DocumentCode :
3110071
Title :
A Model-Driven engineering approach with diagnosis of non-conformance of security objectives in business process models
Author :
Varela-Vaca, A.J. ; Gasca, Rafael M. ; Jimenez-Ramirez, A.
Author_Institution :
Comput. Languages & Syst. Dept., Univ. of Seville, Seville, Spain
fYear :
2011
fDate :
19-21 May 2011
Firstpage :
1
Lastpage :
6
Abstract :
Several reports indicate that the highest business priorities include: business improvement, security, and IT management. The importance of security and risk management is gaining that even government statements in some cases have imposed the inclusion of security and risk management within business management. Risk assessment has become an essential mechanism for business security analysts, since it allows the identification and evaluation of any threats, vulnerabilities, and risks to which organizations maybe be exposed. In this work, a framework based on the concepts of Model-Driven Development has been proposed. The framework provides different stages which range from a high abstraction level to an executable level. The main contribution lie in the presentation of an extension of a business process meta-model which includes risk information based on standard approaches. The meta-model provides necessary characteristics for the risk assessment of business process models at an abstract level of the approach. The framework has been equipped with specific stages for the automatic validation of business processes using model-based diagnosis which permits the detection of the non-conformance of security objectives specified. The validation stages ensure that business processes are correct with regard to the objectives specified by the customer before they are transformed into executable processes.
Keywords :
business data processing; risk management; security of data; software engineering; IT management; business improvement; business management; business process meta-model; business process models; model-based diagnosis; model-driven engineering approach; nonconformance diagnosis; risk assessment; risk management; security management; security objectives; Adaptation models; Organizations; Quality of service; Risk management; Security; Unified modeling language; business process; conformance; risk assessment; risk management; security requirement;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Research Challenges in Information Science (RCIS), 2011 Fifth International Conference on
Conference_Location :
Gosier
ISSN :
2151-1349
Print_ISBN :
978-1-4244-8670-0
Electronic_ISBN :
2151-1349
Type :
conf
DOI :
10.1109/RCIS.2011.6006844
Filename :
6006844
Link To Document :
بازگشت