SlideShare a Scribd company logo
1 of 12
Download to read offline
IESS 1.0 - First International Conference on Exploring Services Sciences
                                     17-18-19 February 2010, Geneva, Switzerland




 Compliance in e-government
 service engineering
 State-of-the-art


 Slim Turki, Marija Bjeković-Obradović
 {slim.turki, marija.bjekovic}@tudor.lu
 CRP Henri Tudor, Luxembourg



24-Mar-10                            IESS 1.0                                         1
Context


       Organisations faced with need to conform to various laws and
       regulations governing their domain of activity
       Obligation of compliance particularly stressed in e-government.
            e-government: “the use of ICT systems and tools to provide better
            public services to citizens and other businesses” [EC]
            administrative laws regulate the activities and decision-making of
            governmental institutions.
       Regulation
            extensive source of requirements to be respected when designing IS
            that support institutional activities and (e-)services to public.
       Approaches aiming to achieve and maintain regulatory compliance
       of IS and services with given regulations




24-Mar-10                                 IESS 1.0                               2
Overview


            Compliance in the business process research area
            Extracting compliance requirements from legal texts
               Deontic logic - Extracting rights and obligations
               Modeling regulations with goal-oriented models
            Traceability support for compliance




24-Mar-10                                IESS 1.0                  3
Compliance in the business process
                    research area

            (Kharbili et al., 2008)
               Ontologies for formal modeling of regulations, to resolve
               inconsistency of legal definitions and regulatory information
               fragments.
               Coupled with business processes, basis for compliance
               management framework, to manage evolution in both business
               process and legislation.
            (Karagiannis et al., 2007, 2008)
               Meta-modeling based approach: regulatory aspects expressed in
               models, and included into business processes models, to improve
               or redesign them for compliance with corresponding regulations.
               Applied to Sarbanes-Oxley (SOX) act.




24-Mar-10                               IESS 1.0                               4
Compliance in the business process
                    research area

            (Rifaut, 2005)
               PRM / PAM
               Support for financial business process design (compliant to Basel
               II), and for assessment of compliance and its improvement.
               Goal-oriented models and ISO/IEC 15504 process assessment
               standard used for structuring requirements for business process,
               and together compose a formal framework according to which
               compliance of business process is assessed.




24-Mar-10                                IESS 1.0                                  5
Deontic logic (1/2)


            Extracting rights and obligations from regulations
            (Kiyavitskaya et al., 2007) (Zeni et al., 2008)
               Extraction of “objects of concern” (right, anti-right, obligation, anti-
               obligation, and exception) from legal texts
               Semantic annotation tool Cerno: Obligations, constraints and
               condition keywords are highlighted in a regulation and a list of
               constraints and obligations are obtained (including traceability
               markers).
            (Biagioli et al.) (Palmirani, 2003)
               Automated extraction of normative references, such as specific
               rights and obligations, detailed in legal texts
               Address problem of law’s evolution by tracking changes over time.




24-Mar-10                                   IESS 1.0                                      6
Deontic logic (2/2)


            (Breaux and Antón, 2006), (Breaux and Antón , 2008)
               Extract and balance formal descriptions of rules (rights and
               obligations) that govern actors' actions from regulation.
               Combines goal-oriented analysis of legal documents and
               techniques for extracting rights, obligations, constraints, rules from
               natural language statements in legal text.
               Strength: resolving the problems of ambiguity, polysemy, cross-
               references when analyzing legal text, and maintaining traceability
               across all the artefacts in the process.
               Has been applied to US regulation governing information privacy
               in health care domain.




24-Mar-10                                  IESS 1.0                                 7
Modeling regulations with goal-
                    oriented models

            SecureTropos (Giorgini et al., 2005)
               Goal-oriented techniques to model security requirements
               Assessing organization's compliance with Italian Data Protection
               Act.
               Manual extraction of concepts from law, coverage of legal
               documents limited only to security aspect.
            (Ghanavati et al., 2007)
               Tracking compliance of business processes to legislation,
               Combines goal-oriented requirement language (GRL), user
               requirements notation (URN), and use case maps (UCM).
               Links between models of legislation, organisation policy and
               processes, to enable examining the influence of evolving
               legislations on organizational policies and business processes..
               Applied in the domain of information privacy in healthcare in
               Canada.


