DocumentCode
1958239
Title
Application and Economic Implications of an Automated Requirement-Oriented and Standard-Based Compliance Monitoring and Reporting Prototype
Author
Kehlenbeck, Matthias ; Sandner, Thorben ; Breitner, Michael H.
Author_Institution
Inst. fur Wirtschaftsinformatik, Leibniz Univ. Hannover, Hannover, Germany
fYear
2010
fDate
15-18 Feb. 2010
Firstpage
468
Lastpage
474
Abstract
Compliance management is a challenging task affected by continuously increasing legal requirements. Compliance with legal requirements can be assured by the incorporation of control activities into business processes. But the maintenance and monitoring of these control activities is a complex, time-consuming and often manual task. However, the timely communication of control exceptions is an important factor for the success of compliance management. The present paper presents an innovative prototypical implementation of an automated compliance monitoring and reporting system. This system is based on established standards and existing technologies. In particular, business processes are notated in BPMN and modeled in XPDL, control activities are linked to risks using COSO, control exceptions are defined using SWRL and access control data is transformed from proprietary models to XACML. The development of the prototype was aligned with common design-science research. The application of the developed prototype and its economic implications are concisely discussed with respect to different business requirements and information needs.
Keywords
XML; authorisation; business process re-engineering; law; socio-economic effects; COSO language; SWRL language; XACML model; XPDL model; access control data; application implication; automated compliance monitoring; automated compliance reporting; business process management; compliance management; control exceptions; economic implications; legal requirements; Automatic control; Communication system control; Computerized monitoring; Control systems; Environmental economics; Law; Legal factors; Prototypes; Risk management; Technology management; IS security; IT compliance; IT risk management; business process management;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability, and Security, 2010. ARES '10 International Conference on
Conference_Location
Krakow
Print_ISBN
978-1-4244-5879-0
Type
conf
DOI
10.1109/ARES.2010.88
Filename
5438054
Link To Document