DocumentCode :
625548
Title :
Business Process Compliance via Security Validation as a Service
Author :
Compagna, Luca ; Guilleminot, Pierre ; Brucker, Achim D.
Author_Institution :
SAP Res. Sophia-Antipolis, Mougins, France
fYear :
2013
fDate :
18-22 March 2013
Firstpage :
455
Lastpage :
462
Abstract :
Modern enterprise systems are often process-based, i.e., they allow for the direct execution of business processes that are specified in a high-level language such as BPMN. In this paper, we present a service, called Security Validation as a Service (SVaaS) for validating the compliance of the business processes during design-time. Basically, while modeling a business process the business analyst specifies as well the security and compliance requirements the business process should comply to. By pressing a button, these requirements are validated and the results are presented in a graphical format to the business analysis. At the core of SVaaS lies a rigorous and industrially viable approach in which the security validation business logic is handled server-side (SVaaS Server) in the Cloud, while the client-side user interface that business analysts use is handled by a light-weight SVaaS Connector. As proof-of-concept we created a SVaaS prototype in which the SVaaS Server is deployed on the SAP NetWeaver Cloud and two SVaaS Connectors are built to enable two well-known BPMN tools, SAP NetWeaver BPM and Activiti, to consume SVaaS against industrial relevant business processes.
Keywords :
business data processing; client-server systems; cloud computing; security of data; user interfaces; Activiti; BPMN tool; SAP NetWeaver BPM; SAP NetWeaver cloud; SVaaS prototype; SVaaS server; business analysis; business analyst; business logic; business process compliance; business process execution; business process modeling; client-side user interface; compliance requirement; design-time; enterprise system; graphical format; high-level language; industrial relevant business process; light-weight SVaaS connector; security validation as a service; Analytical models; Business; Connectors; Security; Servers; Standards; XML; Business Process Management; Security; Validation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Testing, Verification and Validation (ICST), 2013 IEEE Sixth International Conference on
Conference_Location :
Luembourg
Print_ISBN :
978-1-4673-5961-0
Type :
conf
DOI :
10.1109/ICST.2013.63
Filename :
6569760
Link To Document :
بازگشت