<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Modeling and analyzing Information Quality Requirements for Socio-technical Systems: Experience Report</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Mohamad Gharib</string-name>
          <email>gharib@disi.unitn.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Paolo Giorgini</string-name>
          <email>paolo.giorgini@disi.unitn.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="editor">
          <string-name>Information Quality, Requirements Engineering, Modeling, Reasoning</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Trento - DISI</institution>
          ,
          <addr-line>38123, Povo, Trento</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <fpage>84</fpage>
      <lpage>99</lpage>
      <abstract>
        <p>Information Quality (IQ) is particularly important for the efcient performance of any system. Despite this, most of the Requirements Engineering (RE) frameworks either ignore IQ needs, or they deal with them as mere technical issues, i.e., they do not consider the social and organizational aspects that underlie such needs. This paper summarizes the experience of the authors in modeling and analyzing IQ requirements for socio-technical systems. In particular, it summarizes the authors effort to propose an integrated RE framework that provides concepts for modeling and reasoning about IQ requirements since the early phases of the socio-technical system development.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Nowadays, Information Quality (IQ) is a growing concern for most organizations,
since they depend on information for managing their daily operations, taking
important decisions, etc., and relying on low quality information may negatively
in uence their overall performance, or it might even leads to disasters in the
case of critical systems (e.g., air tra c management systems, etc.). Despite this,
most existing Requirements Engineering (RE) frameworks and approaches either
loosely de ne, or simply ignore IQ requirements. Several techniques for dealing
with IQ have been proposed in the literature (e.g., integrity constraints).
However, most of them focus on the technical aspects, and do not solve problems that
may arise at organizational or social levels. More speci cally, these techniques do
not satisfy the needs of current complex systems, such as socio-technical systems
[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], where humans and their interactions are considered as an integral part of
the system along with the technical elements (e.g., smart cities, etc.).
      </p>
      <p>
        Fisher and Kingma [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] highlighted the limitation of existing IQ techniques
for addressing IQ related issues that might arise at the social or organizational
level, where di erent kinds of vulnerabilities might manifest themselves in the
actors' interactions and dependencies. For instance, the Flash Crash (a main
stock market crash) is an example where the problem was not caused by a mere
technical failure, but it was due to several socio-technical related vulnerabilities
of the system [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. In particular, several reasons contributed to the Flash Crash
were caused by socio-technical IQ related issues. For example, some traders
intentionally provide inaccurate information (e.g., fraud, falsi ed, etc.). Others
continue trading during the crash by forwarding their orders to the markets that
did not halt their trading activities due to lack of coordination among the
markets, where the lack of coordination resulted also from IQ related vulnerabilities.
We advocate that such failures could be avoided if the IQ requirements of the
system were captured properly during the system design.
      </p>
      <p>
        In addition, most of these approaches provide ad-hoc techniques to deal with
IQ related vulnerabilities, instead of solving the main reason of such
vulnerabilities by considering them during the early phase of the system development (e.g.,
requirements level). In particular, a RE framework that enables for modeling
and reasoning about IQ requirements is still missed. To this end, we proposed a
novel RE framework that adopts the Goal-Oriented Requirements Engineering
(GORE) paradigm. Among the several GORE approaches o ered in the
literature (e.g., KAOS, i*, etc.), we adopted Secure Tropos [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] as a baseline for
our framework. Secure Tropos introduces primitives for modeling actors of the
system along with their objectives, entitlements and capabilities. Moreover, it
allows for modeling the social and organizational environment where the system
will be eventually implemented, which is the main reason for choosing it as
baseline for our proposed framework. In particular, our proposed framework extends
the conceptual model of Secure Tropos by providing concepts and constructs
for modeling and reasoning about IQ requirements. In what follows, we list and
discuss the main objectives of this research.
      </p>
      <p>Objectives of the research : as previously discussed, a RE framework for
capturing IQ requirements is still missing. This paper summarizes our e ort to
solve this problem by proposing a framework that is able to model and reason
about IQ requirements. In particular, through this paper we summarize our work
trying to answer the following research questions:
RQ1: How can we analyze IQ in socio-technical systems? in other words,
which IQ dimensions should be considered for analyzing IQ from
sociotechnical perspective. We summaries our e ort to answer this question in
section 3;
RQ2: How can we model IQ requirements? we summaries our e ort to
answer this question in section 4 by proposing concepts and constructs for
modeling IQ requirements;
RQ3: How can we verify the correctness of the IQ requirements
model? we summaries our e ort to answer this question in section 5, by
discussing a set of properties of the design that can be used to verify the
correctness and consistency of the IQ requirements model.</p>
      <p>RQ4: How can we support system designers in constructing the
system? we summaries our e ort to answer this question in section 6 by
proposing a methodological process to be followed by system designers during the
di erent phases of the system design.</p>
      <p>RQ5: How well does the framework perform when applied to
realistic settings? we summaries our e ort to answer this question in section
7 by performing a set of experiments to verify whether the framework can
e ciently perform the tasks it has been developed to do.</p>
      <p>This experience report is structured as follows; Section (x2) describes our
motivating example, while in Section (x3) we propose our multi-dimensional
model for analyzing IQ. In Section (x4), we highlight the limitation in Secure
Tropos for dealing with IQ requirements, and then we propose the required
modeling concepts and constructs. Section (x5) presents the reasoning techniques
that our framework o ers; and in Section (x6) we introduce the methodological
process that underlies our framework. Section (x7) implements and evaluates the
proposed framework. Finally, in Section (x8) we present our ongoing work, and
we conclude the report at Section (x9).
