SlideShare a Scribd company logo
An Integrated Solution for Runtime Compliance Governance in SOA Aliaksandr Birukou , Vincenzo D’Andrea,  Frank Leymann, Ja- cek Serafinski, Patricia Silveira, Steve Strauch, Marek Tluczek COMPAS Compliance-driven Models, Languages, and Architectures for Services "The COMPAS project will design and implement novel models, languages, and an architectural framework to ensure dynamic and on-going compliance of software services to business regulations and stated user service-requirements. COMPAS will use model-driven techniques, domain-specific languages, and service-oriented infrastructure software to enable organizations developing business compliance solutions easier and faster“ http://www.compas-ict.eu
Compliance ,[object Object],Compliant ? Sarbanes-Oxley Act Basel III Security policy
Do I care about compliance ? Image from http://www.blogfinanza.com/wp-content/uploads/2010/09/banca1.jpg ECB Image from  http://www.exponent.com/Nuclear-Plant-Services-Capabilities/ AEG GSE http://altocasertano.files.wordpress.com/2007/12/rifiuti1.jpg Ministry of Natural Resources http://www.seebiz.eu/hr/tvrtke/transport/pevec-transporti-u-stecaju,65063.html Ministry of transportation Legge n.6 06/02/2009 Legge n. 152 13/08/2010 Sarbanes-Oxley Act Basel III Direttiva 2010/40/UE Direttiva 2009/548/CE Decreto 10/09/2010 Direttiva 2008/763/CE
Not yet convinced?
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],GRC Spending forecast Source: AMR Research, 2009 Compliance market
2010 GRC software investments priorities Source: AMR Research, 2009 18% Compliance management 17% 16% Business process management 15% Continuous control monitoring Security (internal/external) Risk management Sustainability software Documents/record management Reporting 14% 12% 11% 10% Investments priorities
About COMPAS ,[object Object],[object Object],[object Object],[object Object],[object Object]
Case study: Advanced Telecom Services Internet Internet ... Audio providers Video providers MVNO company AudioSport License FootballGames License EU MVNO directives Austria Telecommunication Act 2003 Bob Alice Carol Customer contracts
Problem ,[object Object],[object Object],[object Object],AudioSport License FootballGames License EU MVNO directives Austria Telecommunication Act 2003 Customer contracts
Compliance governance in COMPAS Internalization Design Regulations, business contracts, standards Internal  policies Business  processes Events Execution  data Internal evaluation Business  execution Auditor Runtime compliance governance
Compliance Domains in COMPAS Regulations Licenses QoS
1. Selecting compliance sources and requirements Pay-per-view plan When  MVNO  company subscribes for the Pay-per-view plan it has to pay  29.90 euro first  and  then receive 300   streams from the media supplier Composition permission VideoSport  can only have audio streams from  AudioSport Availability The WatchMe service must deliver a valid URL at least in 90% of requests per customer subscription.  VideoSport License FootballGames License EU MVNO directives Austria Telecommunication Act 2003 Customer contracts
1. From high-level DSLs to code Code generation
2. Process (re-)design ,[object Object],[object Object],Apache ODE Process Deployed Event BPEL file XPath Trace Trace BPEL file Traceability
3. Monitoring. Complex Event Processing
3. Monitoring -  ETL and Data Warehouse
4.Informing on the current state of compliance Compliance indicators Different types of compliance Details on compliance
4.Informing on the current state of compliance
Current Practice vs. COMPAS Approach ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Pros ,[object Object],[object Object],[object Object],Cons ,[object Object],[object Object]
Future work ,[object Object],[object Object],[object Object],[object Object],[object Object],Learn more about our approach
More about COMPAS at ICSOC’2010 ,[object Object],[object Object],[object Object],[object Object],[object Object],Tomorrow
COMPAS Dissemination Workshop ,[object Object],[object Object]
Questions? Thanks for your attention! Contacts ,[object Object],[object Object],[object Object],[object Object]

More Related Content

Viewers also liked

2011 Small Business Presentation for HAUL
2011 Small Business Presentation for HAUL2011 Small Business Presentation for HAUL
2011 Small Business Presentation for HAUL
Erin McClarty
 
PCQuest CIO Tech Priorities Survey 2014
PCQuest CIO Tech Priorities Survey 2014PCQuest CIO Tech Priorities Survey 2014
PCQuest CIO Tech Priorities Survey 2014Anil Chopra
 
