<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>A Life Cycle for Authorization Systems Development in the GDPR Perspective</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Said Daoudagh</string-name>
          <email>said.daoudagh@di.unipi.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Eda Marchetti</string-name>
          <email>eda.marchettig@isti.cnr.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>ISTI-CNR</institution>
          ,
          <addr-line>Pisa</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Pisa</institution>
          ,
          <addr-line>Pisa</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The General Data Protection Regulation (GDPR) de nes the principle of Integrity and Con dentiality, and implicitly calls for the adoption of authorization systems for regulating the access to personal data. We present here a process development life cycle for the speci cation, deployment and testing of authorization systems. The life cycle targets legal aspects, such as the data usage purpose, the user consent and the data retention period. We also present its preliminary architecture where available solutions for extracting, implementing and testing the data protection regulation are integrated. The objective is to propose for the rst time a unique improved solution for addressing di erent aspects of the GDPR development and enforcement along all the life cycle phases.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        compliant solutions [
        <xref ref-type="bibr" rid="ref29 ref30 ref7">7, 29, 30</xref>
        ]. However, to the best of our knowledge, most of the available
proposals targets just a single aspect of authorization system development and no integrated
solutions for guiding their GDPR-by-design compliant development through the entire life cycle
are provided.
      </p>
      <p>
        Therefore, the proposal of this paper: a speci c, integrated GDPR focused process
development life cycle for the speci cation, deployment and testing of adequate ne-grained
authorization mechanisms able to take into account legal requirements. The idea has been inspired by
the life cycle introduced in [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], which is a systematic approach to implementing authorization
systems within enterprise. Even if generic, the proposal of [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] does not target explicitly the
GDPR demands or any other legal framework.
      </p>
      <p>Additionally, to promote the applicability of the proposed life cycle into the business and
industrial context we also present its preliminary automation. More precisely, we integrated,
for the rst time, into a unique environment some of the available solutions for: specifying
the privacy requirements, controlling personal data, processing them, and demonstrating the
compliance with the GDPR in collecting, using, storing, disclosing and/or disposing of the
personal data.</p>
      <p>In line with this view, the paper focuses on the following primary objectives: OBJ 1:
de ning a GDPR-based life cycle for authorization systems; OBJ 2: providing an integrated
environment for automatically enforcing the data protection or privacy regulations.
Outline. Section 2 presents the basic concepts used along the proposal; Section 3 describes
the adopted development process and the solutions proposed for its phases; Section 4 presents
the unique environment we are developing to accommodate the proposed life cycle; nally,
Section 5 concludes the paper.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Background and Related Work</title>
      <p>In this section we brie y overview the concepts and de nitions adopted in the remains of this
paper, focusing in particular on the GDPR and access control concepts.</p>
      <p>
        General Data Protection Regulation. The GDPR [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] de nes Personal Data as any
information relating to an identi ed or identi able natural person called Data Subject. That
means that, a data subject is a Natural Person (a living human being), whose data are managed
by a Controller. This regulation became into e ect on May 2018 and has replaced the previous
Data Protection Directive conceived in 1995. The aim of the new regulation is to strengthen
the rights of the individual over their own data and at the same time to make organizations
more accountable w.r.t. the previous directive. In addition, the GDPR has also the objective to
eliminate all the barriers for the services to be delivered in the European Union and, therefore,
to enhance business opportunities within the Digital Single Market. The GDPR will contribute
to the harmonization of the previous fragmented data protection laws across the EU, so as to
ensure equal protection of Human Rights of the European Citizens.
      </p>
      <p>The GDPR is composed of 99 articles that represent the mandatory part of the regulation.
The GDPR is applied to the processing of personal data, whether it is automated (even partially)
or not. It de nes, among others, the following principles and demands: Transparency, i.e., data
must be processed fairly, lawfully and transparently; Purposes, i.e., data should only be collected
for determined, explicit and legitimate purposes, and should not be processed later for other
purposes; Minimization, i.e., the processed data must be relevant, adequate and limited to what
is necessary in view of the purposes for which they are processed; Accuracy, i.e., the processed
data must be accurate and up-to-date regularly; Retention, i.e., data must be deleted after a
limited period; Subject explicit consent, i.e., data may be collected and processed only if the
data subject has given his explicit consent.</p>
      <p>
        Access Control Concepts. Access Control (AC) is a fundamental building block for secure
information sharing [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], because it ensures that only the intended people can access
securityclassi ed data and that these intended users are only given the level of access required to
accomplish their tasks. Several access control models have been proposed, including models
taking into account time, location, and situation [
        <xref ref-type="bibr" rid="ref18 ref25 ref32 ref8">8, 18, 25, 32</xref>
        ] and models speci c for
privacysensitive data [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ].
