The Experts below are selected from a list of 112530 Experts worldwide ranked by ideXlab platform
Frank Leymann - One of the best experts on this subject based on the ideXlab platform.
-
CLOSER (Selected Papers) - An Universal Approach for Compliance Management Using Compliance Descriptors
Communications in Computer and Information Science, 2017Co-Authors: Falko Koetter, Frank Leymann, Sebastian Wagner, Maximilien Kintz, Monika Kochanowski, Thatchanok Wiriyarattanakul, Christoph Fehling, Philipp Gildein, Anette WeisbeckerAbstract:Trends like outsourcing and cloud computing have led to a distribution of business processes among different IT systems and organizations. Still, businesses need to ensure Compliance regarding laws and regulations of these distributed processes. This need gave way to many new solutions for Compliance Management and checking. Compliance requirements arise from legal documents and are implemented in all parts of enterprise IT, creating a business IT gap between legal texts and software implementation. Compliance solutions must bridge this gap as well as support a wide variety of Compliance requirements. To achieve these goals, we developed an integrating Compliance descriptor for Compliance modeling on the legal, requirement and technical level, incorporating arbitrary rule languages for specific types of requirements. Using a modeled descriptor a Compliance checking architecture can be configured, including specific rule checking implementations. The graphical notation of the Compliance descriptor and the formalism it’s based on are described and evaluated using a prototype as well as expert interviews. Based on evaluation results, an extension for Compliance Management in unstructured processes is outlined.
-
SOA-enabled Compliance Management: instrumenting, assessing, and analyzing service-based business processes
Service Oriented Computing and Applications, 2013Co-Authors: Carlos Rodríguez, Frank Leymann, Daniel Schleicher, Florian Daniel, Fabio Casati, Sebastian WagnerAbstract:Facilitating Compliance Management, that is, assisting a company’s Management in conforming to laws, regulations, standards, contracts, and policies, is a hot but non-trivial task. The service-oriented architecture (SOA) has evolved traditional, manual business practices into modern, service-based IT practices that ease part of the problem: the systematic definition and execution of business processes. This, in turn, facilitates the online monitoring of system behaviors and the enforcement of allowed behaviors—all ingredients that can be used to assist Compliance Management on the fly during process execution. In this paper, instead of focusing on monitoring and runtime enforcement of rules or constraints, we strive for an alternative approach to Compliance Management in SOAs that aims at assessing and improving Compliance. We propose two ingredients: (i) a model and tool to design compliant service-based processes and to instrument them in order to generate evidence of how they are executed and (ii) a reporting and analysis suite to create awareness of a company’s Compliance state and to enable understanding why and where Compliance violations have occurred. Together, these ingredients result in an approach that is close to how the real stakeholders—Compliance experts and auditors—actually assess the state of Compliance in practice and that is less intrusive than enforcing Compliance.
-
SOA-enabled Compliance Management: instrumenting, assessing, and analyzing service-based business processes
Service Oriented Computing and Applications, 2013Co-Authors: Carlos Rodríguez, Frank Leymann, Daniel Schleicher, Florian Daniel, Fabio Casati, Sebastian WagnerAbstract:Facilitating Compliance Management, that is, assisting a company's Management in conforming to laws, regulations, standards, contracts, and policies, is a hot but non-trivial task. The service-oriented architecture (SOA) has evolved traditional, manual business practices into modern, service-based IT practices that ease part of the problem: the systematic definition and execution of business processes. This, in turn, facilitates the online monitoring of system behaviors and the enforcement of allowed behaviors-all ingredients that can be used to assist Compliance Management on the fly during process execution. In this paper, instead of focusing on monitoring and runtime enforcement of rules or constraints, we strive for an alternative approach to Compliance Management in SOAs that aims at assessing and improving Compliance. We propose two ingredients: (i) a model and tool to design compliant service-based processes and to instrument them in order to generate evidence of how they are executed and (ii) a reporting and analysis suite to create awareness of a company's Compliance state and to enable understanding why and where Compliance violations have occurred. Together, these ingredients result in an approach that is close to how the real stakeholders-Compliance experts and auditors-actually assess the state of Compliance in practice and that is less intrusive than enforcing Compliance. © 2013 Springer-Verlag London
-
Compliant Cloud Computing (C3): Architecture and Language Support for User-Driven Compliance Management in Clouds
2010 IEEE 3rd International Conference on Cloud Computing, 2010Co-Authors: Ivona Brandic, Tobias Anstett, David Schumm, Schahram Dustdar, Frank Leymann, Ralf KonradAbstract:Cloud computing represents a promising computing paradigm, where computational power is provided similar to utilities like water, electricity or gas. While most of the Cloud providers can guarantee some measurable non-functional performance metrics e.g., service availability or throughput, there is lack of adequate mechanisms for guaranteeing certifiable and auditable security, trust, and privacy of the applications and the data they process. This lack represents an obstacle for moving most business relevant applications into the Cloud. In this paper we devise a novel approach for Compliance Management in Clouds, which we termed Compliant Cloud Computing (C3). On one hand, we propose novel languages for specifying Compliance requirements concerning security, privacy, and trust by leveraging domain specific languages and Compliance level agreements. On the other hand, we propose the C3 middleware responsible for the deployment of certifiable and auditable applications, for provider selection in Compliance with the user requirements, and for enactment and enforcement of Compliance level agreements. We underpin our approach with a use case discussing various techniques necessary for achieving security, privacy, and trust in Clouds as for example data fragmentation among different protection domains or among different geographical regions.