2</p>
    </sec>
    <sec id="sec-2">
      <title>Motivating Example</title>
      <p>
        Our motivating example concerns the May 6, 2010 Flash Crash, in which the Dow
Jones Industrial Average (DJIA) dropped about 1000 points (9% of its value).
Based on [
        <xref ref-type="bibr" rid="ref5 ref6">5,6</xref>
        ], we can identify several main stakeholders of system, including:
stock investors are individuals or companies, who have a main goal of making
pro t from trading securities. While stock traders are individuals or companies
involved in trading securities in stock markets either for their own sake or on
behalf of their investors with a main goal of making pro t by trading
securities. Traders can be classi ed under several main categories, including: Market
Makers are traders who have the capability to trade large number of particular
securities, and they facilitate trading on such securities in the market;
HighFrequency Traders (HFTs) are traders who have the capability to trade with
very high trading frequency; and Small traders: trade small amount of securities
with low trading frequency.
      </p>
      <p>Stock markets are the places where traders gather and trade securities (e.g.,
NYSE, Chicago Mercantile Exchange (CME), NASDAQ). Markets have a main
goal of making pro t by facilitating security trading. Usually, they manage
traders' order matching and should ensure stable trading environment, which
can be done by depending on their Circuit Breakers (CBs), where a CB is a
technique that is used to slow down or halt trading to prevent a potential market
crash. Furthermore, accounting rms are specialized for performing accounting
activities, i.e., provide companies with clear and reliable information about their
economic activities and the status of their assets. While auditing rms are
specialized for providing e cient monitoring of the quality of information produced
by companies concerning their nancial statements. Moreover, consulting rms
are rms specialized for providing professional advices concerning nancial
securities for a fee to traders and investors. Finally, credit assessment ratings rms
are rms with a main objective of providing assessments of the credit worthiness
of companies' securities, i.e., such rms help traders in deciding how risky it is
to invest money in a certain security.</p>
      <p>
        A deep analysis of the Flash Crash shows that several reasons that led to
the failure were caused by IQ related vulnerabilities. In what follows, we list
and discuss the main theories that have been proposed to explain the Crash:
(1) Fat- nger trade that is a human error caused by pressing a wrong key when
using a computer to input data; (2) The suspicious behavior of some HFTs that
negatively e ects the market prices and contributed to the Flash Crash [
        <xref ref-type="bibr" rid="ref5 ref6">5,6</xref>
        ]; (3)
Fraud/ falsi ed information that have been used by some actors and negatively
in uence the overall system performance. E.g., HFTs' ickering quotes that last
very short time, which make them unavailable for most of traders, and Market
Makers' stub quotes that are orders with prices far away from the current market
prices[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]; (4) Undetected vulnerabilities in the socio-technical system design that
led to a failure in the overall system.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>A Multi-dimensional Model for IQ Analysis</title>
      <p>
        IQ is a hierarchical multi-dimensional concept that can be characterized by di
erent dimensions/ sub-dimensions (e.g., accuracy, completeness, consistency, etc.
[
        <xref ref-type="bibr" rid="ref7 ref8">7,8</xref>
        ]). Although there exist several models for analyzing IQ (e.g., [
        <xref ref-type="bibr" rid="ref10 ref8 ref9">9,8,10</xref>
        ]), yet
they were not designed to capture the needs of socio-technical systems, i.e., they
do not consider the social and organizational aspects that might underlie some
IQ dimensions.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], we analyzed IQ based on four of its dimensions (highlighted within
a box in Figure 1), namely: accuracy, completeness, timeliness and consistency.
While in [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], we considered an extended model (shown in Figure 1) for
analyzing IQ based on seven IQ dimensions: accessibility, accuracy, believability,
trustworthiness, completeness, timeliness and consistency. In addition, it
considers the intentional, social and organizational aspects that might underlie these
dimensions. We de ne and discuss each of these dimensions along with their
interrelations and how they can be analyzed as follows:
      </p>
      <p>
        Accessibility : the extent to which information is available, or easily and
quickly retrieved [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. We limit accessibility de nition to having the required
permission over information to perform a task at hand.
      </p>
      <p>
        Believability : can be de ned as to which extent information is accepted or
regarded as true [
        <xref ref-type="bibr" rid="ref7 ref8">7,8</xref>
        ]. Concerning our motivating example, if markets apply
mechanisms to analyze the believability of the trading orders, they will be able
to detect \stub quotes" that have been provided by some Market Makers, and in
turn, they can mitigate their negative in uence.
      </p>
      <p>
        Trustworthiness : can be de ned as the extent to which information is credible
[
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. We relied on the trustworthiness of the provenance to analyze
trustworthiness, which enables for capturing any information that helps in determining
the trustworthiness of information based on its source (trustworthiness of the
source), and the process by which it has been delivered to its destination
(trust
      </p>
      <p>IQ</p>
      <sec id="sec-3-1">
        <title>Timeliness</title>
      </sec>
      <sec id="sec-3-2">
        <title>Accuracy</title>
      </sec>
      <sec id="sec-3-3">
        <title>Completeness</title>
      </sec>
      <sec id="sec-3-4">
        <title>Consistency</title>
      </sec>
      <sec id="sec-3-5">
        <title>Value</title>
      </sec>
      <sec id="sec-3-6">
        <title>Completeness</title>
      </sec>
      <sec id="sec-3-7">
        <title>Accessibility</title>
      </sec>
      <sec id="sec-3-8">
        <title>Believability</title>
      </sec>
      <sec id="sec-3-9">
        <title>Trustworthiness of provenance</title>
      </sec>
      <sec id="sec-3-10">
        <title>Purpose of use</title>
        <p>completeness</p>
      </sec>
      <sec id="sec-3-11">
        <title>Trustworthiness</title>
        <p>of the source</p>
      </sec>
      <sec id="sec-3-12">
        <title>Trustworthiness of the provision</title>
        <p>worthiness of the provision). Concerning our example, if markets apply a
mechanism to analyze the trustworthiness of the trading orders, they will be able to
detect \ ickering quotes" that have been provided by some HFTs, and apply the
required mechanisms to mitigate their harmful e ect.</p>
        <p>
          Accuracy : means that information should be true or error free with respect to
some known or measured value [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. Accuracy is the most important and studied
dimension, yet without clear standards, estimating accuracy is not an easy task.
