Supporting Evidence-Based Compliance Evaluation for Partial Business Process Outsourcing Scenarios

  • Authors:
  • Philip L. Miseldine;Ulrich Flegel;Andreas Schaad

  • Affiliations:
  • -;-;-

  • Venue:
  • RELAW '08 Proceedings of the 2008 Requirements Engineering and Law
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present the challenges facing businesses wishing to outsource processes to service providers who must maintain regulatory compliance via data access control procedures. We argue that it is not currently possible to capture the nec- essary agreements, and supporting evidence, pertaining to the usage of data a client may send to a service provider. As a result, the richness of evidence and controls a client has available to it reduces when they choose to use an outsourcer, therefore lessening the business value of considering service outsourcing. The paper introduces a model to clarify these issues, which is implemented against a health-care scenario, to show how data usage in an outsourcing scenario can be better captured and controlled.