24-Mar-10                                IESS 1.0                                 8
Extracting compliance requirements
                    from legal texts - Challenges

            Modeling regulations and extracting key concepts recognized
            as challenging tasks for requirements engineers, system
            developers and compliance auditors (Otto et Antón, 2007)
            (Kiavitskaya et al., 2008)
               the very nature of language in which laws are written, containing
               many ambiguities, cross-references, domain-specific definitions,
               acronyms etc.,
               overlapping or complementing regulations at different level of
               authority,
               frequent changes or amendment of regulations over time, etc.


            Law analysis prone to interpretations and misunderstandings




24-Mar-10                                 IESS 1.0                                 9
Traceability support for compliance


            Traceability gaining on significance
               Ability to maintain links between originating laws and derived
               artefacts (requirements, IS specifications etc.) as measure to
               enable better understanding of legal documents and to prevent
               non-compliance of produced specifications.
            (Ghanavati et al., 2007)
               Set of links to establish between legislation and organizational
               models.
            (Breaux and Antón)
               Traceability maintained across all the artefacts produced from
               legal text to the corresponding software requirements.
               Most of the traceability links to be established manually.




24-Mar-10                                 IESS 1.0                                10
Conclusion
            RE community
               Elaborated techniques, concepts and tool support.
               Assumption: compliance can be achieved at the requirements
               level, through the harmonization between IS requirements and
               those derived from legislation.
               Address compliance regarding specific security and privacy
               regulations.
            Approaches centred on business process
               More at the level of organization, its strategy, policies and
               process, rather than on the underlying IS level.
               Including requirements imposed by specific regulation, to existing
               business processes, to ensure or assess their compliance.
               Focus on modeling dynamic aspects of organization
               Service engineering requires more aspects, not only business
               processes, be covered.
            No method, in the literature, specific to the design of compliant
            e-government services.

24-Mar-10                                 IESS 1.0                              11
IESS 1.0 - First International Conference on Exploring Services Sciences
                                     17-18-19 February 2010, Geneva, Switzerland




 Compliance in e-government
 service engineering
 State-of-the-art


Thank you for your attention!


 Slim Turki, Marija Bjeković-Obradović
 {slim.turki, marija.bjekovic}@tudor.lu
 CRP Henri Tudor, Luxembourg
24-Mar-10                            IESS 1.0                                        12

More Related Content

Similar to Compliance in e-gov service engineering state-of-art

IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...IRJET Journal
 
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...IRJET Journal
 
COBI 2014 - Designing a Meta Model as the Foundation for Compliance Capability
COBI 2014 - Designing a Meta Model as the Foundation for Compliance CapabilityCOBI 2014 - Designing a Meta Model as the Foundation for Compliance Capability
COBI 2014 - Designing a Meta Model as the Foundation for Compliance CapabilityCaaS EU FP7 Project
 
Medicine 2.0 Conference 2014 Abstract
Medicine 2.0 Conference 2014 AbstractMedicine 2.0 Conference 2014 Abstract
Medicine 2.0 Conference 2014 Abstractiehreu
 
Architecture Framework for Resolution of System Complexity in an Enterprise
Architecture Framework for Resolution of System Complexity in an EnterpriseArchitecture Framework for Resolution of System Complexity in an Enterprise
Architecture Framework for Resolution of System Complexity in an EnterpriseIOSR Journals
 
Framework for information systems adaptation to security policies PCI DSS, SO...
Framework for information systems adaptation to security policies PCI DSS, SO...Framework for information systems adaptation to security policies PCI DSS, SO...
Framework for information systems adaptation to security policies PCI DSS, SO...Jesús Vázquez González
 
Towards Automating Security Compliance Value Chain_FSE15_2June_submitted_final
Towards Automating Security Compliance Value Chain_FSE15_2June_submitted_finalTowards Automating Security Compliance Value Chain_FSE15_2June_submitted_final
Towards Automating Security Compliance Value Chain_FSE15_2June_submitted_finalSmita S. Ghaisas
 
Архитектура промышленного интернета
Архитектура промышленного интернетаАрхитектура промышленного интернета
Архитектура промышленного интернетаSergey Zhdanov
 
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES ijwscjournal
 
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESBUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESijwscjournal
 
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESBUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESijwscjournal
 
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESBUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESijwscjournal
 
A Survey on Context Security Policies in the Cloud
A Survey on Context Security Policies in the CloudA Survey on Context Security Policies in the Cloud
A Survey on Context Security Policies in the CloudPaaSword EU Project
 