-
IEEE CLOUD - Compliant Cloud Computing (C3): Architecture and Language Support for User-Driven Compliance Management in Clouds
2010 IEEE 3rd International Conference on Cloud Computing, 2010Co-Authors: Ivona Brandic, Tobias Anstett, David Schumm, Schahram Dustdar, Frank Leymann, Ralf KonradAbstract:Cloud computing represents a promising computing paradigm, where computational power is provided similar to utilities like water, electricity or gas. While most of the Cloud providers can guarantee some measurable non-functional performance metrics e.g., service availability or throughput, there is lack of adequate mechanisms for guaranteeing certifiable and auditable security, trust, and privacy of the applications and the data they process. This lack represents an obstacle for moving most business relevant applications into the Cloud. In this paper we devise a novel approach for Compliance Management in Clouds, which we termed Compliant Cloud Computing (C3). On one hand, we propose novel languages for specifying Compliance requirements concerning security, privacy, and trust by leveraging domain specific languages and Compliance level agreements. On the other hand, we propose the C3 middleware responsible for the deployment of certifiable and auditable applications, for provider selection in Compliance with the user requirements, and for enactment and enforcement of Compliance level agreements. We underpin our approach with a use case discussing various techniques necessary for achieving security, privacy, and trust in Clouds as for example data fragmentation among different protection domains or among different geographical regions.
Ralf Konrad - One of the best experts on this subject based on the ideXlab platform.
-
Compliant Cloud Computing (C3): Architecture and Language Support for User-Driven Compliance Management in Clouds
2010 IEEE 3rd International Conference on Cloud Computing, 2010Co-Authors: Ivona Brandic, Tobias Anstett, David Schumm, Schahram Dustdar, Frank Leymann, Ralf KonradAbstract:Cloud computing represents a promising computing paradigm, where computational power is provided similar to utilities like water, electricity or gas. While most of the Cloud providers can guarantee some measurable non-functional performance metrics e.g., service availability or throughput, there is lack of adequate mechanisms for guaranteeing certifiable and auditable security, trust, and privacy of the applications and the data they process. This lack represents an obstacle for moving most business relevant applications into the Cloud. In this paper we devise a novel approach for Compliance Management in Clouds, which we termed Compliant Cloud Computing (C3). On one hand, we propose novel languages for specifying Compliance requirements concerning security, privacy, and trust by leveraging domain specific languages and Compliance level agreements. On the other hand, we propose the C3 middleware responsible for the deployment of certifiable and auditable applications, for provider selection in Compliance with the user requirements, and for enactment and enforcement of Compliance level agreements. We underpin our approach with a use case discussing various techniques necessary for achieving security, privacy, and trust in Clouds as for example data fragmentation among different protection domains or among different geographical regions.