      </p>
      <p>An AC is usually implemented through Access Control Mechanism (ACM), which is the
system that provides a decision to an authorization request, typically based on prede ned
Access Control Policy (ACP). This is a speci c statement of what is and is not allowed on
the basis of a set of rules, de ned in terms of conditions on attributes of subjects, resources,
actions, and environment, and combining algorithms for establish the precedence among the
rules.</p>
      <p>
        Attribute-Based Access Control (ABAC) [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ] and its standard implementation, the
eXtensible Access Control Markup Language (XACML) [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ], are the widespread adopted
models in the access control environment. As schematize in Figure 1(a), the main components of
XACML standard are: the Policy Administration Point (PAP) is the system entity in charge of
managing the policies; the Policy Enforcement Point (PEP), usually embedded into an
application system, receives the access request in its native format, constructs an XACML request
and sends it to the Policy Decision Point (PDP); the Policy Information Point (PIP) provides
the PDP with the values of subject, resource, action and environment attributes; the PDP
evaluates the policy against the request and returns the response, including the authorization
decision, to the PEP.
      </p>
      <p>The structure of an XACML access control policy is sketched in Figure 1(b). More precisely,
an XACML policy has a tree structure whose main elements are: PolicySet (not presented in
the gure), Policy, Rule, Target and Condition. The PolicySet includes one or more policies.
A Policy contains a Target and one or more rules. The Target speci es a set of constraints on
attributes of a given request. Typical categories of attributes are Subject, Resource, Action and
Environment. The Rule speci es a Target and a Condition containing one or more boolean
functions. If the Condition evaluates to true, then the Rule's E ect (a value of Permit or
Deny ) is returned, otherwise a NotApplicable decision is formulated. If an error occurs during
the evaluation of a policy against a request, Indeterminate value is returned. The
PolicyCombiningAlgorithm (not represented in the gure) and the RuleCombiningAlgorithm de ne
how to combine the results from multiple policies and rules respectively in order to derive a
single authorization access decision.</p>
      <p>
        Related Work. In literature there are several works that use access control as main means
of protecting personal data. Di erent proposals are mainly divided into two main categories.
The former uses Access Control to address speci c concepts that can be related to a given law,
such as consent and purpose. In this area an initial proposal for an automatically enforceable
policy language is discussed in [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], whereas, a formal de nition of the consent is introduced
in [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ]. The latter refers explicitly a given law (e.g., the EU GDPR or the US HIPAA) in
using Access Control. In particular in [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] the authors have evaluated whether the XACML
standard is adequate to express the constraints imposed in HIPAA, whereas in [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ], the authors
investigated the feasibility of translating the articles related to access control of the previous EU
data protection directive. In the industrial environment, authors in [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] proposed a systematic
methodology for the implementation of ABAC solutions in real contexts.
      </p>
      <p>Di erently from the above contributions, the proposal of this paper does not focus on a
single aspect of the development process but provides a uni ed environment able to: model
ACPs that are by-design compliant with the GDPR; test those ACPs by means of
state-of-theart testing tools; and to monitors their application during the production time, and eventually
to suggest possible improvements in case of deviation of the expected behaviour. Therefore, the
solution proposed in this paper aims at providing, for the rst time, a practical speci cation of
the Authorization Development Life Cycle in the light of the GDPR covering all its stages.
3</p>
    </sec>
    <sec id="sec-3">
      <title>Authorization Policy Life Cycle</title>
      <p>In this section we target the rst objective of this paper (OBJ 1): de ning a GDPR-based life
cycle for authorization systems assuring the by-design compliance to data protection regulation.
As any other software application, the development of GDPR compliant authorization systems
involves di erent stages of software development. Thus, our rst objective is to formalize into
a speci c life cycle the required activities for: collecting and specifying legal requirements into
formal representations, de ning and testing data protection policies, and implementing
ACbased mechanisms.</p>
      <p>
        In presenting our proposal, among the di erent development processes, we refer to and
modify the authorization policy life cycle introduced in [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], which is a systematic approach
to implementing ABAC systems within enterprises. The proposed life cycle, schematized in
Figure 2, does not strictly depend on any speci c ABAC implementation. However, in this
paper we refer to the widely industrial adopted XACML-based authorization system because
it is the only available standardized speci cation for ABAC. As schematize in Figure 2, the
modi ed version of the process consists of the following steps:
      </p>
      <p>GDPR-based use case de nition (step 1 ): i.e., de ne context and an achievable scope
so as to establish a common base to discuss with di erent stakeholders. In this case, the
established use cases need to be conceived according to GDPR implementation challenges;
Gather authorization requirements (step 2 ): i.e., to gather all the requirements and
the sources they come from. In our case, the primary source is the GDPR regulation,
therefore, authorization requirements should de de ned in terms of statements or natural language
authorization policies. Additionally, business requirements (e.g., working hours) and security
best practices (e.g., encrypting data) need also to be de ned.</p>
      <p>Identify required attributes (step 3 ): i.e., to identify the attributes used in the selected
requirements and their origin so as to make easier requirement reviews. The attributes should
depend on the language or functionalities of the XACML reference architecture.