However, Dai et al. [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] stated that information accuracy is highly in uenced by
information trustworthiness. While Wang and Strong [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] argued that accuracy
can be analyzed based on several dimensions including believability. Thus, we
analyzed accuracy based on these two sub dimensions.
        </p>
        <p>
          Completeness: means that all parts of information should be available, and
information should be complete for performing a task at hand [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. Thus,
completeness can be analyzed depending on two sub dimensions: Value
Completeness: information is preserved against corruption or lost that might endanger its
integrity (e.g., during its storage/ transfer); and Purpose of use completeness :
information is complete for performing a task at hand, i.e., all the required
information items for performing a speci c task should be available. Concerning
our example, markets depend only on their own CBs information to stabilize
their trading environment. However, such information is enough for each market
alone, but when it comes to coordinate the CBs activities among all the markets,
it can be considered as incomplete information.
        </p>
        <p>
          Timeliness : means to which extent information is valid in term of time (e.g.,
su ciently up-to-date) [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]. According to [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ], information timeliness can be
analyzed depending on information currency that is the time interval between its
creation or update to its usage time [
          <xref ref-type="bibr" rid="ref14 ref7">14,7</xref>
          ]), and information volatility that is
        </p>
        <p>T</p>
        <p>Trade info T</p>
        <p>[time]
Stock
market</p>
        <p>Bank</p>
        <p>NYSE</p>
      </sec>
      <sec id="sec-3-13">
        <title>Manage order and Ensure fair and</title>
        <p>matchtriandgerasmong setnabvlireotnramdeinngt
RfrbeoucmyeiovtRrr[eOad]dseeerlrsals/ndaofPpteeerrrfatotriaromdness enAvtrinraoadlniynPmzgeeanntdenvMtriraRa[odRn]nianmggeent</p>
        <p>Order S
list</p>
        <p>NYSE
part of info
CME
info
Trade
info
information</p>
        <p>[time]
info provision</p>
        <p>produce send modify
Bank
Manage order
matching among
traders
and
and</p>
        <p>Ensure fair and
stable trading
environment</p>
        <p>and
Analyze the Manage</p>
        <p>trading trading
environment environment</p>
        <p>CB info</p>
        <p>
          Trade info
Legend
D goal/info D
goal delegation produceBy
decoamndp/oosrition neededBy
(a) Secure Tropos
Bank
DTT/ inf[otrimmaet]ion DTT/ ][RR []RO paiinnrtffooof [iPn]f[oRr]m[Mati]o[Sn] DTT/ [iPn]f[oRr]m[Mati]o[Sn] DTT/
truinstfo/dpisrtoruvsistsiofnor rerqeuairded oprteioadnal part of pdeerlmegiastsiioonn [dis]trduesltesgpaetiromnission
(b) Modeling extensions proposed in [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] (c) Modeling extensions proposed in [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]
the change frequency of information value [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ], i.e., information is not valid, if
its currency is bigger than its volatility interval, otherwise it is valid.
        </p>
        <p>
          Consistency: means all multiple records of the same information should be the
same across time and space [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. Concerning our example, the lack of coordination
among CB activities of the trading markets will not be resolved unless markets
depend on consistent information for their CB activities.
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4 Extending Secure Tropos with IQ modeling concepts</title>
      <p>
        Secure Tropos (Figure 2 (a)) is able to capture the social and organizational
aspects of the system-to-be, but it does not o ers primitives for capturing IQ
requirements, i.e., it just deals with information whether they are available or
not and who is responsible about their provision. To tackle this problem, we
proposed a framework [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] that extend the conceptual model of Secure Tropos
with concepts for modeling and analyzing four IQ dimensions (Figure 2 (b)).
However, the framework does not provide a systematic process that justify why
a certain IQ dimension should be considered or not for analyzing IQ. Thus, in
[
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] (Figure 2 (c)), we extended our previous framework with a mechanism for
capturing IQ requirements based on the actual purpose of information usage,
and then gradually re ning them in terms of seven di erent IQ dimensions.