Study on Use Case Model for Service Oriented Architecture Development
Study on Use Case Model for Service Oriented Architecture DevelopmentStudy on Use Case Model for Service Oriented Architecture Development
Study on Use Case Model for Service Oriented Architecture Developmentijwtiir
 
Towards legally-compliant governmental case work with Dynamic Condition Respo...
Towards legally-compliant governmental case work with Dynamic Condition Respo...Towards legally-compliant governmental case work with Dynamic Condition Respo...
Towards legally-compliant governmental case work with Dynamic Condition Respo...Hugo Andrés López
 
A Combinational Approach of GIS and SOA for Performance Improvement of Organi...
A Combinational Approach of GIS and SOA for Performance Improvement of Organi...A Combinational Approach of GIS and SOA for Performance Improvement of Organi...
A Combinational Approach of GIS and SOA for Performance Improvement of Organi...dannyijwest
 
Study on Use Case Model for Service Oriented Architecture Development
Study on Use Case Model for Service Oriented Architecture DevelopmentStudy on Use Case Model for Service Oriented Architecture Development
Study on Use Case Model for Service Oriented Architecture Developmentijbuiiir1
 

Similar to Compliance in e-gov service engineering state-of-art (20)

Service specification and service compliance how to consider the responsibil...
Service specification and service compliance  how to consider the responsibil...Service specification and service compliance  how to consider the responsibil...
Service specification and service compliance how to consider the responsibil...
 
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
 
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
IoT, Big Data and AI Applications in the Law Enforcement and Legal System: A ...
 
COBI 2014 - Designing a Meta Model as the Foundation for Compliance Capability
COBI 2014 - Designing a Meta Model as the Foundation for Compliance CapabilityCOBI 2014 - Designing a Meta Model as the Foundation for Compliance Capability
COBI 2014 - Designing a Meta Model as the Foundation for Compliance Capability
 
Medicine 2.0 Conference 2014 Abstract
Medicine 2.0 Conference 2014 AbstractMedicine 2.0 Conference 2014 Abstract
Medicine 2.0 Conference 2014 Abstract
 
Architecture Framework for Resolution of System Complexity in an Enterprise
Architecture Framework for Resolution of System Complexity in an EnterpriseArchitecture Framework for Resolution of System Complexity in an Enterprise
Architecture Framework for Resolution of System Complexity in an Enterprise
 
G1803044045
G1803044045G1803044045
G1803044045
 
Access control data security
Access control data securityAccess control data security
Access control data security
 
Framework for information systems adaptation to security policies PCI DSS, SO...
Framework for information systems adaptation to security policies PCI DSS, SO...Framework for information systems adaptation to security policies PCI DSS, SO...
Framework for information systems adaptation to security policies PCI DSS, SO...
 
Towards Automating Security Compliance Value Chain_FSE15_2June_submitted_final
Towards Automating Security Compliance Value Chain_FSE15_2June_submitted_finalTowards Automating Security Compliance Value Chain_FSE15_2June_submitted_final
Towards Automating Security Compliance Value Chain_FSE15_2June_submitted_final
 
Архитектура промышленного интернета
Архитектура промышленного интернетаАрхитектура промышленного интернета
Архитектура промышленного интернета
 
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
 
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESBUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
 
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESBUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
 
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICESBUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
BUSINESS RULE MANAGEMENT FRAMEWORK FOR ENTERPRISE WEB SERVICES
 
A Survey on Context Security Policies in the Cloud
A Survey on Context Security Policies in the CloudA Survey on Context Security Policies in the Cloud
A Survey on Context Security Policies in the Cloud
 
Study on Use Case Model for Service Oriented Architecture Development
Study on Use Case Model for Service Oriented Architecture DevelopmentStudy on Use Case Model for Service Oriented Architecture Development
Study on Use Case Model for Service Oriented Architecture Development
 
Towards legally-compliant governmental case work with Dynamic Condition Respo...
Towards legally-compliant governmental case work with Dynamic Condition Respo...Towards legally-compliant governmental case work with Dynamic Condition Respo...
Towards legally-compliant governmental case work with Dynamic Condition Respo...
 
A Combinational Approach of GIS and SOA for Performance Improvement of Organi...
A Combinational Approach of GIS and SOA for Performance Improvement of Organi...A Combinational Approach of GIS and SOA for Performance Improvement of Organi...
A Combinational Approach of GIS and SOA for Performance Improvement of Organi...
 
Study on Use Case Model for Service Oriented Architecture Development
Study on Use Case Model for Service Oriented Architecture DevelopmentStudy on Use Case Model for Service Oriented Architecture Development
Study on Use Case Model for Service Oriented Architecture Development
 

More from Slim Turki, Dr.