Author authorization policies (step 4 ): i.e., to transform the natural language
statements into machine-interpretable statements, in order to eliminate any ambiguity introduced
by natural language. Thus, a list of XACML policies encoding the GDPR's provisions need to
be de ned as well as the order in which those policies should be evaluated.</p>
      <p>Test ACPs &amp; AC mechanisms (step 5 ): i.e., to ensure that the implemented XACML
policies meet the GDPR requirements. State-of-the-art and speci cally conceived testing
techniques should be used according to the di erent purposes. This step involves also the evaluation
of the adequacy of the current AC mechanisms in the context of the GDPR.
Deploy the architecture (step 6 ): i.e., to de ne the contact point within the existing
systems in order to make the di erent applications able to interact with authorization system.
Deploy the policies (step 7 ): i.e., to deploying the authored XACML policies according
to the selected (production) environment. This step is usually business dependent.
Run access reviews (step 8 ): i.e., to analyse the policies against a set of attributes to
determine what these attributes grant. In the context of the GDPR, this should involve the
simulation of realistic scenarios according to speci c application use cases. Additionally, the
data coming from the testing activities could be used to assess the implemented solutions and
identify possible improvements.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Life Cycle Automation</title>
      <p>In order to propose an applicable and e ective solution, the second objective of this paper (OBJ
2) is to provide an integrated environment for the automatic enforcing of the GDPR-based life
cycle presented in the previous section. To the best of the authors' knowledge, this proposal is
the rst attempt to integrate, in a unique automated environment, di erent available solutions
for extracting, implementing and testing the data protection regulation.</p>
      <p>Our proposal is depicted in Figure 3, and it is composed of three main modules:
(1) GDPR-Based Access Control Policies Management (module A ); (2) Access Control System
(module B ); and (3) GDPR Analytics (module C ).</p>
      <p>Di erently from the generic ACS architecture, in this paper we assume that the protected
resources are Personal Data hosted in a speci c database, the Personal Data DB component
of Figure 3.</p>
      <p>In the remainder of this section, we detail how the modules have been implemented into the
proposed environment and how they are related to the authorization life cycle schematized in
Figure 2.
4.1</p>
      <sec id="sec-4-1">
        <title>Use case de nition and Gathering of authorization requirements</title>
        <p>
          Among the solutions to tackle security issues and vulnerabilities in an e cient and e ective
way, the possibility of using backlogs to drive the software development work is currently taking
place. Generally, a backlog is a prioritized features list describing the functionalities to be
included in the nal product [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ]. These backlog items are often provided in the form of User
Stories [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ], i.e., a list of ready-made speci cation of items (requirements and task descriptions)
useful for the implementation.
        </p>
        <p>In the context of GDPR having a ready-to-use set of User Stories, focused on GDPR
provisions and associated to speci c ACPs, represents an important means to minimize development
e ort and assure high quality of the nal product. Indeed, when an authorization system need
to be implemented, developers could pick up the necessary prede ned User Stories, and their
associated ACPs, and exploit them in order to easily implement the required policies into the
Access Control Mechanism.</p>
        <p>Considering the life cycle schematized in Figure 2, the de nition of the User Stories set can
be reloaded as: the de nition of a Data Protection Backlog that contains User Stories based
on the GDPR requirements (Step 1 ); and the mapping of the GDPR provisions into User
Stories (Step 2 ).</p>
        <p>
          In the environment proposed in Figure 3, the de nition of User Stories is in charge of the
module A , and speci cally of the User Stories Tool component. From a practical point of
view, the methodology for de ning GDPR based User Stories has been introduced in [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ], and
therefore the component provides an automation of the previously introduced process. More
precisely, the User Stories tool component takes as input a Legal Text (the GDPR text in
this case), analyses the GDPR's articles related to ACs and creates an Epic [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ] for each of them.
An Epic is a set of User Stories having the same conceptual purpose. For the GDPR, a total
of forty-one Epics are produced: three of them concerning only AC mechanism; eight referring
only ACP, and thirty articles related to both ACP and AC mechanism. Then, for each article
one or more User Stories are derived and linked to the proper Epic. As an output of the User
Stories Tool component, a Data Protection Backlog, i.e., a Privacy Backlog containing a set
of User Stories organized in Epics, is stored into the USER Stories DB (Figure 3). In Table 1
an extract of content of the Data Protection Backlog is presented. As in the table the column
Article ( rst column) contains the GDPR's articles, and the column User Story contains the
GDPR-based User Stories de ned.
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>Identify required attributes and Author authorization policies</title>
        <p>Step 3 and Step 4 of the life cycle of Figure 2 aim at transforming the User Stories into
machine-interpretable statements. As a result, a list of XACML policies encoding the GDPR
principles is de ned.</p>
        <p>
          In the environment depicted in Figure 3, the Access Control Tool component of module
A is in charge of automating the two steps. Hence, the component takes as input a set of
User Stories selected by the User from the User Stories DB and, through the automation of
the methodology introduced in [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ], provides the associate GDPR-based ACPs.
