DocumentCode :
2651504
Title :
Lifecycle Management of Relational Records for External Auditing and Regulatory Compliance
Author :
Ataullah, Ahmed A. ; Tompa, Frank Wm
Author_Institution :
David R. Cheriton Sch. of Comput. Sci., Univ. of Waterloo, Waterloo, ON, Canada
fYear :
2011
fDate :
6-8 June 2011
Firstpage :
73
Lastpage :
80
Abstract :
Transactional business records are subject to a wide array of regulatory and auditing requirements. The problem of converting task specific business policies to database level constraints is challenging due to the immense complexity of corporate workflows and record lifecycles. In this paper we present a modeling framework for identifying business processes and record lifecycles within relational database systems that supports the automatic generation, implementation and verification of low level data management constraints. Our modeling language allows users to identify states of business processes within a relational database system and subsequently to enforce a broad set of conditional business rules based on the particular path that a business process has taken in the model. Our approach is unique in that it offers a single unified layer for process modeling and implementing complex workflow based constraints, temporal access control constraints, and records retention restrictions. Furthermore we propose the notion of "business process integrity" as a layer above traditional database integrity constraints, which combines conditional access control and general purpose temporal integrity constraints, to assure external auditors that each business record in the database has followed a legal path to its current state.
Keywords :
auditing; authorisation; business process re-engineering; formal verification; records management; relational databases; transaction processing; automatic generation; automatic verification; business policies; business process integrity; corporate workflows; data management constraints; database level constraints; external auditing; lifecycle management; modeling language; regulatory compliance; relational database systems; relational records; temporal access control constraints; transactional business records; Access control; Business; Database systems; History; Object recognition; Relational databases; modeling integrity constraints; object lifecycle modeling; records management; relational database;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Policies for Distributed Systems and Networks (POLICY), 2011 IEEE International Symposium on
Conference_Location :
Pisa
Print_ISBN :
978-1-4244-9879-6
Electronic_ISBN :
978-0-7695-4330-7
Type :
conf
DOI :
10.1109/POLICY.2011.20
Filename :
5976798
Link To Document :
بازگشت