Enabling Continuous Compliance with Product-Repository Integrated Traceability Management Tool
Hämtar...
Ladda ner
Publicerad
Författare
Typ
Examensarbete för masterexamen
Master's Thesis
Master's Thesis
Modellbyggare
Tidskriftstitel
ISSN
Volymtitel
Utgivare
Sammanfattning
Continuous compliance is becoming increasingly important as software-intensive
systems are developed in regulated domains, where both systems and regulatory
expectations evolve over time. Traditional compliance approaches often rely on
manual evidence collection and periodic assessment, making it difficult to maintain
compliance during continuous development. This thesis investigates how product
repository-integrated traceability management (PRITM) tools can support continuous compliance by managing compliance-relevant artifacts, traceability links and
checks within a product repository.
The study follows a Design Science Research approach with three iterations. For
RQ1, literature review and workshops were used to develop a reference model of
continuous compliance. The main finding is that software development activities
support continuous compliance by producing and updating artifacts that can serve
as evidence of compliance. However, these artifacts only become useful evidence
when they are traceable, maintained and connected to compliance requirements and
compliance checks.
For RQ2, the reference model was instantiated via a TReqs plugin prototype named
treqs-compliance. The prototype uses ISO 26262 Part 8 Clauses 7 and 8 as an
example to demonstrate how standards, clauses, compliance requirements, and work
products can be represented and maintained in a product repository. The prototype
implements rule-based structural checks, lifecycle status handling, change-review
detection, and compliance report generation. The main finding is that PRITM
tools can support continuous compliance by keeping compliance artifacts close to
development artifacts, managing traceability, and enabling lightweight automated
checks.
For RQ3, the prototype and final reference model were used to reflect on where
effort could be reduced compared to traditional compliance approaches. The results
suggest that PRITM tools can mainly reduce effort for structural and traceability
related tasks, such as checking artifact existence, identifying required fields, and locating missing links. However, semantic content evaluation, runtime context checks,
and structured compliance argumentation remain outside the implemented scope
and still require human judgment or more advanced tool support.
This thesis contributes a reference model for understanding continuous compliance
across activities and artifacts, with a particular focus on the DevOps lifecycle. It
also provides a prototype demonstration showing how selected concepts can be implemented in a PRITM tool.
Beskrivning
Ämne/nyckelord
continuous compliance, compliance as code, traceability, Requirements Engineering (RE), ISO 26262
