Uppsats

Enabling Continuous Compliance with Product-Repository Integrated Traceability Management Tool

H

Chalmers tekniska högskola / Institutionen för data och informationsteknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

Continuous compliance is becoming increasingly important as software-intensivesystems are developed in regulated domains, where both systems and regulatoryexpectations evolve over time. Traditional compliance approaches often rely onmanual evidence collection and periodic assessment, making it difficult to maintaincompliance during continuous development. This thesis investigates how productrepository-integrated traceability management (PRITM) tools can support continuous compliance by managing compliance-relevant artifacts, traceability links andchecks within a product repository.The study follows a Design Science Research approach with three iterations. ForRQ1, literature review and workshops were used to develop a reference model ofcontinuous compliance. The main finding is that software development activitiessupport continuous compliance by producing and updating artifacts that can serveas evidence of compliance. However, these artifacts only become useful evidencewhen they are traceable, maintained and connected to compliance requirements andcompliance checks.For RQ2, the reference model was instantiated via a TReqs plugin prototype namedtreqs-compliance. The prototype uses ISO 26262 Part 8 Clauses 7 and 8 as anexample to demonstrate how standards, clauses, compliance requirements, and workproducts can be represented and maintained in a product repository. The prototypeimplements rule-based structural checks, lifecycle status handling, change-reviewdetection, and compliance report generation. The main finding is that PRITMtools can support continuous compliance by keeping compliance artifacts close todevelopment artifacts, managing traceability, and enabling lightweight automatedchecks.For RQ3, the prototype and final reference model were used to reflect on whereeffort could be reduced compared to traditional compliance approaches. The resultssuggest that PRITM tools can mainly reduce effort for structural and traceabilityrelated tasks, such as checking artifact existence, identifying required fields, and locating missing links. However, semantic content evaluation, runtime context checks,and structured compliance argumentation remain outside the implemented scopeand still require human judgment or more advanced tool support.This thesis contributes a reference model for understanding continuous complianceacross activities and artifacts, with a particular focus on the DevOps lifecycle. Italso provides a prototype demonstration showing how selected concepts can be implemented in a PRITM tool.

Information

Författare
Yu, Jinlu
Lärosäte / institution
Chalmers tekniska högskola / Institutionen för data och informationsteknik
Publiceringsdatum
2026
Uppsatstyp
H
Språk
Engelska