      </p>
      <p>In particular, our modeling extensions can be classi ed under the following
two sets: (I) Basic IQ concepts : that provide constructs for modeling seven IQ
dimensions, and (II) Top-level IQ concepts : that are used to capture the IQ
requirements of the stakeholders based on the actual information usage, and
then gradually re ning them until reaching their operational speci cations. More
speci cally, this set is used to identify how top-level IQ requirements can be
captured and then re ned in terms of their di erent IQ dimensions, which can
be modeled by the basic IQ concepts.</p>
      <p>
        (I) Basic IQ concepts: in what follows, we summarize the concepts that
we have proposed in both [
        <xref ref-type="bibr" rid="ref11 ref12">11,12</xref>
        ] for modeling IQ requirements:
      </p>
      <p>Goal-Information relations : we re ned Secure Tropos goal-information
relations by introducing four di erent concepts, (P)roduce indicates that an
information item can be created by achieving the goal that is responsible of it producing;
(R)ead indicates that a goal consumes an information item , and it can be either
optional in which a goal can be achieved even if information was not consumed,
or required in which information is required for the goal achievement; (M)odify :
indicates that the goal achievement depends on modifying an information item;
and (S)end : indicates that the goal achievement depends on transferring an
information item to a speci c destination under prede ned criteria.</p>
      <p>Accessibility : can be in uenced by the permissions that an actor has over
information, which might enables or prevents it from using information as intended.
Thus, we proposed four types of permissions concerning the four types of
information usage that our framework supports (e.g., (P)roduce, (R)ead, (M)odify
and (S)end). In addition, we extend the language to model permission delegation
among actors, and to model trust/ distrusts concerning such permissions.</p>
      <p>Believability : we extended read and produce concepts to accommodate
believability check, since they are the only relations that can be in uenced by
information believability.</p>
      <p>
        Trustworthiness : is subject to (1) trustworthiness of the source that can be
captured by trust/distrust produce relations between information consumer and
its producer concerning the produced information; and the (2) trustworthiness
of the provision. In [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], we proposed trusted/ distrusted provision to analyze
information trustworthiness. However, we noticed that such concepts are at high
abstraction level, and seem to be inappropriate for identifying detailed IQ
speci cations. Thus, we re ned these two concepts in [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], and we analyzed the
trustworthiness of the provision based on the way information arrives to its
destination (e.g., P/IP provision), and the operations (e.g., modify) that have been
applied to it taking into consideration if such operations were authorized or not.
      </p>
      <p>Accuracy : can be analyzed based on : (1) Accuracy of produced information
that can be analyzed based on its believability, which enables to avoid producing
unintended information, and its trustworthiness of the production process if the
producing goal has been delegated; (2) Accuracy of provided information can
be analyzed based on the trustworthiness of the provision; and (3) Accuracy
of read information: can be analyzed based on information believability and its
trustworthiness of the provenance.</p>
      <p>Completeness: completeness can be subject to (1) value completeness for
which we rely on Integrity Preserving provision (IP-provision) that preserves
the integrity of the provided information; and (2) purpose of use completeness
we rely on the \Part of" concept to model the relation between an information
item and its sub-items.</p>
      <p>
        Timeliness (validity): we extended information concept with a volatility
attribute to represent the change rate of information value [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], and we proposed
read time, and send time to analyze the validity of read and send information
respectively. Read time1 captures the actual usage time of information, and it
enables to determine information currency (age), which can be used to analyze
the timeliness of read information, i.e., information is valid, if its currency is
smaller than its volatility, otherwise it is not invalid. While send time represents
the allowed amount of time for information to reach its nal destination. The
timeliness of send information at its destination can be analyzed depending on
the send time and the read time at its destination, i.e., information is valid,
if read time is smaller than the send time. Finally, we extended information
provision with a time aspect that represent the transmission time.
      </p>
      <p>Consistency : we extend the read relation between a goal and information
with Purpose Of Use (POU) attribute that captures the intended purpose of
information usage, which enables to identify interdependent readers that are
actors who read the same information for the same POU. To this end, consistency
can analyzed among interdependent readers based on their read times, i.e.,
information is consistent among its interdependent readers, if all of them have the
same read time, otherwise it is inconsistent.</p>
      <p>
        (II) High-level IQ concepts: in what follows, we summarize the concepts
that we have proposed in [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] for modeling high-level IQ requirements:
      </p>
      <p>Top-level IQ softgoals : are softgoal concerning IQ requirements, and they are
used as a starting point for identifying the stakeholders' needs concerning IQ.</p>
      <p>
        And-decomposition for IQ softgoals re nement : since a softgoal can be re ned
into more speci c sub softgoals, if the joint satisfaction of these softgoals is
considered equivalent to satisfying the re ned softgoal [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. We introduced
Anddecomposition relation between an IQ softgoal and its sub IQ softgoals.
      </p>
      <p>
        Approximating leaf IQ Softgoals : we adopted the approximation relation
proposed by Jureta et al. [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] through which a softgoal can be satis ed by a Quality
Constraint (QC), where a QC can provide clear-cut criteria for the satisfaction of
a softgoal. However, leaf IQ softgoals are used to capture di erent IQ dimensions
(e.g., accuracy, completeness, etc.), i.e., each of them is used to describe di erent
aspects of IQ. Thus, leaf IQ softgoals might not have the same nature/type, and
in turn, they may need to be approximated in di erent ways.
      </p>
      <p>
        Thus, to get better understanding of leaf IQ softgoals nature/type, and to
de ne the appropriate Information Quality Constraints (IQC)2 for their
approximation, we relied on Glinz [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] work that classi es requirements based on their
1 Read time can be derived by analyzing the model, i.e., there is no specialized
construct or attribute to represent it
2 We use IQC to refer to QC, since no other types of constraints are used in this paper
kind, satisfaction and representation, and we classify leaf IQ softgoals under
three main categories.