        </p>
        <p>In details, considering the Step 3 , rst the component classi es the identi ed attributes
into access control commonly-used entities (or categories) (see Section 2), highlights relations
between them and lets the mapping into the ABAC terms. For instance, by referring to the
User Story related to the Art. 15.1 (see the second row of Table 1), the component identi es
and classi es the following attributes: Data Subject as a Subject, access as an Action, and
Personal Data as a Resource category.</p>
        <p>Then, the Access Control Tool component automates the translation of the selected User
Stories into derived AC rules that corresponds to Step 4 of Figure 2. In particular, this step
consist into the instantiation of the AC rules with actual attributes, and the translation of the
resulting policies into a given formalism or language 1.</p>
        <p>As in Figure 3, the nal translation requires the interaction with the User and the Personal
Data DB. Speci cally, the User needs to identify in the Personal Data DB the real attributes
to be considered. As example, considering the Art. 15.1 (Table 1), Table 2 reports the attribute
mapping for the following realistic scenario: Alice (Customer, i.e., Data Subject) provided her
name, her E-mail address, and the name of the city where she has the permanent address to
the ABC company (Controller). Alice in any moment can exercise her right of access pursuant
the Art. 15.1.</p>
        <p>More precisely, column Identi ed Attribute of Table 2 contains the identi ed attributes;
column Attribute Category shows the classi cation of those attributes into a speci c category;
nally, column Access Control Category illustrates the classi cation attributes into the
commonly used entities in access control.</p>
      </sec>
      <sec id="sec-4-3">
        <title>Test ACPs &amp; AC mechanisms</title>
        <p>Step 5 of Figure 2 aims at testing both the developed ACPs and the current AC mechanisms.
Indeed, to ensure that the implemented XACML policies meet the GDPR requirements
speci c testing process should be adopted. Considering the environment of Figure 3, the Access
Control Testing Tools component of module A is in charge of implementing the Step 5 .</p>
        <p>
          1In the current implementation the XACML standard [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ] is considered but other implementation of ABAC
model can be equally adopted.
        </p>
        <p>
          In particular, it integrates available solutions for: assessment of test strategies, testing
GDPRbased ACPs expressed in XACML 3.0 and evaluating the adequacy of AC mechanisms with
respect to the GDPR's provisions. For aim of completeness we report here below the main
features of the Access Control Testing Tools component. Speci cally:
1. Test Case Generation: starting from the developed ACPs, it is possible to generate AC
requests able to test both the ACPs and AC mechanisms through a modi ed version of
the X-CREATE tool [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ], which provides several combinatorial test strategies, and the
XACMET tool [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ] that provides a model-based test generation strategy;
2. Mutation Generation: mutation analysis [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ] can be applied on ACPs for measuring the
adequacy of a test suite through an enhanced version of XACMUT tool [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ];
3. Test Cases Execution &amp; Result Analyzer : is an automated executor of test cases able to
collect the execution results and calculates either the e ectiveness of the considered test
suites, or the vulnerabilities detected;
4. Testing Strategy Enhancement : it suggests possible hints for enhancing the applied test
suite;
5. Oracle Derivation: is an automatic oracle able to associate the expected result for a
given AC request based on a given ACP through an enhanced version of the XACMET
tool [
          <xref ref-type="bibr" rid="ref11 ref19">11, 19</xref>
          ], which is an automated model-based oracle.
        </p>
        <p>The Tester can interact with the Access Control Testing Tools component for realizing
speci c testing purposes. For instance, for testing GDPR-based ACPs expressed in XACML
3.0 the user can run the following facilities: rst, the Test Case Generation for deriving the
set of AC requests (in this case a test strategy can be selected from available ones); then,
through Test Cases Execution &amp; Result Analyzer, the Tester can execute the test cases on the
GDPR-based ACPs and collect the results; whereas, through the Oracle Derivation component
the tester can associate the expected result to each of the executed test cases; nally, the
Testing Strategy Enhancement component can be used to visualize the results and suggestions
for possible improvement of the test case generation strategy.
In this section we brie y provide some hints for targeting the last three phases of the proposed
authorization life cycle that involve the deployment of the AC architecture (Step 6 of Figure 2),
the deployment of the developed and tested policies (Step 7 ), and the nal analysis of the
process development data (Step 8 ).</p>
        <p>The idea behind Step 6 is to decouple the authorization functionalities from the business
logic. This enables to adapt and extend the XACML reference architecture with new features
without modifying the business logic of the applications that use Personal Data. This separation
of concerns helps to propose scalable, manageable and extendible authorization solutions.</p>
        <p>Once the architecture is deployed (module B of Figure 3), Step 7 involves the deployment
of the tested GDPR-based ACPs within the Policy Administration Point component of the
AC system in order to assure the GDPR compliance. This allows the Policy Decision Point
to retrieve and to evaluate the right ACP when the system receives an access request, from the
end user (e.g., Data Subject or Controller), to the Personal Data hosted in the Personal Data
DB.</p>
        <p>
          Additionally, by referring to Step 8 , facilities for collecting and managing information for
the GDPR compliance and audit purposes [
          <xref ref-type="bibr" rid="ref15 ref4">4, 15</xref>
          ] should be included. To this purpose, module
C of Figure 3 is the proposal that we are currently nalizing. The module extends with logging
systems, monitoring capabilities, and reporting functionalities of the proposed environment [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ],
so that data mining and machine learning techniques can be adopted to construct behavioral
models based on data coming from the logging and testing activities and to discover and notify
unwanted behaviors.