12
1212
Escala F F
Escala  F FEscala  F F
Escala F Falondra
 
Measuring the potential of viral stuff
Measuring the potential of viral stuffMeasuring the potential of viral stuff
Measuring the potential of viral stuffBruno Mendonça
 
Choose Respect Final Assessment
Choose Respect Final AssessmentChoose Respect Final Assessment
Choose Respect Final Assessment
guest78c6cc12
 
Tonteras de niño, relevancia creativa de adulto
Tonteras de niño, relevancia creativa de adultoTonteras de niño, relevancia creativa de adulto
Tonteras de niño, relevancia creativa de adulto
Óscar Solano Brenes
 
Electrical characteristics
Electrical characteristicsElectrical characteristics
Electrical characteristicsdijahapple
 
College chapter 1 2
College chapter 1 2College chapter 1 2
College chapter 1 2gmaidekamido
 
Assistive Technology Webquest
Assistive Technology WebquestAssistive Technology Webquest
Assistive Technology Webquestangtapper
 
Kotu2009 juha kreus kriisiviestintä 91009
Kotu2009 juha kreus kriisiviestintä 91009Kotu2009 juha kreus kriisiviestintä 91009
Kotu2009 juha kreus kriisiviestintä 91009
Juha Kreus
 
10 Things A Non-profit Should Include In Its Contracts
10 Things A Non-profit Should Include In Its Contracts10 Things A Non-profit Should Include In Its Contracts
10 Things A Non-profit Should Include In Its Contracts
Erin McClarty
 
Global tax 50 2016 international tax review
Global tax 50 2016   international tax reviewGlobal tax 50 2016   international tax review
Global tax 50 2016 international tax review
Pallavi M
 

Viewers also liked (20)

2011 Small Business Presentation for HAUL
2011 Small Business Presentation for HAUL2011 Small Business Presentation for HAUL
2011 Small Business Presentation for HAUL
 
PCQuest CIO Tech Priorities Survey 2014
PCQuest CIO Tech Priorities Survey 2014PCQuest CIO Tech Priorities Survey 2014
PCQuest CIO Tech Priorities Survey 2014
 
Chapter 2 4
Chapter 2 4Chapter 2 4
Chapter 2 4
 
12
1212
12
 
Escala F F
Escala  F FEscala  F F
Escala F F
 
Measuring the potential of viral stuff
Measuring the potential of viral stuffMeasuring the potential of viral stuff
Measuring the potential of viral stuff
 
Choose Respect Final Assessment
Choose Respect Final AssessmentChoose Respect Final Assessment
Choose Respect Final Assessment
 
Tonteras de niño, relevancia creativa de adulto
Tonteras de niño, relevancia creativa de adultoTonteras de niño, relevancia creativa de adulto
Tonteras de niño, relevancia creativa de adulto
 
E Learning Benefits
E Learning BenefitsE Learning Benefits
E Learning Benefits
 
Russell Simmons Ppt
Russell Simmons PptRussell Simmons Ppt
Russell Simmons Ppt
 
Electrical characteristics
Electrical characteristicsElectrical characteristics
Electrical characteristics
 
1 6 Attempt 2
1 6 Attempt 21 6 Attempt 2
1 6 Attempt 2
 
Chapter 2 3
Chapter 2 3Chapter 2 3
Chapter 2 3
 
College 1 4
College 1 4College 1 4
College 1 4
 
Overview
OverviewOverview
Overview
 
College chapter 1 2
College chapter 1 2College chapter 1 2
College chapter 1 2
 
Assistive Technology Webquest
Assistive Technology WebquestAssistive Technology Webquest
Assistive Technology Webquest
 
Kotu2009 juha kreus kriisiviestintä 91009
Kotu2009 juha kreus kriisiviestintä 91009Kotu2009 juha kreus kriisiviestintä 91009
Kotu2009 juha kreus kriisiviestintä 91009
 
10 Things A Non-profit Should Include In Its Contracts
10 Things A Non-profit Should Include In Its Contracts10 Things A Non-profit Should Include In Its Contracts
10 Things A Non-profit Should Include In Its Contracts
 
Global tax 50 2016 international tax review
Global tax 50 2016   international tax reviewGlobal tax 50 2016   international tax review
Global tax 50 2016 international tax review
 

