DocumentCode :
1958239
Title :
Application and Economic Implications of an Automated Requirement-Oriented and Standard-Based Compliance Monitoring and Reporting Prototype
Author :
Kehlenbeck, Matthias ; Sandner, Thorben ; Breitner, Michael H.
Author_Institution :
Inst. fur Wirtschaftsinformatik, Leibniz Univ. Hannover, Hannover, Germany
fYear :
2010
fDate :
15-18 Feb. 2010
Firstpage :
468
Lastpage :
474
Abstract :
Compliance management is a challenging task affected by continuously increasing legal requirements. Compliance with legal requirements can be assured by the incorporation of control activities into business processes. But the maintenance and monitoring of these control activities is a complex, time-consuming and often manual task. However, the timely communication of control exceptions is an important factor for the success of compliance management. The present paper presents an innovative prototypical implementation of an automated compliance monitoring and reporting system. This system is based on established standards and existing technologies. In particular, business processes are notated in BPMN and modeled in XPDL, control activities are linked to risks using COSO, control exceptions are defined using SWRL and access control data is transformed from proprietary models to XACML. The development of the prototype was aligned with common design-science research. The application of the developed prototype and its economic implications are concisely discussed with respect to different business requirements and information needs.
Keywords :
XML; authorisation; business process re-engineering; law; socio-economic effects; COSO language; SWRL language; XACML model; XPDL model; access control data; application implication; automated compliance monitoring; automated compliance reporting; business process management; compliance management; control exceptions; economic implications; legal requirements; Automatic control; Communication system control; Computerized monitoring; Control systems; Environmental economics; Law; Legal factors; Prototypes; Risk management; Technology management; IS security; IT compliance; IT risk management; business process management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability, and Security, 2010. ARES '10 International Conference on
Conference_Location :
Krakow
Print_ISBN :
978-1-4244-5879-0
Type :
conf
DOI :
10.1109/ARES.2010.88
Filename :
5438054
Link To Document :
بازگشت