CoReL: Policy-Based and Model-Driven Regulatory Compliance Management

被引:9
作者
El Kharbili, Marwane [1 ]
Ma, Qin [1 ,2 ]
Kelsen, Pierre [1 ,2 ]
Pulvermueller, Elke [3 ]
机构
[1] Univ Luxembourg, Lab Adv Software Syst, Luxembourg, Luxembourg
[2] Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust, Luxembourg, Luxembourg
[3] Univ Osnabruck, Inst Comp Sci, Dept Math & Comp Sci, Osnabruck, Germany
来源
15TH IEEE INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE (EDOC 2011) | 2011年
关键词
Regulatory Compliance; Policy; Business Processes; Domain Specific Language; VERIFICATION;
D O I
10.1109/EDOC.2011.23
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Regulatory compliance management is now widely recognized as one of the main challenges still to be efficiently dealt with in information systems. In the discipline of business process management in particular, compliance is considered as an important driver of the efficiency, reliability and market value of companies. It consists of ensuring that enterprise systems behave according to some guidance provided in the form of regulations. This paper gives a definition of the research problem of regulatory compliance. We show why we expect a formal policy-based and model-driven approach to provide significant advantages in allowing enterprises to flexibly manage decision-making related to regulatory compliance. For this purpose, we contribute CoReL, a domain-specific modeling language for representing compliance requirements that has a graphical concrete syntax. Informal semantics of CoReL are introduced and its use is illustrated on an example. CoReL allows to leverage business process compliance modeling and checking, enhancing it with regard to, among other dimensions, user-friendliness, genericity, and traceability.
引用
收藏
页码:247 / 256
页数:10
相关论文
共 35 条
[1]  
[Anonymous], 1999, Model checking
[2]  
Bertino E., 2001, ACM Transactions on Information and Systems Security, V4, P191, DOI 10.1145/501978.501979
[3]  
Boella G., 2010, 13 INT WORKSH NONM R
[4]  
Bonatti B. P. A., 2004, RULE BASED POLICY SP
[5]  
Christel BaierJoost-Pieter Katoen., 2008, Principles of model checking
[6]  
Damianou N, 2001, LECT NOTES COMPUT SC, V1995, P18
[7]  
Dave S., 2009, EMF ECLIPSE MODELING
[8]  
El Kharbili M., 2008, Modellierung betrieblicher Informationssysteme-Modellierung zwischen SOA und Compliance Management-27.-28. November 2008 Saarbrucken, P107
[9]  
El Kharbili M., 2008, P 3 WORKSH EM WEB SE, P87
[10]  
El Kharbili M., 2011, SEMANTIC TECHNOLOGIE