      </p>
      <p>In addition, for the approximation to be consistent with the di erent types
of leaf IQ softgoals, we de ned three di erent types of IQCs: (1) Operational
IQC: are constraints that de ne the required actions to be performed in already
determined situations; (2) Declarative IQC: are constraints used to de ne
properties of the system that should hold; and (3) Quantitative IQC: are constraints
used to specify properties of the system that should hold, and can be measured
on an ordinal scale. Table 1 shows how leaf IQ softgoals can be classi ed and
approximated into the appropriate IQCs.</p>
      <p>
        Finally, in order for the approximation relation between IQ softgoal and its
related IQC to hold, a well-de ned quality space should exist [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], where a quality
space can be de ned as a certain conceptual space that can be used to describe
the quality value [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. The main purpose of the quality space is removing any
ambiguity related to the veri cation of IQCs, i.e., determining whether a certain
IQC is satis ed or not. Consider timeliness for example; how time is represented
and measured should be clear to all stakeholders of the system, i.e., the allowed
number of digits along with the value they represent (e.g., seconds, etc.).
5
      </p>
    </sec>
    <sec id="sec-5">
      <title>Automated Analysis Support</title>
      <p>
        We used Disjunctive Datalog [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] to formalize all the concepts along with the
related axioms (reasoning rules) that have been introduced in the two
frameworks [
        <xref ref-type="bibr" rid="ref11 ref12">11,12</xref>
        ]. In addition, for each of them we de ned a set of properties of the
design that can be used to verify the IQ requirements model. Table 2 lists some
properties of the design; in what follows we discuss each of them:
      </p>
      <p>Pro1 states that the model should not include any top-level goal that is not
achieved from the perspective of the actor, who aims for it. This property can
be used to quickly verify the IQ requirements model, i.e., if this property holds
for all top-level goals, we can infer that the requirements model is correct and
consistent. Pro2 states that the model should not include any goal delegation
chain, if there is no trust chain holds between the delegator and the delegatee,
since delegation with no trust leaves the delegator with no guarantee about the
achievement of its goal. Pro3 states that actors should have all information that
is required for the achievement of the goals they are responsible of.</p>
      <p>Pro4-6 are used to verify information permission related properties. For
instance, Pro4 states that actors should have all the permissions they require to
achieve their objectives. While Pro5 states that the model should not include
actors who delegate permissions that they do not have. Pro6 states that the
model should not include actors who have permissions, and there is no trust/
trust chain between such actors and information owner.</p>
      <p>Pro7-9 are used to verify IQ related properties, i.e., the model should not
include any information that does not ts for the purpose of use (e.g., produce,
read, and send) from the perspectives of their user (e.g., producer (Pro7), reader
(Pro8), and sender (Pro9)). Note that each of these properties covers several
sub-properties. Consider Pro8 for example, information ts for read if it is
accessible, accurate, complete, valid, and consistent.</p>
      <p>
        Pro10-11 are used to ensure that the model manage separation of duties
among its actors to avoid any con ict of interest that may leads to di erent
kinds of vulnerability, i.e., such properties allow to identify situations at the
instance level that might endanger the system performance. In particular, they
state that the model should not include any agent that plays con icting roles in
terms of producing and/or reading information. The Enron scandal [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ] is a
famous example of producing inaccurate (intentionally biased) information due to
playing con icting roles. De ning con icting roles in terms of producing/reading
information is not an easy task, and it is done with the help of domain experts.
      </p>
      <p>
        These properties allow for the automated analysis of the IQ requirements
model, i.e., the analysis relay on them to detect any design violation and notify
the designer about it. In other words, they enable for checking whether
stakeholders' IQ requirements are achieved or not, and identify the reason(s) preventing
their achievement (if any). In what follows, we list the main violations to the
properties of the design concerning the Flash Crash scenario that the automated
analysis was able to capture:
Inaccurate information: markets (e.g., CME ) consider information received
from any trader that plays the role of HFT trader as inaccurate, since no
trust in information production holds between them. In particular, HFTs
has the capability (trade large amount of securities in very fast rate) of
providing inaccurate information that is able to destabilize the trading
environment. According to [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ], there was 16 HFTs for the security that was
under suspicion of triggering the crash.
      </p>
      <p>Inaccurate information due to playing con icting roles: some
companies are playing two con icting roles \accounting rm" and \auditing rm"
concern producing \ nancial statement". Since we cannot trust a company
for producing accurate \ nancial statement" concerning the companies they
get paid from to perform their accounting services, such information is
considered as inaccurate.</p>
      <p>Unauthorized read due to playing con icting roles: some companies are
playing two con icting roles \auditing rm" and \consulting rm" concern
reading \security assessment", since they might use such information for
providing paid consulting services. Thus, such companies should not has read
permissions concerning \security assessment" information.</p>
      <p>Incomplete information: \ NYSE CB info" and \NASDAQ CB info" that are
used to stabilize the trading environment in NYSE and NASDAQ markets
respectively, are identi ed as incomplete information from the perspectives
of their readers, since they miss a sub part related to the purpose of use.
However, this can be solved by providing NYSE and NASDAQ markets with
the missed information sub items \CME CB info".</p>
      <p>
        Inconsistent information: CME CB info is provided to NASDAQ and NYSE
with two di erent provision times 13 ms and 14.65 ms respectively [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ],
which leads to two di erent read times between them, and in turn, results
in inconsistency since they are interdependent readers.
      </p>
      <p>Following Secure Tropos, our framework allows for a clear distinction between
organizational (e.g., roles) and instance (e.g., agents) levels, and most of these
properties apply to both of these levels. However, to avoid con icts between the
organizational and instance levels that is a main issue in Secure Tropos, we are
planning to model actors' interactions only at instance level.