5
        </p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Conclusions</title>
      <p>The GDPR represents a signi cant breakthrough in the digital economy and brings a lot of
changes to the way in which online services are o ered. This scenario calls for new approaches
for developing systems where legal requirements are taken into account, just like the other
requirements that a system must respond to. This paper focused on data protection requirements
and, in particular, on the development of authorization systems able to enforcing the GDPR
provisions. The idea was to provide for the rst time a speci c GDPR-based life cycle, able
to assure the by-design compliance of the developed access control systems. Additionally, in
order to make the proposal e ective and applicable in real context, we provide also a reference
architecture enforcing the proposed life cycle. The general nature of the proposed GDPR-based
life cycle does not constrain the environment to the speci c tools selected in this paper, and
di erent components implementations could be considered. The intention was to demonstrate
the feasibility of our proposal. Therefore, this work represented a preliminary step to integrate
legal requirements into a software development process and several improvements are
possible. In particular, the proposals of this paper need to be thoroughly extended and validated
with real case studies and the architecture nalized in order to provide a unique user-friendly
environment, able to assist developers in all the stages of development.
6</p>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgments</title>
      <p>This work is partially supported by CyberSec4Europe Grant agreement ID: 830929.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Amir</given-names>
            <surname>Shayan</surname>
          </string-name>
          <string-name>
            <surname>Ahmadian</surname>
          </string-name>
          , Daniel Struber, Volker Riediger, and
          <article-title>Jan Jurjens. Supporting privacy impact assessment by model-based privacy analysis</article-title>
          .
          <source>In Proceedings of the The 33rd ACM/SIGAPP Symposium On Applied Computing (SAC)</source>
          . ACM,
          <year>April 2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>J</given-names>
            <surname>Ahola</surname>
          </string-name>
          , C Fruhwirth,
          <string-name>
            <given-names>M</given-names>
            <surname>Helenius</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L</given-names>
            <surname>Kutvonen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J</given-names>
            <surname>Myllylahti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T</given-names>
            <surname>Nyberg</surname>
          </string-name>
          ,
          <article-title>A Pietikainen, P Pietikainen</article-title>
          , J Roning,
          <string-name>
            <given-names>S</given-names>
            <surname>Ruohomaa</surname>
          </string-name>
          , et al.
          <article-title>Handbook of the secure agile software development life cycle</article-title>
          . University of Oulu,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Vishal</given-names>
            <surname>Asthana</surname>
          </string-name>
          , Izar Tarandach,
          <string-name>
            <surname>Niall</surname>
            <given-names>ODonoghue</given-names>
          </string-name>
          , Bryan Sullivan, and
          <string-name>
            <given-names>Mikko</given-names>
            <surname>Saario</surname>
          </string-name>
          .
          <article-title>Practical security stories and security tasks for agile development environments</article-title>
          . Online, July,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Cesare</given-names>
            <surname>Bartolini</surname>
          </string-name>
          , Antonello Calabro, and
          <article-title>Eda Marchetti. GDPR and business processes: an e ective solution</article-title>
          .
          <source>In Proceedings of the 2nd International Conference on Applications of Intelligent Systems, APPIS</source>
          <year>2019</year>
          , Las Palmas de Gran Canaria, Spain, January
          <volume>07</volume>
          -
          <issue>09</issue>
          ,
          <year>2019</year>
          , pages
          <issue>7:1</issue>
          {
          <issue>7</issue>
          :
          <issue>5</issue>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Cesare</given-names>
            <surname>Bartolini</surname>
          </string-name>
          , Said Daoudagh, Gabriele Lenzini, and
          <string-name>
            <given-names>Eda</given-names>
            <surname>Marchetti</surname>
          </string-name>
          .
          <article-title>GDPR-based user stories in the access control perspective</article-title>
          .
          <source>In Mario Piattini, Paulo Rupino da Cunha</source>
          , Ignacio Garc a Rodr guez de Guzman, and
          <string-name>
            <surname>Ricardo</surname>
          </string-name>
          Perez-Castillo, editors,
          <source>Quality of Information and Communications Technology</source>
          , pages
          <volume>3</volume>
          {
          <fpage>17</fpage>
          ,
          <string-name>
            <surname>Cham</surname>
          </string-name>
          ,
          <year>2019</year>
          . Springer International Publishing.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Cesare</given-names>
            <surname>Bartolini</surname>
          </string-name>
          .,
          <string-name>
            <surname>Said</surname>
            <given-names>Daoudagh</given-names>
          </string-name>
          , Gabriele Lenzini., and
          <string-name>
            <given-names>Eda</given-names>
            <surname>Marchetti</surname>
          </string-name>
          .
          <article-title>Towards a lawful authorized access: A preliminary gdpr-based authorized access</article-title>
          .