-
IEEE CLOUD - Compliant Cloud Computing (C3): Architecture and Language Support for User-Driven Compliance Management in Clouds
2010 IEEE 3rd International Conference on Cloud Computing, 2010Co-Authors: Ivona Brandic, Tobias Anstett, David Schumm, Schahram Dustdar, Frank Leymann, Ralf KonradAbstract:Cloud computing represents a promising computing paradigm, where computational power is provided similar to utilities like water, electricity or gas. While most of the Cloud providers can guarantee some measurable non-functional performance metrics e.g., service availability or throughput, there is lack of adequate mechanisms for guaranteeing certifiable and auditable security, trust, and privacy of the applications and the data they process. This lack represents an obstacle for moving most business relevant applications into the Cloud. In this paper we devise a novel approach for Compliance Management in Clouds, which we termed Compliant Cloud Computing (C3). On one hand, we propose novel languages for specifying Compliance requirements concerning security, privacy, and trust by leveraging domain specific languages and Compliance level agreements. On the other hand, we propose the C3 middleware responsible for the deployment of certifiable and auditable applications, for provider selection in Compliance with the user requirements, and for enactment and enforcement of Compliance level agreements. We underpin our approach with a use case discussing various techniques necessary for achieving security, privacy, and trust in Clouds as for example data fragmentation among different protection domains or among different geographical regions.
Sebastian Wagner - One of the best experts on this subject based on the ideXlab platform.
-
CLOSER (Selected Papers) - An Universal Approach for Compliance Management Using Compliance Descriptors
Communications in Computer and Information Science, 2017Co-Authors: Falko Koetter, Frank Leymann, Sebastian Wagner, Maximilien Kintz, Monika Kochanowski, Thatchanok Wiriyarattanakul, Christoph Fehling, Philipp Gildein, Anette WeisbeckerAbstract:Trends like outsourcing and cloud computing have led to a distribution of business processes among different IT systems and organizations. Still, businesses need to ensure Compliance regarding laws and regulations of these distributed processes. This need gave way to many new solutions for Compliance Management and checking. Compliance requirements arise from legal documents and are implemented in all parts of enterprise IT, creating a business IT gap between legal texts and software implementation. Compliance solutions must bridge this gap as well as support a wide variety of Compliance requirements. To achieve these goals, we developed an integrating Compliance descriptor for Compliance modeling on the legal, requirement and technical level, incorporating arbitrary rule languages for specific types of requirements. Using a modeled descriptor a Compliance checking architecture can be configured, including specific rule checking implementations. The graphical notation of the Compliance descriptor and the formalism it’s based on are described and evaluated using a prototype as well as expert interviews. Based on evaluation results, an extension for Compliance Management in unstructured processes is outlined.
-
SOA-enabled Compliance Management: instrumenting, assessing, and analyzing service-based business processes
Service Oriented Computing and Applications, 2013Co-Authors: Carlos Rodríguez, Frank Leymann, Daniel Schleicher, Florian Daniel, Fabio Casati, Sebastian WagnerAbstract:Facilitating Compliance Management, that is, assisting a company’s Management in conforming to laws, regulations, standards, contracts, and policies, is a hot but non-trivial task. The service-oriented architecture (SOA) has evolved traditional, manual business practices into modern, service-based IT practices that ease part of the problem: the systematic definition and execution of business processes. This, in turn, facilitates the online monitoring of system behaviors and the enforcement of allowed behaviors—all ingredients that can be used to assist Compliance Management on the fly during process execution. In this paper, instead of focusing on monitoring and runtime enforcement of rules or constraints, we strive for an alternative approach to Compliance Management in SOAs that aims at assessing and improving Compliance. We propose two ingredients: (i) a model and tool to design compliant service-based processes and to instrument them in order to generate evidence of how they are executed and (ii) a reporting and analysis suite to create awareness of a company’s Compliance state and to enable understanding why and where Compliance violations have occurred. Together, these ingredients result in an approach that is close to how the real stakeholders—Compliance experts and auditors—actually assess the state of Compliance in practice and that is less intrusive than enforcing Compliance.