6</p>
    </sec>
    <sec id="sec-6">
      <title>Methodological Process</title>
      <p>
        Our framework [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] is equipped with an engineering methodological process
(shown in Figure 3) that consists of seven steps, which should be followed by
designers during the system design; each of these steps is described as follows: (1)
Actors modeling : aims to model the actors (e.g., roles and agents) of the system
along with their objectives, entitlements and capabilities; (2) Goals modeling :
aims to re ne the actors' top-level goals, if needed, through and/ or
decomposition until reaching their leaf goals; (3) Information modeling : the di erent
relations between goals and information are identi ed and modeled along with
their IQ needs, and the structure of composed information are modeled as well.
4- Social interactions
modeling
5- Trust
modeling
1- Actor
modeling
2- Goal
modeling
3- Information
modeling
6-Analyzing
IQ model
7- Refining
      </p>
      <p>IQ model
Ex1- modeling
IQ softgoals</p>
      <p>Ex2- Approximating</p>
      <p>IQ softgoals into IQC
(4) Social interactions modeling : aims to identify and model the di erent
social dependencies among actors of the system concerning information provision,
goal and permission delegation. More speci cally, based on actors' capabilities
some goals might be delegated to other actors, who have the capabilities to
achieve them; and based on actors' needs, information/ permission is provided/
delegated to them; (5) Trust modeling : aims to model trust/ distrusts among
actors concerning information producing, goal and permission delegation; (6)
Analyzing IQ model : at this step the model is analyzed to verify whether all
the stakeholders' requirements are achieved or not; and (7) Re ning IQ model :
if some of the stockholders' requirements were not achieved during the model
analysis step, the analyst try to nd solutions for such issues at this step.</p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], we re ned some steps of the previously discussed methodology to
accommodate the proposed modeling extensions (surrounded by dashed lines
in Figure 3). For instance, step (4) Social interactions modeling is extended to
model permissions delegation among actors, while step (5) Trust modeling is
extended to model trust/ distrusts concerning the delegated permissions.
Moreover, we have added two more steps Ex1 and Ex2 to the methodological process,
where the rst aims to identify and model top-level IQ softgoals, and re ne them
until reaching their leaf IQ softgoals, while the last aims to approximate leaf IQ
softgoals into their corresponding IQC.
7
      </p>
    </sec>
    <sec id="sec-7">
      <title>Implementation and evaluation</title>
      <p>We evaluated the applicability and e ectiveness of our framework and its
extended version depending on simulation method (experimental), i.e., execute
artifact with arti cial data. To this end, we developed a prototype
implementation of our framework (ST-IQ Tool)3 to test it for modeling and reasoning about
IQ requirements. In what follows, we brie y describe our prototype, discuss its
applicability and e ectiveness over the Flash Crash scenario, and then test the
scalability of its reasoning support.</p>
      <p>Implementation: our prototype consist of 4 main parts (ST-IQ Tool
structure is shown in Figure 4): (1) Control component (JAVA based-program) that</p>
      <sec id="sec-7-1">
        <title>3 http://mohamadgharib.wordpress.com/</title>
        <p>controls and coordinates the three other components; (2) a graphical user
interface (GUI) developed using Sirius4, which enables the system designers for
drawing the IQ requirements model diagram by dragging-and-dropping
modeling elements from palettes, and allows for specifying the properties of these
elements along with their interrelations; (3) model-to-text transformation
mechanism that supports the translating of the graphical requirements models into
Disjunctive Datalog formal speci cations depending on Acceleo5; and nally (4)
automated reasoning support (DLV system6) that takes the Disjunctive Datalog
speci cation, which resulted from translating the graphical model along with
the reasoning axioms, and then veri es the correctness and completeness of the
requirements model against the properties of the design.</p>
        <p>Applicability and e ectiveness: we evaluated our framework and its
extended version by showing their applicability in capturing the IQ requirements
along with its e ectiveness in identifying any violation to the properties of the
design by applying it to the Flash Crash case study. In particular, we used our
modeling language to model the Flash Crash, and then we translated the
requirements diagram into Disjunctive Datalog formal language. Finally, we depend on
the automated reasoning support to check whether the requirements model is
correct and consistent, i.e., whether all the properties of the design hold. The
analysis captured all violations of the properties of the design that we consider
including inaccurate, incomplete, inconsistent information, etc.</p>
        <p>Experiments on scalability: to test the scalability of the automated
reasoning support, we investigated the reasoning execution time with respect to
the model size. In particular, we proposed a model and then expanded it by
increasing the number of its modeling elements through several steps. At each
step, we performed an analysis test and we calculated the execution time. The
result showed that the relation between the size of the model and the execution
time is linear (not exponential).
8</p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>Ongoing work</title>
      <p>We brie y discuss several ongoing works to improve our proposed framework.</p>
      <p>Social trust analysis: all RE approaches including ours mainly focus on
trust as social relations, without proposing any speci c modeling technique to
relate them with the internal requirements of the system's components. In other
words, existing approaches are able to model trust requirements, but o er no
analysis mechanisms to verify their consistency with the di erent actors'
competencies and motivations toward the trustum. We are currently working on
extending our framework by proposing the required concepts and constructs for
modeling and analyzing trust among actors of the systems based on sets of beliefs
related to the actors' competencies (can do) and motivations (will do), which can
be used to clearly identify \why" an actor can trust/ distrusts another one.</p>
      <sec id="sec-8-1">
        <title>4 https://projects.eclipse.org/projects/modeling.sirius 5 https://projects.eclipse.org/projects/modeling.m2t.acceleo 6 http://www.dlvsystem.com/dlv/</title>
        <p>
          Automated speci cation of IQ policies: organizations rely on di erent
kinds of policies to de ne the permitted/ forbidden actors' activities toward
information in order to deal with IQ related concerns. Yet most of the proposed
solutions focus on the technical aspects of the system, which make them
inadequate for socio-technical systems. Thus, we extended our framework to support
the automatic derivation of the nal IQ policies from the IQ requirements model
[
          <xref ref-type="bibr" rid="ref23">23</xref>
          ]. In particular, we proposed an IQ policy speci cation language that is able
to clearly represent the nal IQ speci cations in terms of permitted, forbidden
and obligated actors' activities toward information. In addition, we introduced
a set of rules that enables for the automatic derivation of such policies from the
requirements model. Currently, we are working on re ning the IQ policy speci
cation language to make it more expressive, and we aim to extend the derivations
rules to cover more IQ policies.
