Information Systems: People, Organizations, Institutions, and Technologies 2009
DOI: 10.1007/978-3-7908-2148-2_45
|View full text |Cite
|
Sign up to set email alerts
|

Compliance Management is Becoming a Major Issue in IS Design

Abstract: This article aims at improving the information systems management support to Risk and Compliance Management process, i.e. the management of all compliance imperatives that impact an organization, including both legal and strategically self-imposed imperatives. We propose a process to achieve such regulatory compliance by aligning the Governance activities with the Risk Management ones, and we suggest Compliance should be considered as a requirement for the Risk Management platform. We will propose a framework … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
9
0

Year Published

2010
2010
2023
2023

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 14 publications
(9 citation statements)
references
References 11 publications
0
9
0
Order By: Relevance
“…Compliance is a well-known research subject in IS. The literature addresses topics such as the compliance of business processes and services [14][15][16], requirements engineering and conceptual modeling [17,18], auditing IS compliance [19,20], and the alignment between law and IT compliance [21]. However, the majority of studies focus on the perspective of modeling and checking compliance [10], lacking the human behavior in that regulatory space and the guidance to allow cooperation between different experts, not specific to a technology or IT architecture.…”
Section: Is Design and Compliancementioning
confidence: 99%
“…Compliance is a well-known research subject in IS. The literature addresses topics such as the compliance of business processes and services [14][15][16], requirements engineering and conceptual modeling [17,18], auditing IS compliance [19,20], and the alignment between law and IT compliance [21]. However, the majority of studies focus on the perspective of modeling and checking compliance [10], lacking the human behavior in that regulatory space and the guidance to allow cooperation between different experts, not specific to a technology or IT architecture.…”
Section: Is Design and Compliancementioning
confidence: 99%
“…The implementation of controls usually does not follow a generic strategy and hence business compliance is reached on a per-case basis, that is, organizations use ad hoc, hand-crafted solutions for specific compliance concerns [3,[5][6][7]. This usually means that a separate project is started and develops an individual, custom solution for the compliance concern to be addressed.…”
Section: Compliance and Business Processesmentioning
confidence: 99%
“…In cases where preventive controls are hard to implement, for example, failure of a system, service, or human operation, monitoring components can play a more active role by ensuring fast detection of compliance violations [4]; in other words, the monitoring component itself is the compliance control. In many organizations, however, implementation of compliance controls does not follow a generic strategy; compliance is reached on a per case basis, with ad hoc, hand-crafted solutions or niche products used for specific compliance scenarios [3,[5][6][7]. Additionally, these compliance controls are scattered throughout an organization system without a clear architectural concept; in some cases, controls are duplicated.…”
mentioning
confidence: 99%
“…Currently, the impact of technical systems to prior analogue world definitions of accountability is unclear. Only few attempts have been made to include the ability of tracing root causes of unwanted events by design, such as [2]. Current e↵orts for data accountability IS lack either the social aspect of IS or a solution by design or both.…”
Section: Introductionmentioning
confidence: 99%