Similar to An Integrated Solution for Runtime Compliance Governance in SOA

IMS Integration Challenges (2010)
IMS Integration Challenges (2010)IMS Integration Challenges (2010)
IMS Integration Challenges (2010)
Marc Jadoul
 
SOA e IMS (NGN)
SOA e IMS (NGN)SOA e IMS (NGN)
SOA e IMS (NGN)
Davi Silva
 
Infonova Telco1 0 2 0 Bss Rel 6 Introduction V10 Timpact
Infonova Telco1 0  2 0 Bss Rel 6 Introduction V10 TimpactInfonova Telco1 0  2 0 Bss Rel 6 Introduction V10 Timpact
Infonova Telco1 0 2 0 Bss Rel 6 Introduction V10 Timpact
fantastic1
 
Cuae Business Values V 1.8.2
Cuae   Business Values V 1.8.2Cuae   Business Values V 1.8.2
Cuae Business Values V 1.8.2Chinmoy Misra
 
IBM - Video Communications - An Enterprise Perspective
IBM - Video Communications - An Enterprise PerspectiveIBM - Video Communications - An Enterprise Perspective
IBM - Video Communications - An Enterprise PerspectiveIMTC
 
Challenges opportunities 2017 onwards v5.0.
Challenges opportunities 2017   onwards v5.0.Challenges opportunities 2017   onwards v5.0.
Challenges opportunities 2017 onwards v5.0.
frankjoh
 
Juan-Camacho-1.pdf
Juan-Camacho-1.pdfJuan-Camacho-1.pdf
Juan-Camacho-1.pdf
DKChaitanyarajSingh
 
Advanced Advertising Standards in the Cable Space
Advanced Advertising Standards in the Cable SpaceAdvanced Advertising Standards in the Cable Space
Advanced Advertising Standards in the Cable Space
Sigma Systems
 
Advanced Advertising Standards in the Cable Space
Advanced Advertising Standards in the Cable SpaceAdvanced Advertising Standards in the Cable Space
Advanced Advertising Standards in the Cable SpaceSigma Systems
 
OEM - запчасти на проводе
OEM - запчасти на проводеOEM - запчасти на проводе
OEM - запчасти на проводе
Sergey Zhdanov
 
Overview of Selected Current MPEG Activities
Overview of Selected Current MPEG ActivitiesOverview of Selected Current MPEG Activities
Overview of Selected Current MPEG ActivitiesAlpen-Adria-Universität
 
Overview of Selected Current MPEG Activities
Overview of Selected Current MPEG ActivitiesOverview of Selected Current MPEG Activities
Overview of Selected Current MPEG ActivitiesAlpen-Adria-Universität
 
Rep Presentation V4 13
Rep Presentation V4 13Rep Presentation V4 13
Rep Presentation V4 13lyndonroberts
 
The Architectural Models Of UC
The Architectural Models Of UCThe Architectural Models Of UC
The Architectural Models Of UC
Ronald Gruia
 
AT_2006-07_IMS_Accenture.pdf
AT_2006-07_IMS_Accenture.pdfAT_2006-07_IMS_Accenture.pdf
AT_2006-07_IMS_Accenture.pdf
MahmudChowdhury15
 
Ascom workshop qoe qos-newparadigm_4g
Ascom workshop qoe qos-newparadigm_4gAscom workshop qoe qos-newparadigm_4g
Ascom workshop qoe qos-newparadigm_4g
Adrian Hall
 
A Model Of An Integrated Unified Communication Network Using Public Switched ...
A Model Of An Integrated Unified Communication Network Using Public Switched ...A Model Of An Integrated Unified Communication Network Using Public Switched ...
A Model Of An Integrated Unified Communication Network Using Public Switched ...
Becky Gilbert
 

Similar to An Integrated Solution for Runtime Compliance Governance in SOA (20)

IMS Integration Challenges (2010)
IMS Integration Challenges (2010)IMS Integration Challenges (2010)
IMS Integration Challenges (2010)
 
SOA e IMS (NGN)
SOA e IMS (NGN)SOA e IMS (NGN)
SOA e IMS (NGN)
 
Infonova Telco1 0 2 0 Bss Rel 6 Introduction V10 Timpact
Infonova Telco1 0  2 0 Bss Rel 6 Introduction V10 TimpactInfonova Telco1 0  2 0 Bss Rel 6 Introduction V10 Timpact
Infonova Telco1 0 2 0 Bss Rel 6 Introduction V10 Timpact
 
