• DocumentCode
    2651504
  • Title

    Lifecycle Management of Relational Records for External Auditing and Regulatory Compliance

  • Author

    Ataullah, Ahmed A. ; Tompa, Frank Wm

  • Author_Institution
    David R. Cheriton Sch. of Comput. Sci., Univ. of Waterloo, Waterloo, ON, Canada
  • fYear
    2011
  • fDate
    6-8 June 2011
  • Firstpage
    73
  • Lastpage
    80
  • Abstract
    Transactional business records are subject to a wide array of regulatory and auditing requirements. The problem of converting task specific business policies to database level constraints is challenging due to the immense complexity of corporate workflows and record lifecycles. In this paper we present a modeling framework for identifying business processes and record lifecycles within relational database systems that supports the automatic generation, implementation and verification of low level data management constraints. Our modeling language allows users to identify states of business processes within a relational database system and subsequently to enforce a broad set of conditional business rules based on the particular path that a business process has taken in the model. Our approach is unique in that it offers a single unified layer for process modeling and implementing complex workflow based constraints, temporal access control constraints, and records retention restrictions. Furthermore we propose the notion of "business process integrity" as a layer above traditional database integrity constraints, which combines conditional access control and general purpose temporal integrity constraints, to assure external auditors that each business record in the database has followed a legal path to its current state.
  • Keywords
    auditing; authorisation; business process re-engineering; formal verification; records management; relational databases; transaction processing; automatic generation; automatic verification; business policies; business process integrity; corporate workflows; data management constraints; database level constraints; external auditing; lifecycle management; modeling language; regulatory compliance; relational database systems; relational records; temporal access control constraints; transactional business records; Access control; Business; Database systems; History; Object recognition; Relational databases; modeling integrity constraints; object lifecycle modeling; records management; relational database;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks (POLICY), 2011 IEEE International Symposium on
  • Conference_Location
    Pisa
  • Print_ISBN
    978-1-4244-9879-6
  • Electronic_ISBN
    978-0-7695-4330-7
  • Type

    conf

  • DOI
    10.1109/POLICY.2011.20
  • Filename
    5976798