• DocumentCode
    1958239
  • Title

    Application and Economic Implications of an Automated Requirement-Oriented and Standard-Based Compliance Monitoring and Reporting Prototype

  • Author

    Kehlenbeck, Matthias ; Sandner, Thorben ; Breitner, Michael H.

  • Author_Institution
    Inst. fur Wirtschaftsinformatik, Leibniz Univ. Hannover, Hannover, Germany
  • fYear
    2010
  • fDate
    15-18 Feb. 2010
  • Firstpage
    468
  • Lastpage
    474
  • Abstract
    Compliance management is a challenging task affected by continuously increasing legal requirements. Compliance with legal requirements can be assured by the incorporation of control activities into business processes. But the maintenance and monitoring of these control activities is a complex, time-consuming and often manual task. However, the timely communication of control exceptions is an important factor for the success of compliance management. The present paper presents an innovative prototypical implementation of an automated compliance monitoring and reporting system. This system is based on established standards and existing technologies. In particular, business processes are notated in BPMN and modeled in XPDL, control activities are linked to risks using COSO, control exceptions are defined using SWRL and access control data is transformed from proprietary models to XACML. The development of the prototype was aligned with common design-science research. The application of the developed prototype and its economic implications are concisely discussed with respect to different business requirements and information needs.
  • Keywords
    XML; authorisation; business process re-engineering; law; socio-economic effects; COSO language; SWRL language; XACML model; XPDL model; access control data; application implication; automated compliance monitoring; automated compliance reporting; business process management; compliance management; control exceptions; economic implications; legal requirements; Automatic control; Communication system control; Computerized monitoring; Control systems; Environmental economics; Law; Legal factors; Prototypes; Risk management; Technology management; IS security; IT compliance; IT risk management; business process management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability, and Security, 2010. ARES '10 International Conference on
  • Conference_Location
    Krakow
  • Print_ISBN
    978-1-4244-5879-0
  • Type

    conf

  • DOI
    10.1109/ARES.2010.88
  • Filename
    5438054