• DocumentCode
    492660
  • Title

    Rubacon

  • Author

    Hohn, S. ; Jurjens, Jan

  • Author_Institution
    Univ. of Freiburg, Freiburg
  • fYear
    2008
  • fDate
    10-18 May 2008
  • Firstpage
    875
  • Lastpage
    878
  • Abstract
    Compliance frameworks, laws and regulations such as Sarbanes Oxley, Basel II, Solvency II, HIPAA etc. demand from companies in a more and more rigorous way to demonstrate that their organisation, processes and supporting IT landscape implement and follow a set of guidelines at differing levels of abstraction. The work presented in this paper aims to contribute to a software engineering process which is driven by security, risk and compliance management considerations. We concentrate on a part of this approach that focusses on the question how one can use software engineering methods and tools to enforce that the configuration of a system enforces the security policies that arise from business compliance regulations. We present tool support for model-based compliance engineering, i.e. for the model-based development and analysis of software configurations that ensures compliance with security policies. It allows one to check UML models of business applications and their configuration data for adherence to security policies and compliance requirements. The tool is based on standardized data formats, such as UML and XML, which makes its integration into existing business architectures as efficient as possible.
  • Keywords
    Unified Modeling Language; XML; business process re-engineering; security of data; software tools; Basel II; HIPAA; Rubacon; Sarbanes Oxley; Solvency II; UML models; XML; business applications; business architectures; model-based compliance engineering; security policies; software engineering methods; software engineering tools; Application software; Computer architecture; Data security; Engineering management; Guidelines; Risk management; Software engineering; Software tools; Unified modeling language; XML; access control; security analysis; user permissions;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering, 2008. ICSE '08. ACM/IEEE 30th International Conference on
  • Conference_Location
    Leipzig
  • ISSN
    0270-5257
  • Print_ISBN
    978-1-4244-4486-1
  • Electronic_ISBN
    0270-5257
  • Type

    conf

  • DOI
    10.1145/1368088.1368228
  • Filename
    4814214