• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. Towards systematic achievement of compliance in service-oriented architectures: The MASTER approach
 
  • Details
  • Full
Options
2008
Journal Article
Title

Towards systematic achievement of compliance in service-oriented architectures: The MASTER approach

Abstract
Service-oriented architectures (SOA) have been successfully adapted by agile businesses to support dynamic outsourcing of business processes and the maintenance of business ecosystems. Still, businesses need to comply with applicable laws and regulations. Abstract service interfaces, distributed ownership and cross-domain operations introduce new challenges for the implementation of compliance controls and the assessment of their effectiveness. In this paper, we analyze the challenges for automated support of the enforcement and evaluation of IT security controls in a SOA. We introduce these challenges by means of an example control, and outline a methodology and a high-level architecture that supports the phases of the control lifecycle through dedicated components for observation, evaluation, decision support and reaction. The approach is model-based and features policy-driven controls. A monitoring infrastructure assesses observations in terms of key indicators and interprets them in business terms. Reaction is supported through components that implement both automated enforcement and the provision of feedback by a human user. The resulting architecture essentially is a decoupled security architecture for SOA with enhanced analysis capabilities and will be detailed and implemented in the MASTER project.
Author(s)
Lotz, Volkmar
Pigout, Emmanuel
Fischer, Peter M.
Kossmann, Donald
Massacci, Fabio
Pretschner, Alexander
Journal
Wirtschaftsinformatik  
DOI
10.1007/s11576-008-0086-1
Language
English
Fraunhofer-Institut für Experimentelles Software Engineering IESE  
Keyword(s)
  • compliance

  • service-oriented architecture (SOA)

  • it-security

  • security measure

  • run time monitoring

  • model-based architecture

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024