-
SOA-enabled Compliance Management: instrumenting, assessing, and analyzing service-based business processes
Service Oriented Computing and Applications, 2013Co-Authors: Carlos Rodríguez, Frank Leymann, Daniel Schleicher, Florian Daniel, Fabio Casati, Sebastian WagnerAbstract:Facilitating Compliance Management, that is, assisting a company's Management in conforming to laws, regulations, standards, contracts, and policies, is a hot but non-trivial task. The service-oriented architecture (SOA) has evolved traditional, manual business practices into modern, service-based IT practices that ease part of the problem: the systematic definition and execution of business processes. This, in turn, facilitates the online monitoring of system behaviors and the enforcement of allowed behaviors-all ingredients that can be used to assist Compliance Management on the fly during process execution. In this paper, instead of focusing on monitoring and runtime enforcement of rules or constraints, we strive for an alternative approach to Compliance Management in SOAs that aims at assessing and improving Compliance. We propose two ingredients: (i) a model and tool to design compliant service-based processes and to instrument them in order to generate evidence of how they are executed and (ii) a reporting and analysis suite to create awareness of a company's Compliance state and to enable understanding why and where Compliance violations have occurred. Together, these ingredients result in an approach that is close to how the real stakeholders-Compliance experts and auditors-actually assess the state of Compliance in practice and that is less intrusive than enforcing Compliance. © 2013 Springer-Verlag London
Marta Indulska - One of the best experts on this subject based on the ideXlab platform.
-
Compliance Management ontology – a shared conceptualization for research and practice in Compliance Management
Information Systems Frontiers, 2016Co-Authors: Norris Syed Abdullah, Marta Indulska, Shazia SadiqAbstract:The diversity of stakeholders in Compliance Management initiatives contributes to the challenges organisations face when managing Compliance, and consequently adds to the cost of Compliance. In particular, there is evidence that the lack of a common or shared understanding of Compliance Management concepts is a barrier to effective Compliance Management practice. Taking an information-centric view to addressing this challenge, this paper reports on the development of an ontology intended to provide a shared conceptualisation of the Compliance Management domain for various stakeholders. The ontology is based on input from domain experts and practitioners, validated and refined through eight case studies, and subsequently evaluated for its usability in practice.
-
A Study of Ontology Construction: The Case of a Compliance Management Ontology
Ontology-Based Applications for Enterprise Systems and Knowledge Management, 2013Co-Authors: Norris Syed Abdullah, Shazia Sadiq, Marta IndulskaAbstract:Ontology has been recognized, and prominently used, as tool to facilitate shared understanding (and knowledge sharing) in a particular domain. Ensuring that such an ontology is relevant to a particular domain, however, remains a challenging task to the ontology developer. Motivated by the lack of consistent holistic guidelines to assist development of ontologies that are industry-relevant, the goal of this chapter is to present such an approach. The presented approach is based on the synthesis of existing approaches and varied sources of academic and industry input. The approach follows a typical ontology development cycle and consists of incremental steps that need to be taken to assure industry-relevance of the ontology. To provide a thorough discussion of the approach, the authors utilize a previously completed ontology development project that followed the developed approach. The project was specifically aimed at developing an industry-relevant ontology for the Compliance Management domain and was based on three main inputs, namely, scholarly articles, industry expert/practitioner input and industry reports. Their experience indicates that the use of the ontology development approach promotes an ontology that is closely aligned with the needs of industry.
-
A Compliance Management ontology: Developing shared understanding through models
Lecture Notes in Computer Science, 2012Co-Authors: Norris Syed Abdullah, Shazia Sadiq, Marta IndulskaAbstract:Managing regulatory Compliance is increasingly challenging and costly for organizations world-wide. Due to the diversity of stakeholders in Compliance Management initiatives, any effort towards providing Compliance Management solutions demands a common understanding of Compliance Management concepts and practice. This paper reports on research undertaken to develop an ontology to create a shared conceptualization of the Compliance Management domain, namely CoMOn (Compliance Management Ontology). The ontology concepts are extracted from interviews and surveys of Compliance Management experts and practitioners, and refined through synthesis with leading academic literature related to Compliance Management. A semiotic framework was utilized to conduct a rigorous evaluation of CoMOn through a series of eight case studies spanning a number of industry sectors. The consensus achieved through the evaluation has positioned CoMOn as a comprehensive domain ontology for Compliance Management.
