Normative requirements for regulatory compliance: An abstract formal framework
نویسندگان
چکیده
By definition, regulatory rules (in legal context called norms) intend to achieve specific behaviour from business processes, and might be relevant to the whole or part of a business process. They can impose conditions on different aspects of process models, e.g., control-flow, data and resources etc. Based on the rules sets, norms can be classified into various classes and sub-classes according to their effects. This paper presents an abstract framework consisting of a list of norms and a generic compliance checking approach on the idea of (possible) execution of processes. The proposed framework is independent of any existing formalism, and provides a conceptually rich and exhaustive ontology and semantics of norms needed for business process compliance checking. Apart from the other uses, the proposed framework can be used to compare different compliance management frameworks (CMFs).
منابع مشابه
Towards A Formal Framework for Business Process Compliance
The advent of regulatory compliance requirements such as Sarbanes Oxley Act has forced enterprises to set up a process for managing an effective internal controls system on business processes. In this paper a formal framework consisting of a formal definition of business process compliance and a set of properties is proposed. A system implementing the formalization must satisfy the given proper...
متن کاملInformation Technology An Abstract Normative Framework for Business Process Compliance
In this paper we propose an abstract framework to model the deontic notions relevant for business process compliance. In particular, we provide a comprehensive classification of the obligation types relevant for modelling whether a process is compliant, and we describe their semantics in terms of execution traces.
متن کاملBusiness Process Compliance: An Abstract Normative Framework
In this paper we propose an abstract framework to model the deontic notions relevant for business process compliance. In particular, we provide a comprehensive classification of the obligation types relevant for modelling whether a process is compliant, and we describe their semantics in terms of execution traces.
متن کاملDevelopment of a Normative Package for Safety-Critical Software Using Formal Regulatory Requirements
The important tasks in requirement engineering are resolving requirements inconsistencies between regulators and developers of safety-critical computer systems, and the validation of regulatory requirements. This paper proposes a new approach to the regulatory process, including formulating requirements and elaborating methods for their assessment. We address the differences between prescriptiv...
متن کاملFormal Contract Logic Based Patterns for Facilitating Compliance Checking against ISO 26262
ISO 26262 demands a confirmation review of the safety plan, which includes the compliance checking of planned processes against safety requirements. Formal Contract Logic (FCL), a logic-based language stemming from business compliance, provides means to formalize normative requirements enabling automatic compliance checking. However, formalizing safety requirements in FCL requires skills, which...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Information Systems Frontiers
دوره 18 شماره
صفحات -
تاریخ انتشار 2016