KIT | KIT-Bibliothek | Impressum | Datenschutz

Enabling a Model-Driven Workflow for Ongoing Interdisciplinary Collaboration in Legal Threat Modeling

Boltz, Nicolas ORCID iD icon 1; Sterz, Leonie ORCID iD icon 1; Raabe, Oliver 1,2; Gerking, Christopher ORCID iD icon 1
1 Institut für Informationssicherheit und Verlässlichkeit (KASTEL), Karlsruher Institut für Technologie (KIT)
2 Institut für Informations- und Wirtschaftsrecht (IIWR), Karlsruher Institut für Technologie (KIT)

Abstract:

Context: Software systems often provide critical functionality or process personal data, requiring compliance with applicable legal regulations. Ensuring legal conformity demands close collaboration between legal and technical experts, but differences in terminology and methodology make this challenging. Objective: In this article, we aim to address the challenges in legal interdisciplinary collaboration by proposing a model-based workflow for continuous and collaborative legal assessments within the context of threat modeling. Method: The central aspects of the workflow are based on model-driven engineering techniques and were developed through active collaboration between researchers in software engineering and legal informatics/data protection at the KASTEL Security Research Labs. The goal of the collaboration was to integrate the methodologies of both domains into the workflow equally. Result: The proposed workflow centers on maintaining consistency between a legal viewpoint and data flow diagrams, allowing each discipline to work from its own perspective while providing automated support in threat identification through an extended existing data flow analysis framework. ... mehr


Preprint §
DOI: 10.5445/IR/1000189188
Veröffentlicht am 19.12.2025
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Publikationstyp Zeitschriftenaufsatz
Publikationsjahr 2025
Sprache Englisch
Identifikator ISSN: 0950-5849, 1873-6025
KITopen-ID: 1000189188
HGF-Programm 46.23.03 (POF IV, LK 01) Engineering Security for Mobility Systems
Erschienen in Information & software technology
Verlag Elsevier
Bemerkung zur Veröffentlichung in press
Schlagwörter interdisciplinary collaboration, legal assessments, threat modeling, data, flow analysis, data protection
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page