        </p>
        <p>
          Modeling and analyzing IQ requirements in Business Processes
(BP): driven by the needs of some system designers, who put more emphasis
on modeling BPs within the system rather than modeling the whole system, we
proposed an extension to our framework [
          <xref ref-type="bibr" rid="ref24">24</xref>
          ] that o ers mechanisms for
modeling and analyzing IQ requirements in BPs. In particular, we proposed a detailed
approach for capturing IQ requirements of the overall system where the BP is
executed, and then we introduced mechanisms for mapping these requirements into
work ow net with actors (WFA-net) that is a graphical language for modeling
and analyzing IQ requirements in BP.
9
        </p>
      </sec>
    </sec>
    <sec id="sec-9">
      <title>Conclusions</title>
      <p>In this paper, we summarized our experience in modeling and analyzing IQ
requirements for socio-technical systems. First, we argued that IQ is not only
a technical issue, but it is also an organizational and social issue. Thus, any
solution for IQ should consider the social and organizational context where the
system will operate. Moreover, we highlighted the importance of capturing IQ
requirements of the system from the early development phases.</p>
      <p>Second, we showed how IQ can be analyzed through its di erent
dimensions, and we proposed a multi-dimensional model for analyzing IQ from
sociotechnical perspective. Third, we justify our choice in considering Secure Tropos
as a baseline for our proposed framework, and we discussed its limitations for
modeling and reasoning about IQ requirements. In addition, we discussed the
required extensions of Secure Tropos for capturing IQ requirements, and then we
extended its conceptual model with the required concepts. In particular, our
proposed framework enables system designers to capture IQ requirements in terms
of its di erent dimensions, and it provide the required analysis techniques to
verify whether the IQ requirements are met or not. In addition, we discussed
our methodological process that supports designers during the di erent phases
of the system design.</p>
      <p>We illustrated the utility of our framework by applying it to a stock market
crash case study. More speci cally, we evaluated our framework by showing its
ability in modeling and analyzing IQ requirements along with its e ectiveness in
detecting any violations to the properties of the design. Moreover, we evaluated
the scalability of its reasoning techniques by calculating the relation between the
model sizes and the reasoning execution time, and the result proves that such
relation is linear (not exponential). Finally, we discussed our ongoing research
related to IQ requirements.</p>
    </sec>
    <sec id="sec-10">
      <title>Acknowledgment References</title>
      <p>This research was partially supported by the ERC advanced grant 267856,
\Lucretius: Foundations for Software Evolution", http://www.lucretius.eu/.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Emery</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Trist</surname>
          </string-name>
          , E.:
          <article-title>Socio-technical systems</article-title>
          .
          <source>management sciences, models and techniques. churchman cw et al</source>
          (
          <year>1960</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2. Fisher,
          <string-name>
            <given-names>C.</given-names>
            ,
            <surname>Kingma</surname>
          </string-name>
          ,
          <string-name>
            <surname>B.</surname>
          </string-name>
          :
          <article-title>Criticality of data quality as exempli ed in two disasters</article-title>
          .
          <source>Information &amp; Management</source>
          <volume>39</volume>
          (
          <issue>2</issue>
          ) (
          <year>2001</year>
          )
          <volume>109</volume>
          {
          <fpage>116</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Sommerville</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cli</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Calinescu</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Keen</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kelly</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kwiatkowska</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mcdermid</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Paige</surname>
          </string-name>
          , R.:
          <article-title>Large-scale complex it systems</article-title>
          .
          <source>Communications of the ACM</source>
          <volume>55</volume>
          (
          <issue>7</issue>
          ) (
          <year>2012</year>
          )
          <volume>71</volume>
          {
          <fpage>77</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Mouratidis</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Giorgini</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Secure tropos: A security-oriented extension of the tropos methodology</article-title>
          .
          <source>International Journal of Software Engineering and Knowledge Engineering</source>
          <volume>17</volume>
          (
          <issue>2</issue>
          ) (
          <year>2007</year>
          )
          <volume>285</volume>
          {
          <fpage>309</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Securities</surname>
          </string-name>
          ,
          <string-name>
            <surname>Commission</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          , et al.:
          <article-title>Findings regarding the market events of may 6, 2010</article-title>
          .
          <article-title>Report of the Sta s of the CFTC and SEC to the Joint Advisory Committee on Emerging Regulatory Issues (</article-title>
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Kirilenko</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kyle</surname>
            ,
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Samadi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tuzun</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>The ash crash: The impact of high frequency trading on an electronic market</article-title>
          . Manuscript, U of Maryland (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Pipino</surname>
            ,
            <given-names>L.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>Y.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>R.Y.</given-names>
          </string-name>
          :
          <article-title>Data quality assessment</article-title>
          .