          <source>In Proceedings of the 14th International Conference on Software Technologies - Volume</source>
          <volume>1</volume>
          : ICSOFT,, pages
          <fpage>331</fpage>
          {
          <fpage>338</fpage>
          . INSTICC, SciTePress,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>David</given-names>
            <surname>Basin</surname>
          </string-name>
          , S ren Debois, and Thomas Hildebrandt.
          <article-title>On purpose and by necessity</article-title>
          .
          <source>In Proceedings of the Twenty-Second International Conference on Financial Cryptography and Data Security (FC)</source>
          ,
          <year>February 2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Elisa</given-names>
            <surname>Bertino</surname>
          </string-name>
          , Piero A.
          <string-name>
            <surname>Bonatti</surname>
            , and
            <given-names>Elena</given-names>
          </string-name>
          <string-name>
            <surname>Ferrari</surname>
          </string-name>
          . TRBAC:
          <article-title>A temporal role-based access control model</article-title>
          .
          <source>ACM Trans. Inf. Syst. Secur.</source>
          ,
          <volume>4</volume>
          (
          <issue>3</issue>
          ):
          <volume>191</volume>
          {
          <fpage>233</fpage>
          ,
          <year>2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Elisa</given-names>
            <surname>Bertino</surname>
          </string-name>
          , Gabriel Ghinita, and
          <string-name>
            <given-names>Ashish</given-names>
            <surname>Kamra</surname>
          </string-name>
          .
          <article-title>Access control for databases: Concepts and systems</article-title>
          . Foundations and Trends R in Databases,
          <volume>3</volume>
          (
          <issue>1</issue>
          {2):1{
          <fpage>148</fpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bertolino</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Daoudagh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Lonetti</surname>
          </string-name>
          , and
          <string-name>
            <given-names>E.</given-names>
            <surname>Marchetti</surname>
          </string-name>
          .
          <source>Xacmut: Xacml</source>
          <volume>2</volume>
          .
          <article-title>0 mutants generator</article-title>
          .
          <source>In Proc. of 8th International Workshop on Mutation Analysis</source>
          , pages
          <volume>28</volume>
          {
          <fpage>33</fpage>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Antonia</surname>
            <given-names>Bertolino</given-names>
          </string-name>
          , Said Daoudagh, Francesca Lonetti, and
          <string-name>
            <given-names>Eda</given-names>
            <surname>Marchetti</surname>
          </string-name>
          .
          <article-title>An automated modelbased test oracle for access control systems</article-title>
          .
          <source>In Proceedings of the 13th International Workshop on Automation of Software Test, AST '18</source>
          , pages
          <issue>2</issue>
          {
          <fpage>8</fpage>
          , New York, NY, USA,
          <year>2018</year>
          . ACM.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Antonia</surname>
            <given-names>Bertolino</given-names>
          </string-name>
          , Said Daoudagh, Francesca Lonetti, Eda Marchetti, and
          <string-name>
            <given-names>Louis</given-names>
            <surname>Schilders</surname>
          </string-name>
          .
          <article-title>Automated testing of extensible access control markup language-based access control systems</article-title>
          .
          <source>IET Software</source>
          ,
          <volume>7</volume>
          (
          <issue>4</issue>
          ):
          <volume>203</volume>
          {
          <fpage>212</fpage>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Felix</surname>
            <given-names>Bieker</given-names>
          </string-name>
          , Nicholas Martin,
          <string-name>
            <given-names>Michael</given-names>
            <surname>Friedewald</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Marit</given-names>
            <surname>Hansen</surname>
          </string-name>
          .
          <article-title>Data protection impact assessment</article-title>
          . In Marit Hansen, Eleni Kosta, Igor Nai-Fovino, and
          <string-name>
            <surname>Simone</surname>
          </string-name>
          Fischer-Hubner, editors,
          <source>Privacy and Identity Management</source>
          , volume
          <volume>526</volume>
          <source>of IFIP Advances in Information and Communication Technology</source>
          , pages
          <volume>207</volume>
          {
          <fpage>220</fpage>
          . Springer,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>David</given-names>
            <surname>Brossard</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Gerry</given-names>
            <surname>Gebel</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Mark</given-names>
            <surname>Berg</surname>
          </string-name>
          .
          <article-title>A systematic approach to implementing abac</article-title>
          .
          <source>In Proceedings of the 2Nd ACM Workshop on Attribute-Based Access Control</source>
          ,
          <source>ABAC '17</source>
          , pages
          <fpage>53</fpage>
          {
          <fpage>59</fpage>
          , New York, NY, USA,
          <year>2017</year>
          . ACM.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Antonello</surname>
            <given-names>Calabro</given-names>
          </string-name>
          , Said Daoudagh, and
          <string-name>
            <given-names>Eda</given-names>
            <surname>Marchetti</surname>
          </string-name>
          .
          <article-title>Integrating access control and business process for GDPR compliance: A preliminary study</article-title>
          .
