@InProceedings{2007RejasCR-EuroSPI, author="Rejas-Muslera, Ricardo J. and Cuadrado-Gallego, Juan. J. and Rodriguez, Daniel", editor="Abrahamsson, Pekka and Baddoo, Nathan and Margaria, Tiziana and Messnarz, Richard", title="Defining a Legal Risk Management Strategy: Process, Legal Risk and Lifecycle", booktitle="Software Process Improvement", year="2007", publisher="Springer Berlin Heidelberg", address="Berlin, Heidelberg", pages="118--123", abstract="All systems during their lifecycle, no matter how simple, will generate legal implications that need to be managed. The potential cost of an inadequate management of legal aspects can even imply the failure of the project. As a consequence, legal risk management should not only be a major activity of the development lifecycle, but it needs to be performed by qualified personnel following well-defined procedures and standards. However, current software process improvement models do not properly include processes for legal audits and more concretely legal risks management for each phase of the software development lifecycle. Neither in industry related to manage legal risks of software projects is possible to find well-defined and standardised projects. This lack of standardised process means that legal risks are handled reactively instead of proactively. This work presents a process for managing legal risks. It is organised by a series of activities to be performed at each stage of the software development lifecycle to eliminate or minimize the risk of project failures for legal reasons.", isbn="978-3-540-75381-0" }