Rubacon: Automated Support for Model-based Compliance Engineering

被引:0
|
作者
Hoehn, Sebastian [1 ]
Juerjens, Jan [1 ]
机构
[1] Inst Comp Sci & Social Studies, D-79098 Freiburg, Germany
关键词
Access Control; Security Analysis; User Permissions; UMLsec;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Compliance frameworks, laws and regulations such as Sarbanes Oxley, Basel II, Solvency II, HIPAA etc. demand from companies in a more and more rigorous way to demonstrate that their organisation, processes and supporting IT landscape implement and follow a set of guidelines at differing levels of abstraction. This work aims to contribute to a software engineering process which is driven by security, risk and compliance management considerations. We concentrate on a part of this approach that focusses on the question how one can use software engineering methods and tools to enforce that the configuration of a system enforces the security policies that arise from business compliance regulations. We present tool support for Model-based Compliance Engineering, i.e. for the model-based development and analysis of software configurations that ensures compliance with security policies. It allows one to check UML models of business applications and their configuration data for adherence to security policies and compliance requirements. The tool is based on standardized data formats, such as UML and XML, which makes its integration into existing business architectures as efficient as possible.
引用
收藏
页码:875 / 878
页数:4
相关论文
共 50 条
  • [1] A model-based approach to support privacy compliance
    Alshammari, Majed
    Simpson, Andrew
    [J]. INFORMATION AND COMPUTER SECURITY, 2018, 26 (04) : 437 - 453
  • [2] Model-based engineering for automated production systems
    Fay, Alexander
    Witte, Martin Emmerich
    Figalist, Helmut
    [J]. AT-AUTOMATISIERUNGSTECHNIK, 2018, 66 (05) : 357 - 359
  • [3] Analysis of SLA Compliance in the Cloud: An Automated, Model-based Approach
    de Boer, Frank S.
    Giachino, Elena
    de Gouw, Stijn
    Haehnle, Reiner
    Johnsen, Einar Broch
    Laneve, Cosimo
    Pun, Ka, I
    Zavattaro, Gianluigi
    [J]. ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2019, (302): : 1 - 15
  • [4] Toward Model-Based Requirement Engineering Tool Support
    Reza, Hassan
    Sehgal, Rashmi
    Straub, Jeremy
    Alexander, Nicholas
    [J]. 2017 IEEE AEROSPACE CONFERENCE, 2017,
  • [5] Model-based support for business re-engineering
    Jarzabek, S
    Ling, TW
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 1996, 38 (05) : 355 - 374
  • [6] Application of Model-Based Systems Engineering Concepts to Support Mission Engineering
    Beery, Paul
    Paulo, Eugene
    [J]. SYSTEMS, 2019, 7 (03):
  • [7] Automated Identification of Valid Model Networks Using Model-Based Systems Engineering
    Berges, Julius Moritz
    Spuetz, Kathrin
    Jacobs, Georg
    Kowalski, Julia
    Zerwas, Thilo
    Berroth, Joerg
    Konrad, Christian
    [J]. SYSTEMS, 2022, 10 (06):
  • [8] Model-Based Systems Engineering in Support of Complex Systems Development
    Topper, J. Stephen
    Horner, Nathaniel C.
    [J]. JOHNS HOPKINS APL TECHNICAL DIGEST, 2013, 32 (01): : 419 - 432
  • [9] INTEGRATED MODELING AND ANALYSIS TO SUPPORT MODEL-BASED SYSTEMS ENGINEERING
    Kim, Hongman
    Fried, David
    Menegay, Peter
    Soremekun, Grant
    [J]. PROCEEDINGS OF THE ASME 11TH BIENNIAL CONFERENCE ON ENGINEERING SYSTEMS DESIGN AND ANALYSIS, 2012, VOL 3, 2012, : 833 - 839
  • [10] Towards Language Support for Model-based Security Policy Engineering
    Amthor, Peter
    Schlegel, Marius
    [J]. PROCEEDINGS OF THE 17TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (SECRYPT), VOL 1, 2020, : 513 - 521