Rubacon: Automated Support for Model-based Compliance Engineering

被引:0
|
作者
Hoehn, Sebastian [1 ]
Juerjens, Jan [1 ]
机构
[1] Inst Comp Sci & Social Studies, D-79098 Freiburg, Germany
关键词
Access Control; Security Analysis; User Permissions; UMLsec;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Compliance frameworks, laws and regulations such as Sarbanes Oxley, Basel II, Solvency II, HIPAA etc. demand from companies in a more and more rigorous way to demonstrate that their organisation, processes and supporting IT landscape implement and follow a set of guidelines at differing levels of abstraction. This work aims to contribute to a software engineering process which is driven by security, risk and compliance management considerations. We concentrate on a part of this approach that focusses on the question how one can use software engineering methods and tools to enforce that the configuration of a system enforces the security policies that arise from business compliance regulations. We present tool support for Model-based Compliance Engineering, i.e. for the model-based development and analysis of software configurations that ensures compliance with security policies. It allows one to check UML models of business applications and their configuration data for adherence to security policies and compliance requirements. The tool is based on standardized data formats, such as UML and XML, which makes its integration into existing business architectures as efficient as possible.
引用
收藏
页码:875 / 878
页数:4
相关论文
共 50 条
  • [31] Foundations for model-based systems engineering and model-based safety assessment
    Rauzy, Antoine B.
    Haskins, Cecilia
    [J]. SYSTEMS ENGINEERING, 2019, 22 (02) : 146 - 155
  • [32] Support of the Useware-Engineering Process by Using a Model-based Tool Chain
    Meixner, Gerrit
    Goerlich, Daniel
    [J]. ATP EDITION, 2008, (12): : 44 - 48
  • [33] Model-Based Design to support Complex Systems implementation as a result of Reverse Engineering
    Foglesong, Tim
    Arlitt, Ryan
    Stone, Rob
    Parmigiani, John
    [J]. 2015 INTERNATIONAL CONFERENCE ON COMPLEX SYSTEMS ENGINEERING (ICCSE), 2015,
  • [34] CONCURRENT ENGINEERING APPROACH TO SUPPORT CIM REFERENCE MODEL-BASED FMS DESIGN
    KOVACS, GL
    MEZGAR, I
    NACSA, J
    [J]. COMPUTER INTEGRATED MANUFACTURING SYSTEMS, 1994, 7 (01): : 17 - 27
  • [35] Capturing experimental design insights in support of the model-based system engineering approach
    MacCalman, Alex
    Kwak, Hyangshim
    McDonald, Mary
    Upton, Stephen
    [J]. 2015 CONFERENCE ON SYSTEMS ENGINEERING RESEARCH, 2015, 44 : 315 - 324
  • [36] Challenges in Developing a Method to Support the Adoption of a Model-Based Systems Engineering Methodology
    Kozak, Lea
    Bonjour, Eric
    Mayer, Frederique
    Micaelli, Jean-Pierre
    [J]. INSIGHT, 2023, 26 (04): : 15 - 17
  • [37] Model-Based Automated Accessibility Testing
    Brajnik, Giorgio
    Pighin, Chiara
    Fabbro, Sara
    [J]. ASSETS'15: PROCEEDINGS OF THE 17TH INTERNATIONAL ACM SIGACCESS CONFERENCE ON COMPUTERS & ACCESSIBILITY, 2015, : 319 - 320
  • [38] DEVELOPMENT OF AN AUTOMATED GUIDED VEHICLE CONTROLLER USING A MODEL-BASED SYSTEMS ENGINEERING APPROACH
    Ferreira, T.
    Gorlach, I. A.
    [J]. SOUTH AFRICAN JOURNAL OF INDUSTRIAL ENGINEERING, 2016, 27 (02): : 206 - 217
  • [39] Model-Based Systems Engineering Tool-Chain for Automated Parameter Value Selection
    Lu, Jinzhi
    Chen, Dejiu
    Wang, Guoxin
    Kiritsis, Dimitris
    Torngren, Martin
    [J]. IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2022, 52 (04): : 2333 - 2347
  • [40] ASPICE compliance development of Cyber-Physical Systems by using Model-Based Systems Engineering
    Fanmuy, Gauthier
    Hassan, Bassem
    [J]. INCOSE International Symposium, 2023, 33 (01) : 416 - 430