Local Digital Twins Conversations: Framing the Green + Digital Transition
Local Digital Twins Conversations:  Framing the Green + Digital TransitionLocal Digital Twins Conversations:  Framing the Green + Digital Transition
Local Digital Twins Conversations: Framing the Green + Digital TransitionSlim Turki, Dr.
 
Data ecosystems: turning data into public value
Data ecosystems:  turning data into public valueData ecosystems:  turning data into public value
Data ecosystems: turning data into public valueSlim Turki, Dr.
 
#opendata Back to the future
#opendata Back to the future#opendata Back to the future
#opendata Back to the futureSlim Turki, Dr.
 
Data Ecosystems for Geospatial Data
Data Ecosystems for Geospatial DataData Ecosystems for Geospatial Data
Data Ecosystems for Geospatial DataSlim Turki, Dr.
 
Open Data in Disaster Management
Open Data in Disaster ManagementOpen Data in Disaster Management
Open Data in Disaster ManagementSlim Turki, Dr.
 
BE-GOOD: Building an Ecosystem to Generate Opportunities in Open Data
BE-GOOD: Building an Ecosystem to Generate Opportunities in Open DataBE-GOOD: Building an Ecosystem to Generate Opportunities in Open Data
BE-GOOD: Building an Ecosystem to Generate Opportunities in Open DataSlim Turki, Dr.
 
How open data ecosystems are stimulated?
How open data ecosystems are stimulated?How open data ecosystems are stimulated?
How open data ecosystems are stimulated?Slim Turki, Dr.
 
BE-GOOD Challenges - factsheet 2017-06
BE-GOOD Challenges - factsheet 2017-06BE-GOOD Challenges - factsheet 2017-06
BE-GOOD Challenges - factsheet 2017-06Slim Turki, Dr.
 
Service innovation: the hidden value of open data
Service innovation: the hidden value of open dataService innovation: the hidden value of open data
Service innovation: the hidden value of open dataSlim Turki, Dr.
 
From open data to data-driven services
From open data to data-driven servicesFrom open data to data-driven services
From open data to data-driven servicesSlim Turki, Dr.
 
How open data are turned into services?
How open data are turned into services?How open data are turned into services?
How open data are turned into services?Slim Turki, Dr.
 
1-5 stars: Metadata on the Openness Level of Open Data Sets in Europe
1-5 stars: Metadata on the Openness Level of Open Data Sets in Europe1-5 stars: Metadata on the Openness Level of Open Data Sets in Europe
1-5 stars: Metadata on the Openness Level of Open Data Sets in EuropeSlim Turki, Dr.
 
SPOCS: A semantic interoperability layer to support the implementation of the...
SPOCS: A semantic interoperability layer to support the implementation of the...SPOCS: A semantic interoperability layer to support the implementation of the...
SPOCS: A semantic interoperability layer to support the implementation of the...Slim Turki, Dr.
 
Open Data: Barriers, Risks, and Opportunities
Open Data: Barriers, Risks, and OpportunitiesOpen Data: Barriers, Risks, and Opportunities
Open Data: Barriers, Risks, and OpportunitiesSlim Turki, Dr.
 
Luxembourg Service Jam 2013 - Guide book
Luxembourg Service Jam 2013 - Guide bookLuxembourg Service Jam 2013 - Guide book
Luxembourg Service Jam 2013 - Guide bookSlim Turki, Dr.
 
Luxembourg Service Jam 2012 - Guide book
Luxembourg Service Jam 2012 - Guide bookLuxembourg Service Jam 2012 - Guide book
Luxembourg Service Jam 2012 - Guide bookSlim Turki, Dr.
 
Global Service Jam - Luxembourg spot
Global Service Jam - Luxembourg spotGlobal Service Jam - Luxembourg spot
Global Service Jam - Luxembourg spotSlim Turki, Dr.
 

