Rubacon: Automated Support for Model-based Compliance Engineering

被引:0
|
作者
Hoehn, Sebastian [1 ]
Juerjens, Jan [1 ]
机构
[1] Inst Comp Sci & Social Studies, D-79098 Freiburg, Germany
关键词
Access Control; Security Analysis; User Permissions; UMLsec;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Compliance frameworks, laws and regulations such as Sarbanes Oxley, Basel II, Solvency II, HIPAA etc. demand from companies in a more and more rigorous way to demonstrate that their organisation, processes and supporting IT landscape implement and follow a set of guidelines at differing levels of abstraction. This work aims to contribute to a software engineering process which is driven by security, risk and compliance management considerations. We concentrate on a part of this approach that focusses on the question how one can use software engineering methods and tools to enforce that the configuration of a system enforces the security policies that arise from business compliance regulations. We present tool support for Model-based Compliance Engineering, i.e. for the model-based development and analysis of software configurations that ensures compliance with security policies. It allows one to check UML models of business applications and their configuration data for adherence to security policies and compliance requirements. The tool is based on standardized data formats, such as UML and XML, which makes its integration into existing business architectures as efficient as possible.
引用
收藏
页码:875 / 878
页数:4
相关论文
共 50 条
  • [21] Integrating Computational Design Support in Model-Based Systems Engineering Using Model Transformations
    Rigger, Eugen
    Raedler, Simon
    Stankovic, Tino
    [J]. PRODUCT LIFECYCLE MANAGEMENT PLM IN TRANSITION TIMES: THE PLACE OF HUMANS AND TRANSFORMATIVE TECHNOLOGIES, PLM 2022, 2023, 667 : 186 - 195
  • [22] Model-based security engineering
    Juerjens, Jan
    [J]. ICE-B 2006: Proceedings of the International Conference on e-Business, 2006, : IS23 - IS29
  • [23] Model-based security engineering
    Juerjens, Jan
    [J]. SIGMAP 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND MULTIMEDIA APPLICATIONS, 2006, : IS23 - IS29
  • [24] Model-based security engineering
    Juerjens, Jan
    [J]. SECRYPT 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2006, : IS23 - IS29
  • [25] Patterns in model-based engineering
    Sinnig, D
    Gaffar, A
    Reichart, D
    Forbrig, P
    Seffah, A
    [J]. COMPUTER-AIDED DESIGN OF USER INTERFACES IV, 2005, : 197 - 210
  • [26] PROCESS MODEL-BASED ENGINEERING
    COTT, BJ
    DURHAM, RG
    LEE, PL
    SULLIVAN, GR
    [J]. COMPUTERS & CHEMICAL ENGINEERING, 1989, 13 (09) : 973 - 984
  • [27] Model-based transcriptome engineering
    Brent, Michael
    [J]. ACM-BCB' 2017: PROCEEDINGS OF THE 8TH ACM INTERNATIONAL CONFERENCE ON BIOINFORMATICS, COMPUTATIONAL BIOLOGY,AND HEALTH INFORMATICS, 2017, : 636 - 636
  • [28] Model-based security engineering
    Juerjens, Jan
    [J]. WINSYS 2006: Proceedings of the International Conference on Wireless Information Networks and Systems, 2006, : IS23 - IS29
  • [29] A Model-Based Systems Engineering Approach to Support Continuous Validation in PGE - Product Generation Engineering
    Mandel, Constantin
    Boening, Jannis
    Behrendt, Matthias
    Albers, Albert
    [J]. 7TH IEEE INTERNATIONAL SYMPOSIUM ON SYSTEMS ENGINEERING (IEEE ISSE 2021), 2021,
  • [30] Model-Based Systems Engineering for Machine Tools and Production Systems (Model-Based Production Engineering)
    Kuebler, Karl
    Scheifele, Stefan
    Scheifele, Christian
    Riedel, Oliver
    [J]. 4TH INTERNATIONAL CONFERENCE ON SYSTEM-INTEGRATED INTELLIGENCE: INTELLIGENT, FLEXIBLE AND CONNECTED SYSTEMS IN PRODUCTS AND PRODUCTION, 2018, 24 : 216 - 221