Cuae Business Values V 1.8.2
Cuae   Business Values V 1.8.2Cuae   Business Values V 1.8.2
Cuae Business Values V 1.8.2
 
IBM - Video Communications - An Enterprise Perspective
IBM - Video Communications - An Enterprise PerspectiveIBM - Video Communications - An Enterprise Perspective
IBM - Video Communications - An Enterprise Perspective
 
Ecosystem Building for Hong Kong's IT Industry
Ecosystem Building for Hong Kong's IT IndustryEcosystem Building for Hong Kong's IT Industry
Ecosystem Building for Hong Kong's IT Industry
 
Challenges opportunities 2017 onwards v5.0.
Challenges opportunities 2017   onwards v5.0.Challenges opportunities 2017   onwards v5.0.
Challenges opportunities 2017 onwards v5.0.
 
Juan-Camacho-1.pdf
Juan-Camacho-1.pdfJuan-Camacho-1.pdf
Juan-Camacho-1.pdf
 
Craft2.ppt
Craft2.pptCraft2.ppt
Craft2.ppt
 
Craft2.ppt
Craft2.pptCraft2.ppt
Craft2.ppt
 
Advanced Advertising Standards in the Cable Space
Advanced Advertising Standards in the Cable SpaceAdvanced Advertising Standards in the Cable Space
Advanced Advertising Standards in the Cable Space
 
Advanced Advertising Standards in the Cable Space
Advanced Advertising Standards in the Cable SpaceAdvanced Advertising Standards in the Cable Space
Advanced Advertising Standards in the Cable Space
 
OEM - запчасти на проводе
OEM - запчасти на проводеOEM - запчасти на проводе
OEM - запчасти на проводе
 
Overview of Selected Current MPEG Activities
Overview of Selected Current MPEG ActivitiesOverview of Selected Current MPEG Activities
Overview of Selected Current MPEG Activities
 
Overview of Selected Current MPEG Activities
Overview of Selected Current MPEG ActivitiesOverview of Selected Current MPEG Activities
Overview of Selected Current MPEG Activities
 
Rep Presentation V4 13
Rep Presentation V4 13Rep Presentation V4 13
Rep Presentation V4 13
 
The Architectural Models Of UC
The Architectural Models Of UCThe Architectural Models Of UC
The Architectural Models Of UC
 
AT_2006-07_IMS_Accenture.pdf
AT_2006-07_IMS_Accenture.pdfAT_2006-07_IMS_Accenture.pdf
AT_2006-07_IMS_Accenture.pdf
 
Ascom workshop qoe qos-newparadigm_4g
Ascom workshop qoe qos-newparadigm_4gAscom workshop qoe qos-newparadigm_4g
Ascom workshop qoe qos-newparadigm_4g
 
A Model Of An Integrated Unified Communication Network Using Public Switched ...
A Model Of An Integrated Unified Communication Network Using Public Switched ...A Model Of An Integrated Unified Communication Network Using Public Switched ...
A Model Of An Integrated Unified Communication Network Using Public Switched ...
 

More from Aliaksandr Birukou

Publishing conference proceedings internationally: how does it work
Publishing conference proceedings internationally: how does it workPublishing conference proceedings internationally: how does it work
Publishing conference proceedings internationally: how does it work
Aliaksandr Birukou
 
Технические аспекты публикации на нескольких языках – как правильно связать DOI
Технические аспекты публикации на нескольких языках – как правильно связать DOIТехнические аспекты публикации на нескольких языках – как правильно связать DOI
Технические аспекты публикации на нескольких языках – как правильно связать DOI
Aliaksandr Birukou
 
Conference Identity: persistent identifiers for conferences
Conference Identity: persistent identifiers for conferencesConference Identity: persistent identifiers for conferences
Conference Identity: persistent identifiers for conferences
Aliaksandr Birukou
 
Springer LOD conference portal. Demo paper - screenshots
Springer LOD conference portal. Demo paper - screenshotsSpringer LOD conference portal. Demo paper - screenshots
Springer LOD conference portal. Demo paper - screenshots
Aliaksandr Birukou
 
PersistentIDs and CrossMark for Conference Proceedings
PersistentIDs and CrossMark for Conference ProceedingsPersistentIDs and CrossMark for Conference Proceedings
PersistentIDs and CrossMark for Conference Proceedings
Aliaksandr Birukou
 
