Towards Systematic Achievement of Compliance in Service-Oriented Architectures: The MASTER Approach

نویسندگان

  • Volkmar Lotz
  • Emmanuel Pigout
  • Peter M. Fischer
  • Donald Kossmann
  • Fabio Massacci
  • Alexander Pretschner
چکیده

service interfaces, distributed ownership and cross-domain operations introduce new challenges for the implementation of compliance controls and the assessment of their effectiveness. In this paper, we analyze the challenges for automated support of the enforcement and evaluation of IT security controls in a SOA. We introduce these challenges by means of an example control, and outline a methodology and a high-level architecture that supports the phases of the control lifecycle through dedicated components for observation, evaluation, decision support and reaction. The approach is model-based and features policy-driven controls. A monitoring infrastructure assesses observations in terms of key indicators and interprets them in business terms. Reaction is supported through components that implement both automated enforcement and the provision of feedback by a human user. The resulting architecture essentially is a decoupled security architecture for SOA with enhanced analysis capabilities and will be detailed and implemented in

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Achieving Life-Cycle Compliance of Service-Oriented Architectures: Open Issues and Challenges

The introduction of regulations such as the Sarbanes-Oxley act requires companies to ensure that appropriate controls are implemented in their business applications. Implementing and validating compliance measures in ‘agile’ companies is time consuming, costly, errorprone and a maintenance-intensive task. This paper presents an approach towards dynamically adapting a Service Oriented Architectu...

متن کامل

Aligning Service-Oriented Architectures with Security Requirements

Aligning requirements and architectures is a long-standing concern in software engineering. Alignment is crucial in the area of systems evolution, wherein requirements and system architectures keep changing after system deployment. We address a specific alignment problem, i.e., checking the compliance of a service-oriented architecture— representing a composite service—with security requirement...

متن کامل

Requirements for privacy-enhancing Service-oriented architectures

Service-oriented architectures expose new chances and challenges for privacy and data protection. The potentially increased distribution of personal information across multiple domains make subject access requests difficult to handle. Which service did process what data? Whom to address for liability issues? At the same time, the service orientation offers a new approach for the granularity of ...

متن کامل

Designing and Validating the Service-Oriented University Model from the Standpoint of Higher Education Experts

Service orientation is a pivotal factor and a strategic direction for the university to keep with changes and perceptions of social needs. Accordingly, the main purpose of this study is to develop a model for the service-oriented university within the framework of service provision to the community. This research was conducted using a qualitative approach based on the grounded theory method. Th...

متن کامل

A customer oriented systematic framework to extract business strategy in Indian electricity services

Competition in the electric service industry is highlighting the importance of a number of issues affecting the nature and quality of customer service. The quality of service(s) provided to electricity customers may be enhanced by competition, if doing so offers service suppliers a competitive advantage. On the other hand, service quality offered to some consumers could decline if utilities foc...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Wirtschaftsinformatik

دوره 50  شماره 

صفحات  -

تاریخ انتشار 2008