-
CAiSE - A Compliance Management ontology: developing shared understanding through models
Notes on Numerical Fluid Mechanics and Multidisciplinary Design, 2012Co-Authors: Norris Syed Abdullah, Shazia Sadiq, Marta IndulskaAbstract:Managing regulatory Compliance is increasingly challenging and costly for organizations world-wide. Due to the diversity of stakeholders in Compliance Management initiatives, any effort towards providing Compliance Management solutions demands a common understanding of Compliance Management concepts and practice. This paper reports on research undertaken to develop an ontology to create a shared conceptualization of the Compliance Management domain, namely CoMOn (Compliance Management Ontology). The ontology concepts are extracted from interviews and surveys of Compliance Management experts and practitioners, and refined through synthesis with leading academic literature related to Compliance Management. A semiotic framework was utilized to conduct a rigorous evaluation of CoMOn through a series of eight case studies spanning a number of industry sectors. The consensus achieved through the evaluation has positioned CoMOn as a comprehensive domain ontology for Compliance Management.
-
PACIS - Information systems research: Aligning to industry challenges in Management of regulatory Compliance
2010Co-Authors: Norris Syed Abdullah, Shazia Sadiq, Marta IndulskaAbstract:Managing regulatory Compliance is increasingly challenging and costly for organizations world-wide. While there is evidence that research on Compliance Management is on the increase, to facilitate industry-relevance there is a need to inform future research directions with empirical insights from practice. In this paper, we present the results of an empirical study that examines challenges in managing regulatory Compliance, derived from Australian Compliance Management practitioners. The insights from the study are complemented by results from a set of interviews with Compliance Management experts. The study reveals the consolidated views of challenges in managing regulatory Compliance as experienced by practitioners and as perceived by the experts in the Australian Compliance industry. The results indicate core challenges that are agreed on by both stakeholder groups. In particular, the speed of regulatory changes/updates, organisational culture, risk Management, scarcity of resources and a lack of value-add perception of Compliance are considered the most critical five challenges. We present a discussion of these challenges and highlight their importance for Information Systems research.
Marwane El Kharbili - One of the best experts on this subject based on the ideXlab platform.
-
business process regulatory Compliance Management solution frameworks a comparative evaluation
Asia-Pacific Conference on Conceptual Modelling, 2012Co-Authors: Marwane El KharbiliAbstract:Regulatory Compliance Management (RCM) is a problem gaining wide interest in the business process Management (BPM) community. However, research has not yet provided a non-ambiguous and agreed-upon definition of RCM, and it is hard for newcomers to this field of research to get a clear overview of available results. This paper surveys and analyzes solutions proposed in research on RCM from the perspective of BPM, and gives an insight into the current strengths and limitations of solutions to RCM applied to BPM. We extract a set of evaluation criteria on RCM elicited from the surveyed works and proceed to a comparative analysis of the latter against the identified requirements.
-
EDOC - CoReL: Policy-Based and Model-Driven Regulatory Compliance Management
2011 IEEE 15th International Enterprise Distributed Object Computing Conference, 2011Co-Authors: Marwane El Kharbili, Pierre Kelsen, Elke PulvermuellerAbstract:Regulatory Compliance Management is now widely recognized as one of the main challenges still to be efficiently dealt with in information systems. In the discipline of business process Management in particular, Compliance is considered as an important driver of the efficiency, reliability and market value of companies. It consists of ensuring that enterprise systems behave according to some guidance provided in the form of regulations. This paper gives a definition of the research problem of regulatory Compliance. We show why we expect a formal policy-based and model-driven approach to provide significant advantages in allowing enterprises to flexibly manage decision-making related to regulatory Compliance. For this purpose, we contribute CoReL, a domain-specific modeling language for representing Compliance requirements that has a graphical concrete syntax. Informal semantics of CoReL are introduced and its use is illustrated on an example. CoReL allows to leverage business process Compliance modeling and checking, enhancing it with regard to, among other dimensions, user-friendliness, genericity, and traceability.
-
MobIS Workshops - Policy-Based Semantic Compliance Checking for Business Process Management.
2008Co-Authors: Marwane El Kharbili, Sebastian SteinAbstract:Compliance Management, risk analysis, and auditing are disciplines that are critical for large scale distributed enterprise systems. The way these complex systems are developed and deployed makes the Management and enforcement of enterprise goals or policies a hard task. This is also true for Compliance Management of business processes (BPs). Such an observation is emphasized if we give Compliance Management the scope of the whole enterprise model. In this paper we explain our approach to modeling Compliance measures based on policies and present a framework for managing and enforcing Compliance policies on enterprise models and BPs. We discuss our ideas in the context of a semantically-enabled environment and discuss why leveraging Compliance checking to a semantic level enhances Compliance Management.