More from Slim Turki, Dr. (18)

Local Digital Twins Conversations: Framing the Green + Digital Transition
Local Digital Twins Conversations:  Framing the Green + Digital TransitionLocal Digital Twins Conversations:  Framing the Green + Digital Transition
Local Digital Twins Conversations: Framing the Green + Digital Transition
 
Data ecosystems: turning data into public value
Data ecosystems:  turning data into public valueData ecosystems:  turning data into public value
Data ecosystems: turning data into public value
 
#opendata Back to the future
#opendata Back to the future#opendata Back to the future
#opendata Back to the future
 
Data Ecosystems for Geospatial Data
Data Ecosystems for Geospatial DataData Ecosystems for Geospatial Data
Data Ecosystems for Geospatial Data
 
Open Data in Disaster Management
Open Data in Disaster ManagementOpen Data in Disaster Management
Open Data in Disaster Management
 
BE-GOOD: Building an Ecosystem to Generate Opportunities in Open Data
BE-GOOD: Building an Ecosystem to Generate Opportunities in Open DataBE-GOOD: Building an Ecosystem to Generate Opportunities in Open Data
BE-GOOD: Building an Ecosystem to Generate Opportunities in Open Data
 
How open data ecosystems are stimulated?
How open data ecosystems are stimulated?How open data ecosystems are stimulated?
How open data ecosystems are stimulated?
 
BE-GOOD Challenges - factsheet 2017-06
BE-GOOD Challenges - factsheet 2017-06BE-GOOD Challenges - factsheet 2017-06
BE-GOOD Challenges - factsheet 2017-06
 
Service innovation: the hidden value of open data
Service innovation: the hidden value of open dataService innovation: the hidden value of open data
Service innovation: the hidden value of open data
 
From open data to data-driven services
From open data to data-driven servicesFrom open data to data-driven services
From open data to data-driven services
 
How open data are turned into services?
How open data are turned into services?How open data are turned into services?
How open data are turned into services?
 
1-5 stars: Metadata on the Openness Level of Open Data Sets in Europe
1-5 stars: Metadata on the Openness Level of Open Data Sets in Europe1-5 stars: Metadata on the Openness Level of Open Data Sets in Europe
1-5 stars: Metadata on the Openness Level of Open Data Sets in Europe
 
SPOCS: A semantic interoperability layer to support the implementation of the...
SPOCS: A semantic interoperability layer to support the implementation of the...SPOCS: A semantic interoperability layer to support the implementation of the...
SPOCS: A semantic interoperability layer to support the implementation of the...
 
Open Data: Barriers, Risks, and Opportunities
Open Data: Barriers, Risks, and OpportunitiesOpen Data: Barriers, Risks, and Opportunities
Open Data: Barriers, Risks, and Opportunities
 
Luxembourg Service Jam 2013 - Guide book
Luxembourg Service Jam 2013 - Guide bookLuxembourg Service Jam 2013 - Guide book
Luxembourg Service Jam 2013 - Guide book
 
Luxembourg Service Jam 2012 - Guide book
Luxembourg Service Jam 2012 - Guide bookLuxembourg Service Jam 2012 - Guide book
Luxembourg Service Jam 2012 - Guide book
 
Global Service Jam - Luxembourg spot
Global Service Jam - Luxembourg spotGlobal Service Jam - Luxembourg spot
Global Service Jam - Luxembourg spot
 
