Ontology support for Management System Audit Programs



Similar documents
Translation Service Provider according to ISO 17100

TOTAL QUALITY MANAGEMENT II QUALITY AUDIT

FINAL DOCUMENT. Guidelines for Regulatory Auditing of Quality Management Systems of Medical Device Manufacturers Part 1: General Requirements

Software Quality Standards and. from Ontological Point of View SMEF. Konstantina Georgieva

Procedure for Assessment of System and Software

ISMS Implementation Guide

ISO 9001:2008 Internal Audit Guidance

GOVERNANCE AND MANAGEMENT OF CITY COMPUTER SOFTWARE NEEDS IMPROVEMENT. January 7, 2011

Auditing Process-based Quality Management Systems. Charlie Cianfrani and Jack West

ISO COMPLIANCE WITH OBSERVEIT

TABLE OF CONTENTS ABSTRACT ACKNOWLEDGEMENT LIST OF FIGURES LIST OF TABLES

Internal Audit Hearing Sheet

COMBINE. Part B. Manual for Marine Monitoring in the. Programme of HELCOM. General guidelines on quality assurance for monitoring in the Baltic Sea

An organization properly establishes and operates its control over risks regarding the information system to fulfill the following objectives:

Enabling Compliance Requirements using ISMS Framework (ISO27001)

HONG KONG ENVIRONMENTAL ELECTRICAL APPLIANCE COMPANY. Environmental Procedure

CP14 ISSUE 5 DATED 1 st OCTOBER 2015 BINDT Audit Procedure Conformity Assessment and Certification/Verification of Management Systems

Certification Process Requirements

Web Services-Interoperability Organization Online Privacy Statement

Regulatory Compliance and its Impact on Software Development

Auditor General s Office. Governance and Management of City Computer Software Needs Improvement

EDUCORE ISO Expert Training

Design Specification for IEEE Std 1471 Recommended Practice for Architectural Description IEEE Architecture Working Group 0 Motivation

Frequently Asked Questions (FAQ) Guidelines for quality compliance of. eprocurement System?

Learning outcomes. Systems Engineering. Software Quality Management. Product reflects Process. Lecture 5. Introduction to Software Quality Management

Competency Unit: Exemplar Global AU Management Systems Auditing

NEOXEN MODUS METHODOLOGY

What changes will ISO 9001:2015 bring?

What s New Guide: Version 5.6

ISO 9001 Quality Management Systems. Tips for Internal Auditing

ISO 9001:2008 STANDARD OPERATING PROCEDURES MANUAL

Solution Brief for ISO 27002: 2013 Audit Standard ISO Publication Date: Feb 6, EventTracker 8815 Centre Park Drive, Columbia MD 21045

Pursuant to Convention No. 108 of the Council of Europe for the protection of persons with regard to the automated processing of personal data;

SECTION B DEFINITION, PURPOSE, INDEPENDENCE AND NATURE OF WORK OF INTERNAL AUDIT

SonaVault Archiving Software

ISO/IEC IT Service Management - Benefits and Requirements for Service Providers and Customers

This Business Management System Manual is based on ISO 9001:2008 requirements

ISO 9001 Quality Management Systems Professional

Developing a Theory-Based Ontology for Best Practices Knowledge Bases

ISO/IEC Part 1 the next edition. Lynda Cooper project editor for ISO20000 part 1

TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION

Building Decision Support through Dynamic Workflow Systems for Health Care Ontology Focus. Tanay Sharma B

EMS Example Example EMS Audit Procedure

NASCIO EA Development Tool-Kit Solution Architecture. Version 3.0

Questions and Answers

Type of Personal Data We Collect and How We Use It

Your Software Quality is Our Business. INDEPENDENT VERIFICATION AND VALIDATION (IV&V) WHITE PAPER Prepared by Adnet, Inc.

Information Technology Branch Access Control Technical Standard

TECHNICAL SPECIFICATION: LEGISLATION EXECUTING CLOUD SERVICES

IIA Super Conference

preliminary experiment conducted on Amazon EC2 instance further demonstrates the fast performance of the design.

IEEE ComputerSociety 1 Software and Systems Engineering Vocabulary

An Enterprise Framework for Evaluating and Improving Software Quality

3.11 System Administration

SERVICE-ORIENTED MODELING FRAMEWORK (SOMF ) SERVICE-ORIENTED SOFTWARE ARCHITECTURE MODEL LANGUAGE SPECIFICATIONS

3rd Party Assurance & Information Governance outlook IIA Ireland Annual Conference Straightforward Security and Compliance

Technology Partners. Acceleratio Ltd. is a software development company based in Zagreb, Croatia, founded in 2009.