Publishing conference proceedings internationally: Tips and tricks
Publishing conference proceedings internationally: Tips and tricksPublishing conference proceedings internationally: Tips and tricks
Publishing conference proceedings internationally: Tips and tricks
Aliaksandr Birukou
 
Linked Open Data about Springer Nature conferences. The story so far
Linked Open Data about Springer Nature conferences. The story so farLinked Open Data about Springer Nature conferences. The story so far
Linked Open Data about Springer Nature conferences. The story so far
Aliaksandr Birukou
 
Creating a dataset of peer review in computer science conferences published b...
Creating a dataset of peer review in computer science conferences published b...Creating a dataset of peer review in computer science conferences published b...
Creating a dataset of peer review in computer science conferences published b...
Aliaksandr Birukou
 
Linked Data Initiatives at Springer Verlag
Linked Data Initiatives at Springer Verlag Linked Data Initiatives at Springer Verlag
Linked Data Initiatives at Springer Verlag
Aliaksandr Birukou
 
Diversity-aware search for people, content, events AND Diversity-aware hiring...
Diversity-aware search for people, content, events AND Diversity-aware hiring...Diversity-aware search for people, content, events AND Diversity-aware hiring...
Diversity-aware search for people, content, events AND Diversity-aware hiring...
Aliaksandr Birukou
 
Diversity-aware search for people, content, events AND Diversity-aware hiring...
Diversity-aware search for people, content, events AND Diversity-aware hiring...Diversity-aware search for people, content, events AND Diversity-aware hiring...
Diversity-aware search for people, content, events AND Diversity-aware hiring...
Aliaksandr Birukou
 
20101112 librinnovando liquidpub
20101112 librinnovando liquidpub20101112 librinnovando liquidpub
20101112 librinnovando liquidpub
Aliaksandr Birukou
 
Is peer review any good? A quantitative analysis of peer review
Is peer review any good? A quantitative analysis of peer reviewIs peer review any good? A quantitative analysis of peer review
Is peer review any good? A quantitative analysis of peer review
Aliaksandr Birukou
 
Liquid Journals - Intro and RoadMap
Liquid Journals - Intro and RoadMapLiquid Journals - Intro and RoadMap
Liquid Journals - Intro and RoadMap
Aliaksandr Birukou
 
Liquid Journals. Overview. How social computing and liquid knowledge will sha...
Liquid Journals. Overview. How social computing and liquid knowledge will sha...Liquid Journals. Overview. How social computing and liquid knowledge will sha...
Liquid Journals. Overview. How social computing and liquid knowledge will sha...
Aliaksandr Birukou
 
Automated Experimentation in Social Informatics
Automated Experimentation in Social InformaticsAutomated Experimentation in Social Informatics
Automated Experimentation in Social Informatics
Aliaksandr Birukou
 
General presentation of the LiquidPub project
General presentation of the LiquidPub projectGeneral presentation of the LiquidPub project
General presentation of the LiquidPub project
Aliaksandr Birukou
 
General presentation of the LiquidPub project
General presentation of the LiquidPub projectGeneral presentation of the LiquidPub project
General presentation of the LiquidPub project
Aliaksandr Birukou
 
Peer Review in the LiquidPub project
Peer Review in the LiquidPub projectPeer Review in the LiquidPub project
Peer Review in the LiquidPub project
Aliaksandr Birukou
 
LiquidPub: Services at Service of Science
LiquidPub: Services at Service of ScienceLiquidPub: Services at Service of Science
LiquidPub: Services at Service of Science
Aliaksandr Birukou
 

More from Aliaksandr Birukou (20)

Publishing conference proceedings internationally: how does it work
Publishing conference proceedings internationally: how does it workPublishing conference proceedings internationally: how does it work
Publishing conference proceedings internationally: how does it work
 
Технические аспекты публикации на нескольких языках – как правильно связать DOI
Технические аспекты публикации на нескольких языках – как правильно связать DOIТехнические аспекты публикации на нескольких языках – как правильно связать DOI
Технические аспекты публикации на нескольких языках – как правильно связать DOI
 
Conference Identity: persistent identifiers for conferences
Conference Identity: persistent identifiers for conferencesConference Identity: persistent identifiers for conferences
Conference Identity: persistent identifiers for conferences
 