Legora@IESS1.0
Legora@IESS1.0Legora@IESS1.0
Legora@IESS1.0
 

Compliance in e-gov service engineering state-of-art

  • 1. IESS 1.0 - First International Conference on Exploring Services Sciences 17-18-19 February 2010, Geneva, Switzerland Compliance in e-government service engineering State-of-the-art Slim Turki, Marija Bjeković-Obradović {slim.turki, marija.bjekovic}@tudor.lu CRP Henri Tudor, Luxembourg 24-Mar-10 IESS 1.0 1
  • 2. Context Organisations faced with need to conform to various laws and regulations governing their domain of activity Obligation of compliance particularly stressed in e-government. e-government: “the use of ICT systems and tools to provide better public services to citizens and other businesses” [EC] administrative laws regulate the activities and decision-making of governmental institutions. Regulation extensive source of requirements to be respected when designing IS that support institutional activities and (e-)services to public. Approaches aiming to achieve and maintain regulatory compliance of IS and services with given regulations 24-Mar-10 IESS 1.0 2
  • 3. Overview Compliance in the business process research area Extracting compliance requirements from legal texts Deontic logic - Extracting rights and obligations Modeling regulations with goal-oriented models Traceability support for compliance 24-Mar-10 IESS 1.0 3
  • 4. Compliance in the business process research area (Kharbili et al., 2008) Ontologies for formal modeling of regulations, to resolve inconsistency of legal definitions and regulatory information fragments. Coupled with business processes, basis for compliance management framework, to manage evolution in both business process and legislation. (Karagiannis et al., 2007, 2008) Meta-modeling based approach: regulatory aspects expressed in models, and included into business processes models, to improve or redesign them for compliance with corresponding regulations. Applied to Sarbanes-Oxley (SOX) act. 24-Mar-10 IESS 1.0 4
  • 5. Compliance in the business process research area (Rifaut, 2005) PRM / PAM Support for financial business process design (compliant to Basel II), and for assessment of compliance and its improvement. Goal-oriented models and ISO/IEC 15504 process assessment standard used for structuring requirements for business process, and together compose a formal framework according to which compliance of business process is assessed. 24-Mar-10 IESS 1.0 5
  • 6. Deontic logic (1/2) Extracting rights and obligations from regulations (Kiyavitskaya et al., 2007) (Zeni et al., 2008) Extraction of “objects of concern” (right, anti-right, obligation, anti- obligation, and exception) from legal texts Semantic annotation tool Cerno: Obligations, constraints and condition keywords are highlighted in a regulation and a list of constraints and obligations are obtained (including traceability markers). (Biagioli et al.) (Palmirani, 2003) Automated extraction of normative references, such as specific rights and obligations, detailed in legal texts Address problem of law’s evolution by tracking changes over time. 24-Mar-10 IESS 1.0 6
  • 7. Deontic logic (2/2) (Breaux and Antón, 2006), (Breaux and Antón , 2008) Extract and balance formal descriptions of rules (rights and obligations) that govern actors' actions from regulation. Combines goal-oriented analysis of legal documents and techniques for extracting rights, obligations, constraints, rules from natural language statements in legal text. Strength: resolving the problems of ambiguity, polysemy, cross- references when analyzing legal text, and maintaining traceability across all the artefacts in the process. Has been applied to US regulation governing information privacy in health care domain. 24-Mar-10 IESS 1.0 7
  • 8. Modeling regulations with goal- oriented models SecureTropos (Giorgini et al., 2005) Goal-oriented techniques to model security requirements Assessing organization's compliance with Italian Data Protection Act. Manual extraction of concepts from law, coverage of legal documents limited only to security aspect. (Ghanavati et al., 2007) Tracking compliance of business processes to legislation, Combines goal-oriented requirement language (GRL), user requirements notation (URN), and use case maps (UCM). Links between models of legislation, organisation policy and processes, to enable examining the influence of evolving legislations on organizational policies and business processes.. Applied in the domain of information privacy in healthcare in Canada. 24-Mar-10 IESS 1.0 8
  • 9. Extracting compliance requirements from legal texts - Challenges Modeling regulations and extracting key concepts recognized as challenging tasks for requirements engineers, system developers and compliance auditors (Otto et Antón, 2007) (Kiavitskaya et al., 2008) the very nature of language in which laws are written, containing many ambiguities, cross-references, domain-specific definitions, acronyms etc., overlapping or complementing regulations at different level of authority, frequent changes or amendment of regulations over time, etc. Law analysis prone to interpretations and misunderstandings 24-Mar-10 IESS 1.0 9
  • 10. Traceability support for compliance Traceability gaining on significance Ability to maintain links between originating laws and derived artefacts (requirements, IS specifications etc.) as measure to enable better understanding of legal documents and to prevent non-compliance of produced specifications. (Ghanavati et al., 2007) Set of links to establish between legislation and organizational models. (Breaux and Antón) Traceability maintained across all the artefacts produced from legal text to the corresponding software requirements. Most of the traceability links to be established manually. 24-Mar-10 IESS 1.0 10
  • 11. Conclusion RE community Elaborated techniques, concepts and tool support. Assumption: compliance can be achieved at the requirements level, through the harmonization between IS requirements and those derived from legislation. Address compliance regarding specific security and privacy regulations. Approaches centred on business process More at the level of organization, its strategy, policies and process, rather than on the underlying IS level. Including requirements imposed by specific regulation, to existing business processes, to ensure or assess their compliance. Focus on modeling dynamic aspects of organization Service engineering requires more aspects, not only business processes, be covered. No method, in the literature, specific to the design of compliant e-government services. 24-Mar-10 IESS 1.0 11
  • 12. IESS 1.0 - First International Conference on Exploring Services Sciences 17-18-19 February 2010, Geneva, Switzerland Compliance in e-government service engineering State-of-the-art Thank you for your attention! Slim Turki, Marija Bjeković-Obradović {slim.turki, marija.bjekovic}@tudor.lu CRP Henri Tudor, Luxembourg 24-Mar-10 IESS 1.0 12