konstruktör)

Geografisk plats

Byggnad (typ)

Byggår

Modelltyp

Skala

Teknik / material

Index

Endorsement

Review

Supplemented By

Referenced By