Springer LOD conference portal. Demo paper - screenshots
Springer LOD conference portal. Demo paper - screenshotsSpringer LOD conference portal. Demo paper - screenshots
Springer LOD conference portal. Demo paper - screenshots
 
PersistentIDs and CrossMark for Conference Proceedings
PersistentIDs and CrossMark for Conference ProceedingsPersistentIDs and CrossMark for Conference Proceedings
PersistentIDs and CrossMark for Conference Proceedings
 
Publishing conference proceedings internationally: Tips and tricks
Publishing conference proceedings internationally: Tips and tricksPublishing conference proceedings internationally: Tips and tricks
Publishing conference proceedings internationally: Tips and tricks
 
Linked Open Data about Springer Nature conferences. The story so far
Linked Open Data about Springer Nature conferences. The story so farLinked Open Data about Springer Nature conferences. The story so far
Linked Open Data about Springer Nature conferences. The story so far
 
Creating a dataset of peer review in computer science conferences published b...
Creating a dataset of peer review in computer science conferences published b...Creating a dataset of peer review in computer science conferences published b...
Creating a dataset of peer review in computer science conferences published b...
 
Linked Data Initiatives at Springer Verlag
Linked Data Initiatives at Springer Verlag Linked Data Initiatives at Springer Verlag
Linked Data Initiatives at Springer Verlag
 
Diversity-aware search for people, content, events AND Diversity-aware hiring...
Diversity-aware search for people, content, events AND Diversity-aware hiring...Diversity-aware search for people, content, events AND Diversity-aware hiring...
Diversity-aware search for people, content, events AND Diversity-aware hiring...
 
Diversity-aware search for people, content, events AND Diversity-aware hiring...
Diversity-aware search for people, content, events AND Diversity-aware hiring...Diversity-aware search for people, content, events AND Diversity-aware hiring...
Diversity-aware search for people, content, events AND Diversity-aware hiring...
 
20101112 librinnovando liquidpub
20101112 librinnovando liquidpub20101112 librinnovando liquidpub
20101112 librinnovando liquidpub
 
Is peer review any good? A quantitative analysis of peer review
Is peer review any good? A quantitative analysis of peer reviewIs peer review any good? A quantitative analysis of peer review
Is peer review any good? A quantitative analysis of peer review
 
Liquid Journals - Intro and RoadMap
Liquid Journals - Intro and RoadMapLiquid Journals - Intro and RoadMap
Liquid Journals - Intro and RoadMap
 
Liquid Journals. Overview. How social computing and liquid knowledge will sha...
Liquid Journals. Overview. How social computing and liquid knowledge will sha...Liquid Journals. Overview. How social computing and liquid knowledge will sha...
Liquid Journals. Overview. How social computing and liquid knowledge will sha...
 
Automated Experimentation in Social Informatics
Automated Experimentation in Social InformaticsAutomated Experimentation in Social Informatics
Automated Experimentation in Social Informatics
 
General presentation of the LiquidPub project
General presentation of the LiquidPub projectGeneral presentation of the LiquidPub project
General presentation of the LiquidPub project
 
General presentation of the LiquidPub project
General presentation of the LiquidPub projectGeneral presentation of the LiquidPub project
General presentation of the LiquidPub project
 
Peer Review in the LiquidPub project
Peer Review in the LiquidPub projectPeer Review in the LiquidPub project
Peer Review in the LiquidPub project
 
LiquidPub: Services at Service of Science
LiquidPub: Services at Service of ScienceLiquidPub: Services at Service of Science
LiquidPub: Services at Service of Science
 

Recently uploaded

De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
Product School
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Tobias Schneck
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
Product School
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Thierry Lestable
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Albert Hoitingh
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
Cheryl Hung
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
ControlCase
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
Product School
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
DianaGray10
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
Alan Dix
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Product School
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
Guy Korland
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Ramesh Iyer
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
Frank van Harmelen
 

Recently uploaded (20)

De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
Assuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyesAssuring Contact Center Experiences for Your Customers With ThousandEyes
Assuring Contact Center Experiences for Your Customers With ThousandEyes
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
 

