A platform-independent approach for auditing information systems

  • Authors:
  • Gerald Weber

  • Affiliations:
  • The University of Auckland, Auckland, New Zealand

  • Venue:
  • HDKM '08 Proceedings of the second Australasian workshop on Health data and knowledge management - Volume 80
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Information systems in several application domains have to fulfil particularly stringent requirements, first of all concerning privacy, but then also concerning the ability to audit the use of data in hindsight. For databases as a key component of such systems, the concept of hippocratic databases was proposed (Agrawal et al. 2002). These databases are targeted at privacy-intensive applications including healthcare applications. Hippocratic databases enable active enforcement of privacy policies, as well as audits of compliance. We present here a framework that allows us to audit the data that was actually presented. In a model-driven approach, platform-independent models support reuse and are translated into platform dependent models. We present here a platform-independent model for auditing information systems. It is based on a message-based system viewpoint that allows us to discuss aspects of a service-oriented architecture on a high-level analysis and design level. This method shows how we can use a protocol of all ingoing and outgoing messages as an audit trail for the system.