Cristin-resultat-ID: 1336223
Sist endret: 16. februar 2016, 09:46
NVI-rapporteringsår: 2015
Resultat
Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
2015

An integrated method for compliance and risk assessment

Bidragsytere:
  • Samson Yoseph Esayas
  • Tobias Mahler
  • Fredrik Seehusen
  • Frode Bjørnstad og
  • Veda Brubakk

Bok

Om resultatet

Vitenskapelig Kapittel/Artikkel/Konferanseartikkel
Publiseringsår: 2015
Sider: 568 - 576
ISBN:
  • 978-1-4673-7876-5

Klassifisering

Fagfelt (NPI)

Fagfelt: Rettsvitenskap
- Fagområde: Samfunnsvitenskap

Beskrivelse Beskrivelse

Tittel

An integrated method for compliance and risk assessment

Sammendrag

This paper presents an integrated method for risk and compliance assessment and its evaluation in a case study. The sophistication with which modern business is carried out and the unprecedented access to a global market means that businesses are exposed to diverse regulatory requirements in and across jurisdictions. Compliance with such requirements is practically challenging, partly due to the complexity of regulatory environments. One possibility in this regard is a riskbased approach to compliance where resources are allocated to those compliance issues that are most risky. Despite the need for risk-based compliance, few specific methods and techniques for identifying and modeling compliance risks have been developed. The lack of methodological and tool support means the compliance risk identification often involves unstructured brainstorming, with uncertain outcomes. As part of the integrated method, a structured approach for the identification of compliance risks and their graphical modelling is provided. The main goal of the structured approach is to facilitate the identification and assessment of compliance risks and their subsequent documentation in a consistent and reusable fashion. The method is applied in a case study with the aim of assessing the compliance concerns in adopting cloud services. Our experience in the case study demonstrates that the integrated method enables a better structuring in the identification of compliance risks and yields reusable results. As well, the method facilitates communication among different expertise and mitigates subjectivity in making compliance decisions.

Bidragsytere

Samson Yoseph Esayas

  • Tilknyttet:
    Forfatter
    ved Institutt for privatrett ved Universitetet i Oslo
Aktiv cristin-person

Tobias Mahler

  • Tilknyttet:
    Forfatter
    ved Institutt for privatrett ved Universitetet i Oslo

Fredrik Seehusen

  • Tilknyttet:
    Forfatter
    ved Sustainable Communication Technologies ved SINTEF AS

Frode Bjørnstad

  • Tilknyttet:
    Forfatter
    ved Evry Consulting

Veda Brubakk

  • Tilknyttet:
    Forfatter
    ved Evry Consulting
1 - 5 av 5

Resultatet er en del av Resultatet er en del av

2015 IEEE Conference on Communications and Network Security (CNS), Florence, 28-30 September, 2015.

Samarati, Pierangela; Noubir, Guevara. 2015, IEEE conference proceedings. Vitenskapelig antologi/Konferanseserie
1 - 1 av 1