An Integrated Solution for Runtime Compliance Governance in SOA

  • 1. An Integrated Solution for Runtime Compliance Governance in SOA Aliaksandr Birukou , Vincenzo D’Andrea, Frank Leymann, Ja- cek Serafinski, Patricia Silveira, Steve Strauch, Marek Tluczek COMPAS Compliance-driven Models, Languages, and Architectures for Services "The COMPAS project will design and implement novel models, languages, and an architectural framework to ensure dynamic and on-going compliance of software services to business regulations and stated user service-requirements. COMPAS will use model-driven techniques, domain-specific languages, and service-oriented infrastructure software to enable organizations developing business compliance solutions easier and faster“ http://www.compas-ict.eu
  • 2.
  • 3. Do I care about compliance ? Image from http://www.blogfinanza.com/wp-content/uploads/2010/09/banca1.jpg ECB Image from http://www.exponent.com/Nuclear-Plant-Services-Capabilities/ AEG GSE http://altocasertano.files.wordpress.com/2007/12/rifiuti1.jpg Ministry of Natural Resources http://www.seebiz.eu/hr/tvrtke/transport/pevec-transporti-u-stecaju,65063.html Ministry of transportation Legge n.6 06/02/2009 Legge n. 152 13/08/2010 Sarbanes-Oxley Act Basel III Direttiva 2010/40/UE Direttiva 2009/548/CE Decreto 10/09/2010 Direttiva 2008/763/CE
  • 5.
  • 6. 2010 GRC software investments priorities Source: AMR Research, 2009 18% Compliance management 17% 16% Business process management 15% Continuous control monitoring Security (internal/external) Risk management Sustainability software Documents/record management Reporting 14% 12% 11% 10% Investments priorities
  • 7.
  • 8. Case study: Advanced Telecom Services Internet Internet ... Audio providers Video providers MVNO company AudioSport License FootballGames License EU MVNO directives Austria Telecommunication Act 2003 Bob Alice Carol Customer contracts
  • 9.
  • 10. Compliance governance in COMPAS Internalization Design Regulations, business contracts, standards Internal policies Business processes Events Execution data Internal evaluation Business execution Auditor Runtime compliance governance
  • 11. Compliance Domains in COMPAS Regulations Licenses QoS
  • 12. 1. Selecting compliance sources and requirements Pay-per-view plan When MVNO company subscribes for the Pay-per-view plan it has to pay 29.90 euro first and then receive 300 streams from the media supplier Composition permission VideoSport can only have audio streams from AudioSport Availability The WatchMe service must deliver a valid URL at least in 90% of requests per customer subscription. VideoSport License FootballGames License EU MVNO directives Austria Telecommunication Act 2003 Customer contracts
  • 13. 1. From high-level DSLs to code Code generation
  • 14.
  • 15. 3. Monitoring. Complex Event Processing
  • 16. 3. Monitoring - ETL and Data Warehouse
  • 17. 4.Informing on the current state of compliance Compliance indicators Different types of compliance Details on compliance
  • 18. 4.Informing on the current state of compliance
  • 19.
  • 20.
  • 21.
  • 22.
  • 23.
  • 24.

Editor's Notes

  1. I’ll show later how we derive requirements, etc
  2. Waste management
  3. Solutions like COMPAS can help companies to save those money buy providing more automated controls
  4. COMPAS – Compliance-driven Models, Languages and Architectures for services
  5. The case study we consider deals with telecommunication domain[CLICK] There is a Virtual Mobile Network Operator which uses network of other operators to provide additional services[CLICK] It combines video and audio from different content providers and streams sport content to its customers over the internet This case study focuses on particularly challenging evnironment, since network infrastructure and many applications that provide service components are owned and managed by different interprises, including third party application providers, network carriers and the MVNO company. The business of the MVNO company must run in accordance with different regulations.[CLICK] And it also must adhere contracts with audio and video providers and contracts of their customers. So, it faces the problem of ensuring the compliance with all those regulations. If they do not comply they can be sued by the companies, loose customers, or loose a lot of money in fines because of not following legislation. Now we will show how our approach allows the company to deal with those concerns in a systematic manner.
  6. selecting the sources to be compliant with and designing corresponding compliance requirements; (2) (re-)designing business processes compliant with the selected requirements; (3) monitoring compliance of processes during their execution; (4) informing interested parties (managers, auditors) on the current state of compliance; (5) taking specific actions or chang- ing the processes in cases of (predicted or happened) non-compliance. DESIGN ASPECTS – in parallel session
  7. Benefits of our solution
  8. … and we presented runtime aspects of such system
  9. STARTUP on compas – contact US!