          <source>In Proceedings of the Third Italian Conference on Cyber Security</source>
          , Pisa, Italy,
          <source>February 13-15</source>
          ,
          <year>2019</year>
          .,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Francesco</given-names>
            <surname>Di</surname>
          </string-name>
          <string-name>
            <surname>Cerbo</surname>
          </string-name>
          , Fabio Martinelli, Ilaria Matteucci, and
          <string-name>
            <given-names>Paolo</given-names>
            <surname>Mori</surname>
          </string-name>
          .
          <article-title>Towards a declarative approach to stateful and stateless usage control for data protection</article-title>
          .
          <source>In WEBIST</source>
          , pages
          <volume>308</volume>
          {
          <fpage>315</fpage>
          .
          <string-name>
            <surname>SciTePress</surname>
          </string-name>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Omar</surname>
            <given-names>Chowdhury</given-names>
          </string-name>
          , Haining Chen, Jianwei Niu,
          <string-name>
            <given-names>Ninghui</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>and Elisa</given-names>
            <surname>Bertino</surname>
          </string-name>
          .
          <article-title>On xacml's adequacy to specify and to enforce hipaa</article-title>
          .
          <source>In Proceedings of the 3rd USENIX Conference on Health Security and Privacy</source>
          ,
          <source>HealthSec'12</source>
          , pages
          <fpage>11</fpage>
          {
          <fpage>11</fpage>
          , Berkeley, CA, USA,
          <year>2012</year>
          . USENIX Association.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>Maria</given-names>
            <surname>Luisa</surname>
          </string-name>
          <string-name>
            <surname>Damiani</surname>
          </string-name>
          , Elisa Bertino, Barbara Catania, and
          <string-name>
            <given-names>Paolo</given-names>
            <surname>Perlasca</surname>
          </string-name>
          .
          <article-title>GEO-RBAC: A spatially aware RBAC</article-title>
          .
          <source>ACM Trans. Inf. Syst. Secur.</source>
          ,
          <volume>10</volume>
          (
          <issue>1</issue>
          ):
          <fpage>2</fpage>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>S.</given-names>
            <surname>Daoudagh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Lonetti</surname>
          </string-name>
          , and
          <string-name>
            <given-names>E.</given-names>
            <surname>Marchetti</surname>
          </string-name>
          .
          <source>XACMET: XACML Testing &amp; Modeling. Software Quality Journal</source>
          ,
          <year>2019</year>
          . To appear.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>Said</given-names>
            <surname>Daoudagh</surname>
          </string-name>
          .
          <article-title>A Data Warehouse and a Framework for the Validation and Testing of Access Control Systems</article-title>
          .
          <source>Master's thesis</source>
          , Department of Computer Science, University of Pisa, Italy,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Regulation</surname>
          </string-name>
          (EU)
          <year>2016</year>
          /
          <article-title>679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data</article-title>
          ,
          <source>and repealing Directive</source>
          <volume>95</volume>
          /46/EC (
          <article-title>General Data Protection Regulation)</article-title>
          .
          <source>O cial Journal of the European Union, L119:1</source>
          {
          <fpage>88</fpage>
          , May
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Kaniz</surname>
            <given-names>Fatema</given-names>
          </string-name>
          , Christophe Debruyne,
          <string-name>
            <given-names>Dave</given-names>
            <surname>Lewis</surname>
          </string-name>
          ,
          <string-name>
            <surname>Declan</surname>
            <given-names>OSullivan</given-names>
          </string-name>
          , John P Morrison, and
          <string-name>
            <surname>Abdullah-Al Mazed</surname>
          </string-name>
          .
          <article-title>A semi-automated methodology for extracting access control rules from the european data protection directive</article-title>
          .
          <source>In Security and Privacy Workshops (SPW)</source>
          ,
          <year>2016</year>
          IEEE, pages
          <volume>25</volume>
          {
          <fpage>32</fpage>
          . IEEE,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>David</surname>
            <given-names>F.</given-names>
          </string-name>
          <string-name>
            <surname>Ferraiolo</surname>
          </string-name>
          , Ramaswamy Chandramouli, Rick Kuhn, and
          <string-name>
            <surname>Vincent</surname>
            <given-names>C.</given-names>
          </string-name>
          <string-name>
            <surname>Hu</surname>
          </string-name>
          .
          <article-title>Extensible access control markup language (XACML) and next generation access control (NGAC)</article-title>
          .
          <source>In Proceedings of the 2016 ACM International Workshop on Attribute Based Access Control</source>
          ,
          <source>ABAC@CODASPY</source>
          <year>2016</year>
          , New Orleans, Louisiana, USA, March
          <volume>11</volume>
          ,
          <year>2016</year>
          , pages
          <fpage>13</fpage>
          {
          <fpage>24</fpage>
          . ACM,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>Pietro</given-names>
            <surname>Ferrara</surname>
          </string-name>
          and
          <string-name>
            <given-names>Fausto</given-names>
            <surname>Spoto</surname>
          </string-name>
          .
