A semantic based framework for software regulatory compliance
PhD Thesis
Zarrabi Jorshari, F. 2016. A semantic based framework for software regulatory compliance. PhD Thesis University of East London Architecture, Computing and Engineering https://doi.org/10.15123/PUB.6366
Authors | Zarrabi Jorshari, F. |
---|---|
Type | PhD Thesis |
Abstract | Software development market is currently witnessing an increasing demand for software applications conformance with the international regime of GRC for Governance, Risk and Compliance. In this thesis, we propose a compliance requirement analysis method for early stages of software development based on a semantically-rich model, where a mapping can be established from legal and regulatory requirements relevant to system context to software system goals and contexts. This research is an attempt to address the requirement of General Data Protection Regulation (GDPR, Article 25) (European Commission) for implementation of a "privacy by design” approach as part of organizational IT-systems and processes. It requires design of data protection requirements in the development of business processes for products and services. The proposed semantic model consists of a number of ontologies each corresponding to a knowledge component within the developed framework of our approach. Each ontology is a thesaurus of concepts in the compliance and risk assessment domain related to system development along with relationships and rules between concepts that compromise the domain knowledge. The main contribution of the work presented in this paper is a novel ontology-based framework that demonstrates how description-logic reasoning techniques can be used to simulate legal reasoning requirements employed by legal professions against the description of each ontology. The semantic modelling of each component of framework can highly influence the compliance of developing software system and enables the reusability, adaptability and maintainability of these components. Through the discrete modelling of these components, the flexibility and extensibility of compliance systems will be improved. |
Year | 2016 |
Digital Object Identifier (DOI) | https://doi.org/10.15123/PUB.6366 |
Publication dates | |
Jan 2016 | |
Publication process dates | |
Deposited | 21 Sep 2017 |
Publisher's version | License CC BY-NC-ND |
https://repository.uel.ac.uk/item/852yy
Download files
265
total views835
total downloads0
views this month3
downloads this month