首页> 外文期刊>Service Oriented Computing and Applications >SOA-enabled compliance management: instrumenting, assessing, and analyzing service-based business processes
【24h】

SOA-enabled compliance management: instrumenting, assessing, and analyzing service-based business processes

机译:支持SOA的合规性管理:仪器化,评估和分析基于服务的业务流程

获取原文
获取原文并翻译 | 示例

摘要

Facilitating compliance management, that is, assisting a company’s management in conforming to laws, regulations, standards, contracts, and policies, is a hot but non-trivial task. The service-oriented architecture (SOA) has evolved traditional, manual business practices into modern, service-based IT practices that ease part of the problem: the systematic definition and execution of business processes. This, in turn, facilitates the online monitoring of system behaviors and the enforcement of allowed behaviors—all ingredients that can be used to assist compliance management on the fly during process execution. In this paper, instead of focusing on monitoring and runtime enforcement of rules or constraints, we strive for an alternative approach to compliance management in SOAs that aims at assessing and improving compliance. We propose two ingredients: (i) a model and tool to design compliant service-based processes and to instrument them in order to generate evidence of how they are executed and (ii) a reporting and analysis suite to create awareness of a company’s compliance state and to enable understanding why and where compliance violations have occurred. Together, these ingredients result in an approach that is close to how the real stakeholders—compliance experts and auditors—actually assess the state of compliance in practice and that is less intrusive than enforcing compliance.
机译:促进合规性管理,即协助公司的管理层遵守法律,法规,标准,合同和政策,是一项艰巨而艰巨的任务。面向服务的体系结构(SOA)已将传统的手动业务实践演变为基于服务的现代IT实践,从而缓解了部分问题:系统定义和执行业务流程。反过来,这有利于系统行为的在线监视和所允许行为的执行-所有可用于在流程执行过程中快速进行合规性管理的要素。在本文中,我们将重点放在评估和改善合规性上,而不是致力于监视或规则或约束的运行时强制执行,而是为SOA中的合规性管理寻求一种替代方法。我们提出两个要素:(i)一种模型和工具,用于设计基于服务的合规流程并对其进行检测,以便生成有关其执行方式的证据;(ii)报告和分析套件,以使人们了解公司的合规状态并使人们了解为什么以及在何处发生了合规违规。这些要素共同形成了一种方法,该方法与真正的利益相关者(合规专家和审计师)如何在实践中实际评估合规状态相比较,并且不像执行合规那样具有侵入性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号