          <article-title>Static analysis for GDPR compliance</article-title>
          . In Elena Ferrari, Marco Baldi, and Roberto Baldoni, editors,
          <source>Proceedings of the Second Italian Conference on Cyber Security (ITASEC)</source>
          ,
          <year>February 2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>A. S. M. Kayes</surname>
          </string-name>
          , Jun Han, and
          <string-name>
            <surname>Alan</surname>
            <given-names>W.</given-names>
          </string-name>
          <string-name>
            <surname>Colman</surname>
          </string-name>
          .
          <article-title>An ontological framework for situation-aware access control of software services</article-title>
          .
          <source>Inf. Syst.</source>
          ,
          <volume>53</volume>
          :
          <fpage>253</fpage>
          {
          <fpage>277</fpage>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Qun</surname>
            <given-names>Ni</given-names>
          </string-name>
          , Elisa Bertino, Jorge Lobo, Carolyn Brodie,
          <string-name>
            <surname>Clare-Marie</surname>
            <given-names>Karat</given-names>
          </string-name>
          , John Karat, and
          <string-name>
            <given-names>Alberto</given-names>
            <surname>Trombetta</surname>
          </string-name>
          .
          <article-title>Privacy-aware role-based access control</article-title>
          .
          <source>ACM Trans. Inf. Syst. Secur.</source>
          ,
          <volume>13</volume>
          (
          <issue>3</issue>
          ):
          <volume>24</volume>
          :1{
          <fpage>24</fpage>
          :
          <fpage>31</fpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          <source>[27] OASIS. eXtensible Access Control Markup Language (XACML) Version</source>
          <volume>3</volume>
          .0. http://docs. oasis-open.
          <source>org/xacml/3</source>
          .0/xacml-3.0
          <article-title>-core-spec-os-en</article-title>
          .html,
          <year>January 2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Mike</surname>
            <given-names>Papadakis</given-names>
          </string-name>
          , Marinos Kintis, Jie Zhang, Yue Jia, Yves Le Traon, and
          <string-name>
            <given-names>Mark</given-names>
            <surname>Harman</surname>
          </string-name>
          .
          <article-title>Chapter six - mutation testing advances: An analysis and survey</article-title>
          . volume
          <volume>112</volume>
          of Advances in Computers, pages
          <volume>275</volume>
          {
          <fpage>378</fpage>
          .
          <string-name>
            <surname>Elsevier</surname>
          </string-name>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <surname>Qusai</surname>
            <given-names>Ramadan</given-names>
          </string-name>
          , Mattia Salnitri, Daniel Struber, Jan Jurjens, and Paolo Giorgini.
          <article-title>From secure business process modeling to design-level security veri cation</article-title>
          .
          <source>In Proceedings of the ACM/IEEE 20th International Conference on Model Driven Engineering Languages and Systems (MODELS)</source>
          , pages
          <fpage>123</fpage>
          {
          <fpage>133</fpage>
          . IEEE,
          <year>September 2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>Silvio</given-names>
            <surname>Ranise</surname>
          </string-name>
          and
          <string-name>
            <given-names>Hari</given-names>
            <surname>Siswantoro</surname>
          </string-name>
          .
          <article-title>Automated legal compliance checking by security policy analysis</article-title>
          .
          <source>In Computer Safety</source>
          , Reliability, and Security - SAFECOMP 2017 Workshops,
          <string-name>
            <surname>ASSURE</surname>
          </string-name>
          , DECSoS, SASSUR, TELERISE, and
          <string-name>
            <surname>TIPS</surname>
          </string-name>
          , Trento, Italy,
          <year>September 12</year>
          ,
          <year>2017</year>
          , Proceedings, volume
          <volume>10489</volume>
          of Lecture Notes in Computer Science, pages
          <volume>361</volume>
          {
          <fpage>372</fpage>
          . Springer,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <surname>Max-Robert Ulbricht</surname>
            and
            <given-names>Frank</given-names>
          </string-name>
          <string-name>
            <surname>Pallas</surname>
          </string-name>
          .
          <article-title>Yappl - A lightweight privacy preference language for legally su cient and automated consent provision in iot scenarios</article-title>
          .
          <source>In DPM 2018</source>
          and
          <article-title>CBT 2018 - ESORICS 2018 International Workshops</article-title>
          , Barcelona, Spain, September 6-
          <issue>7</issue>
          ,
          <year>2018</year>
          , pages
          <fpage>329</fpage>
          {
          <fpage>344</fpage>
          ,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <surname>Stephen</surname>
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Yau</surname>
            and
            <given-names>Junwei</given-names>
          </string-name>
          <string-name>
            <surname>Liu</surname>
          </string-name>
          .
          <article-title>A situation-aware access control based privacy-preserving service matchmaking approach for service-oriented architecture</article-title>
          .
          <source>In 2007 IEEE (ICWS 2007), July 9-13</source>
          ,
          <year>2007</year>
          , Salt Lake City, Utah, USA, pages
          <volume>1056</volume>
          {
          <fpage>1063</fpage>
          . IEEE Computer Society,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>