          <source>Communications of the ACM</source>
          <volume>45</volume>
          (
          <issue>4</issue>
          ) (
          <year>2002</year>
          )
          <volume>211</volume>
          {
          <fpage>218</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Bovee</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Srivastava</surname>
            ,
            <given-names>R.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mak</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>A conceptual framework and belief-function approach to assessing overall information quality</article-title>
          .
          <source>International journal of intelligent systems 18(1)</source>
          (
          <year>2003</year>
          )
          <volume>51</volume>
          {
          <fpage>74</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>R.Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reddy</surname>
            ,
            <given-names>M.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kon</surname>
          </string-name>
          , H.B.:
          <article-title>Toward quality data: An attribute-based approach</article-title>
          .
          <source>Decision Support Systems</source>
          <volume>13</volume>
          (
          <issue>3</issue>
          ) (
          <year>1995</year>
          )
          <volume>349</volume>
          {
          <fpage>372</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chi</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Evolutional data quality: A theory-speci c view</article-title>
          .
          <source>In: IQ</source>
          . (
          <year>2002</year>
          )
          <volume>292</volume>
          {
          <fpage>304</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Gharib</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Giorgini</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Modeling and reasoning about information quality requirements</article-title>
          . In: Requirements Engineering:
          <article-title>Foundation for Software Quality -</article-title>
          21st
          <source>International Working Conference, REFSQ</source>
          <year>2015</year>
          , Essen, Germany, March 23-26,
          <year>2015</year>
          . Proceedings. (
          <year>2015</year>
          )
          <volume>49</volume>
          {
          <fpage>64</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Gharib</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Giorgini</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Dealing with information quality requirements</article-title>
          .
          <source>In: Enterprise, Business-Process and Information Systems Modeling (EMMSADS15)</source>
          , to appear. Springer (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Dai</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lin</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bertino</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kantarcioglu</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>An approach to evaluate data trustworthiness based on data provenance</article-title>
          .
          <source>In: Secure Data Management</source>
          . Springer (
          <year>2008</year>
          )
          <volume>82</volume>
          {
          <fpage>98</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Strong</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Beyond accuracy: What data quality means to data consumers</article-title>
          .
          <source>Journal of management information systems</source>
          (
          <year>1996</year>
          )
          <volume>5</volume>
          {
          <fpage>33</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Ballou</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pazer</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tayi</surname>
            ,
            <given-names>G.K.</given-names>
          </string-name>
          :
          <article-title>Modeling information manufacturing systems to determine information product quality</article-title>
          .
          <source>Management Science</source>
          <volume>44</volume>
          (
          <issue>4</issue>
          ) (
          <year>1998</year>
          )
          <volume>462</volume>
          {
          <fpage>484</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Jureta</surname>
            ,
            <given-names>I.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mylopoulos</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Faulkner</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Revisiting the core ontology and problem in requirements engineering</article-title>
          . In: International Requirements Engineering,
          <year>2008</year>
          . RE'
          <volume>08</volume>
          .
          <string-name>
            <surname>16th</surname>
            <given-names>IEEE</given-names>
          </string-name>
          , IEEE (
          <year>2008</year>
          )
          <volume>71</volume>
          {
          <fpage>80</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Glinz</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Rethinking the notion of non-functional requirements</article-title>
          .
          <source>In: Proc. Third World Congress for Software Quality. Volume</source>
          <volume>2</volume>
          . (
          <year>2005</year>
          )
          <volume>55</volume>
          {
          <fpage>64</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Masolo</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Borgo</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gangemi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Guarino</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Oltramari</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schneider</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Dolce: a descriptive ontology for linguistic and cognitive engineering</article-title>
          .
          <source>WonderWeb Project, Deliverable D17 v2 1</source>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Bihlmeyer</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Faber</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ielpa</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lio</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pfeifer</surname>
          </string-name>
          , G.:
          <article-title>Dlv-user manual</article-title>
          .
          <source>The DLV Project</source>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Petrick</surname>
            ,
            <given-names>J.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Scherer</surname>
            ,
            <given-names>R.F.</given-names>
          </string-name>
          :
          <article-title>The enron scandal and the neglect of management integrity capacity</article-title>
          .
          <source>American Journal of Business</source>
          <volume>18</volume>
          (
          <issue>1</issue>
          ) (
          <year>2003</year>
          )
          <volume>37</volume>
          {
          <fpage>50</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Paddrik</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hayes</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Todd</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yang</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Beling</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Scherer</surname>
            ,
            <given-names>W.:</given-names>
          </string-name>
          <article-title>An agent based model of the e-mini s&amp;p 500 applied to ash crash analysis</article-title>
          .
          <source>In: Computational Intelligence for Financial Engineering &amp; Economics (CIFEr)</source>
          ,
          <source>2012 IEEE Conference on, IEEE</source>
          (
          <year>2012</year>
          ) 1{
          <fpage>8</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Lewis</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Flash boys: a Wall Street revolt</article-title>
          .
          <source>WW Norton &amp; Company</source>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Gharib</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Giorgini</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>A goal-based approach for automated speci cation of information quality policies</article-title>
          .
          <source>In: Research Challenges in Information Science (RCIS)</source>
          ,
          <source>2015 IEEE Ninth International Conference</source>
          , to appear, IEEE (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Gharib</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Giorgini</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Modeling and reasoning about information quality requirements in business processes</article-title>
          .
          <source>In: Enterprise, Business-Process and Information Systems Modeling (BPMDSS15 )</source>
          , to appear. Springer (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>