Challenges of Assuring Compliance of Information Systems in Finance

被引:1
|
作者
Momcilovic, Tomas Bueno [1 ]
Balta, Dian [1 ]
机构
[1] Fortiss GmbH, Munich, Germany
关键词
regulatory compliance; assurance; knowledge modeling; MANAGEMENT; SECURITY; METHODOLOGY; DESIGN; LAW;
D O I
10.1007/978-3-031-56281-5_8
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Assuring regulatory compliance of information systems (IS), as a bundle of software systems and business processes, is an important, but costly and continuous effort. Laws formulate demands for quality properties in ambiguous language, requiring substantial interpretation. Industry standards provide support, but remain generic and applicable to heterogeneous company IS contexts. Before compliance measures can be implemented in software assets and processes, a specific interpretation based on the context of each company is a prerequisite. Compliance experts such as auditors support this process by accounting for the perspectives of company stakeholders. Ultimately, however, the complexity of the required knowledge, legal and technical facets prevents organizations from continuously establishing situational awareness or guarantees, and answering the question: is the company currently compliant? We illustrate the complexity of assuring compliance in a qualitative case study with a European, software-driven corporation in the financial industry. Through modeling of an example of annual audits and analyzing literature, we describe the perspectives of the involved stakeholders with their roles, knowledge needs and facets. We observe six challenges: (1) large number of items and links; (2) unclear and implicit links; (3) siloing of knowledge; (4) multiple sources of truth; (5) high costs of learning from audits; and (6) uncertain results of traditional auditing. We discuss the implications of these observed challenges, and briefly explore potential avenues for resolution.
引用
收藏
页码:135 / 152
页数:18
相关论文
共 50 条
  • [1] Emergent Needs in Assuring Security-Relevant Compliance of Information Systems
    Momcilovic, Tomas Bueno
    Balta, Dian
    PROCEEDINGS OF THE 2024 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2024, 2024, : 46 - 49
  • [2] Assuring Information Quality in Talent Information Systems
    Wang, Yunhong
    Su, Ying
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON COOPERATION AND PROMOTION OF INFORMATION RESOURCES IN SCIENCE AND TECHNOLOGY(COINFO 10), 2010, : 265 - +
  • [3] ASSURING INFORMATION QUALITY IN WEB INFORMATION SYSTEMS
    Su, Ying
    Peng, Jie
    Jin, Zhanming
    IMETI 2008: INTERNATIONAL MULTI-CONFERENCE ON ENGINEERING AND TECHNOLOGICAL INNOVATION, VOL III, POST-CONFERENCE ISSUE, PROCEEDINGS, 2008, : 50 - +
  • [4] Emerging Challenges in Information Systems Research for Regulatory Compliance Management
    Abdullah, Norris Syed
    Sadiq, Shazia
    Indulska, Marta
    ADVANCED INFORMATION SYSTEMS ENGINEERING, PROCEEDINGS, 2010, 6051 : 251 - +
  • [5] Voters Use Campaign Finance Transparency and Compliance Information
    Abby K. Wood
    Political Behavior, 2023, 45 : 1553 - 1579
  • [6] Voters Use Campaign Finance Transparency and Compliance Information
    Wood, Abby K.
    POLITICAL BEHAVIOR, 2023, 45 (04) : 1553 - 1579
  • [7] Information systems in public finance
    Buhl, HU
    Weinhardt, C
    WIRTSCHAFTSINFORMATIK, 1999, 41 (02): : 103 - 104
  • [8] Assuring Compliance with Protection Profiles with ThreatGet
    El Sadany, Magdy
    Schmittner, Christoph
    Kastner, Wolfgang
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2019, 2019, 11699 : 62 - 73
  • [9] ASSURING ADHERENCE AND COMPLIANCE WITH AEROSOL THERAPY
    Bos, A. C.
    Engelkes, M.
    Janssens, H. M.
    PEDIATRIC PULMONOLOGY, 2015, 50 : S14 - S15
  • [10] Assuring Compliance in IT Subcontracting and Cloud Computing
    Knolmayer, Gerhard F.
    Asprion, Petra
    NEW STUDIES IN GLOBAL IT AND BUSINESS SERVICES OUTSOURCING, 2011, 91 : 21 - 45