DocumentCode
492660
Title
Rubacon
Author
Hohn, S. ; Jurjens, Jan
Author_Institution
Univ. of Freiburg, Freiburg
fYear
2008
fDate
10-18 May 2008
Firstpage
875
Lastpage
878
Abstract
Compliance frameworks, laws and regulations such as Sarbanes Oxley, Basel II, Solvency II, HIPAA etc. demand from companies in a more and more rigorous way to demonstrate that their organisation, processes and supporting IT landscape implement and follow a set of guidelines at differing levels of abstraction. The work presented in this paper aims to contribute to a software engineering process which is driven by security, risk and compliance management considerations. We concentrate on a part of this approach that focusses on the question how one can use software engineering methods and tools to enforce that the configuration of a system enforces the security policies that arise from business compliance regulations. We present tool support for model-based compliance engineering, i.e. for the model-based development and analysis of software configurations that ensures compliance with security policies. It allows one to check UML models of business applications and their configuration data for adherence to security policies and compliance requirements. The tool is based on standardized data formats, such as UML and XML, which makes its integration into existing business architectures as efficient as possible.
Keywords
Unified Modeling Language; XML; business process re-engineering; security of data; software tools; Basel II; HIPAA; Rubacon; Sarbanes Oxley; Solvency II; UML models; XML; business applications; business architectures; model-based compliance engineering; security policies; software engineering methods; software engineering tools; Application software; Computer architecture; Data security; Engineering management; Guidelines; Risk management; Software engineering; Software tools; Unified modeling language; XML; access control; security analysis; user permissions;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Engineering, 2008. ICSE '08. ACM/IEEE 30th International Conference on
Conference_Location
Leipzig
ISSN
0270-5257
Print_ISBN
978-1-4244-4486-1
Electronic_ISBN
0270-5257
Type
conf
DOI
10.1145/1368088.1368228
Filename
4814214
Link To Document