Towards end-to-end continuous monitoring of compliance status across multiple requirements

Monitoring compliance status by an organization has been historically difficult due to the growing number of compliance requirements being imposed by various standards, frameworks, and regulatory requirements. Existing practices by organizations even with the assistance of security tools and applian...

Full description

Saved in:
Bibliographic Details
Main Authors: Cheng, Danny C., Villamarin, Jod B., Cu, Gregory, Cheng, Nathalie Rose Lim-
Format: text
Published: Animo Repository 2018
Subjects:
Online Access:https://animorepository.dlsu.edu.ph/faculty_research/2869
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: De La Salle University
id oai:animorepository.dlsu.edu.ph:faculty_research-3868
record_format eprints
spelling oai:animorepository.dlsu.edu.ph:faculty_research-38682021-11-15T03:33:26Z Towards end-to-end continuous monitoring of compliance status across multiple requirements Cheng, Danny C. Villamarin, Jod B. Cu, Gregory Cheng, Nathalie Rose Lim- Monitoring compliance status by an organization has been historically difficult due to the growing number of compliance requirements being imposed by various standards, frameworks, and regulatory requirements. Existing practices by organizations even with the assistance of security tools and appliances is mostly manual in nature as there is still a need for a human expert to interpret and map the reports generated by various solutions to actual requirements as stated in various compliance documents. As the number of requirements increases, this process is becoming either too costly or impractical to manage by the organization. Aside from the numerous requirements, multiple of these documents actually overlap in terms of domains and actual requirements. However, since current tools do not directly map and highlight overlaps as well as generate detailed gap reports, an organization would perform compliance activities redundantly across multiple requirements thereby increasing cost as well. In this paper, we present an approach that attempts to provide an end-to-end solution from compliance document requirements to actual verification and validation of implementation for audit purposes with the intention of automating compliance status monitoring as well as providing the ability to have continuous compliance monitoring as well as reducing the redundant efforts that an organization embarks on for multiple compliance requirements. This research thru enhancing existing security ontologies to model compliance documents and applying information extraction practices would allow for overlapping requirements to be identified and gaps to be clearly explained to the organization. Thru the use of secure systems development lifecycle, and heuristics the research also provide a mechanism to automate the technical validation of compliance statuses thereby allowing for continuous monitoring as well as mapping to the enhanced ontology to allow reusability via conceptual mapping of multiple standards and requirements. Practices such as unit testing and continuous integration from secure systems development life cycle are incorporated to allow for flexibility of the automation process while at the same time using it to support the mapping between compliance requirements. © 2018 International Journal of Advanced Computer Science and Applications. 2018-01-01T08:00:00Z text https://animorepository.dlsu.edu.ph/faculty_research/2869 Faculty Research Work Animo Repository Compliance Compliance auditing--Automation Computer Sciences
institution De La Salle University
building De La Salle University Library
continent Asia
country Philippines
Philippines
content_provider De La Salle University Library
collection DLSU Institutional Repository
topic Compliance
Compliance auditing--Automation
Computer Sciences
spellingShingle Compliance
Compliance auditing--Automation
Computer Sciences
Cheng, Danny C.
Villamarin, Jod B.
Cu, Gregory
Cheng, Nathalie Rose Lim-
Towards end-to-end continuous monitoring of compliance status across multiple requirements
description Monitoring compliance status by an organization has been historically difficult due to the growing number of compliance requirements being imposed by various standards, frameworks, and regulatory requirements. Existing practices by organizations even with the assistance of security tools and appliances is mostly manual in nature as there is still a need for a human expert to interpret and map the reports generated by various solutions to actual requirements as stated in various compliance documents. As the number of requirements increases, this process is becoming either too costly or impractical to manage by the organization. Aside from the numerous requirements, multiple of these documents actually overlap in terms of domains and actual requirements. However, since current tools do not directly map and highlight overlaps as well as generate detailed gap reports, an organization would perform compliance activities redundantly across multiple requirements thereby increasing cost as well. In this paper, we present an approach that attempts to provide an end-to-end solution from compliance document requirements to actual verification and validation of implementation for audit purposes with the intention of automating compliance status monitoring as well as providing the ability to have continuous compliance monitoring as well as reducing the redundant efforts that an organization embarks on for multiple compliance requirements. This research thru enhancing existing security ontologies to model compliance documents and applying information extraction practices would allow for overlapping requirements to be identified and gaps to be clearly explained to the organization. Thru the use of secure systems development lifecycle, and heuristics the research also provide a mechanism to automate the technical validation of compliance statuses thereby allowing for continuous monitoring as well as mapping to the enhanced ontology to allow reusability via conceptual mapping of multiple standards and requirements. Practices such as unit testing and continuous integration from secure systems development life cycle are incorporated to allow for flexibility of the automation process while at the same time using it to support the mapping between compliance requirements. © 2018 International Journal of Advanced Computer Science and Applications.
format text
author Cheng, Danny C.
Villamarin, Jod B.
Cu, Gregory
Cheng, Nathalie Rose Lim-
author_facet Cheng, Danny C.
Villamarin, Jod B.
Cu, Gregory
Cheng, Nathalie Rose Lim-
author_sort Cheng, Danny C.
title Towards end-to-end continuous monitoring of compliance status across multiple requirements
title_short Towards end-to-end continuous monitoring of compliance status across multiple requirements
title_full Towards end-to-end continuous monitoring of compliance status across multiple requirements
title_fullStr Towards end-to-end continuous monitoring of compliance status across multiple requirements
title_full_unstemmed Towards end-to-end continuous monitoring of compliance status across multiple requirements
title_sort towards end-to-end continuous monitoring of compliance status across multiple requirements
publisher Animo Repository
publishDate 2018
url https://animorepository.dlsu.edu.ph/faculty_research/2869
_version_ 1718382664925315072