Basics of Internet Security

ISO 9001 : 2000 Quality Management Systems Requirements

EFFICIENT AND SECURE DATA PRESERVING IN CLOUD USING ENHANCED SECURITY

REPORT 2015/112 INTERNAL AUDIT DIVISION

Certification criteria for. Internal QMS Auditor Training Course

Department of Information Technology Remote Access Audit Final Report. January promoting efficient & effective local government

Business Process Modeling Information Systems in Industry ( )

1.1 The Nature of Software... Object-Oriented Software Engineering Practical Software Development using UML and Java. The Nature of Software...

Gallagher Vapour Recovery Monitoring

ONTOLOGY FOR MOBILE PHONE OPERATING SYSTEMS

CHECKLIST ISO/IEC 17021:2011 Conformity Assessment Requirements for Bodies Providing Audit and Certification of Management Systems

Intunex Oy Skillhive Service Description 1 / 6

EUROLAB Cook Book Doc No. 13 ELECTRONIC RECORDS

THE PROCESS APPROACH IN ISO 9001:2015

Chapter 2 ISO 9001:2008 QMS

NEOXEN MODUS METHODOLOGY

CAREER TRACKS PHASE 1 UCSD Information Technology Family Function and Job Function Summary

Cloud Computing: Legal Risks and Best Practices

Information Security Basic Concepts

Application of ontologies for the integration of network monitoring platforms

Industry Services Quality Management System

IRCA Briefing note ISO/IEC : 2011

Automated Test Approach for Web Based Software

Design and Development of Ontology for Risk Management in Software Project Management

The Infrastructure Audit Trail and Part 11

GUIDE 62. General requirements for bodies operating assessment and certification/registration of quality systems

Aadhaar. Security Policy & Framework for UIDAI Authentication. Version 1.0. Unique Identification Authority of India (UIDAI)

SOA REFERENCE ARCHITECTURE: WEB TIER

IT Vendor Due Diligence. Jennifer McGill CIA, CISA, CGEIT IT Audit Director Carolinas HealthCare System December 9, 2014

AUDITOR GUIDELINES. Responsibilities Supporting Inputs. Receive AAA, Sign and return to IMS with audit report. Document Review required?

Development of an Ontology for the Document Management Systems for Construction

Configuration Management

EXAM PREPARATION GUIDE

SPICE International Standard for Software Process Assessment

Information Security Management Systems

Do you know? "7 Practices" for a Reliable Requirements Management. by Software Process Engineering Inc. translated by Sparx Systems Japan Co., Ltd.

Compliance Response Edition 07/2009. SIMATIC WinCC V7.0 Compliance Response Electronic Records / Electronic Signatures. simatic wincc DOKUMENTATION

Transcription:

Ontology support for Management System Audit Programs Protégé Assisted Management System Auditing A. Gehrmann,, S. Ishizu Aoyama Gakuin University, Japan

Auditing and audit programs Caution: : The term audit is used in many domains: Management, Computer security, Finance etc., We refer to Management System Audits as defined in ISO 19011:2002: systematic,, independent and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled; ISO 19011:2002 clause 3.1 audit A set of audits for a defined purpose constitutes an audit program; ; e.g. evaluation of effectiveness of management system

Problem and approach 3 rd Party Management System Auditing is criticized for not delivering values; we see the difficulty to deal with organizational complexity as one main obstacle to value- adding auditing We understand the management of complexity of organizations as a main factor for improvement and propose the use of an audit ontology and protégé for enhancing the value of auditing

rigins of complexity in 3 rd party auditing.third Third party auditors have to deal with hundred of less familiar domain concepts in a very short time, but as human beings can cope only with 7 (+/- 2) concepts at a time.management standards are generic in nature and give raise to many interpretational issues,, therefore fundamental concepts such as Quality, Contract, Design Integrity and Availability of Information assets lacking often on clarity in the context of an organization and are not shared consistently between the auditee and the auditors; leads to conceptual inconsistencies / clashes.many Many requirements might be applicable : Quality and Information Security, IT risk management based, Quality Manuals, Internal Procedures, Auditee s s client s specification, Auditee s s client s s quality procedures.demand on documentation is high.organizational complexity is high (horizontal, vertical)

Conceptual clashes: Availability P800-30 (Appendix A): ISO/IEC 17799:2000 : he security goal that generates the ensuring that authorized quirement for protection against users have access to tentional or accidental attempts to information and associated Perform unauthorized deletion of assets when required data or Otherwise cause a denial of service or data Unauthorized use of system resources

uditing as on-going knowledge acquisition with Protégé Phase 4 Phase 1 Phase 3 Phase 2

uditing as on-going knowledge acquisition with protégé Phase 1

uditing as on-going knowledge acquisition with protégé Phase 2

uditing as on-going knowledge acquisition with protégé Phase 3

uditing as on-going knowledge acquisition with protégé Phase 4

Service: Total network solutions including information security solution A case: The auditee -Total Business Information Systems Ltd.- CEO Procurement Finance Technical service IT Hardware Software IT Security Installation Medical Network Testing General Windows Novell Development 5 Levels, 50 Engineers, 10 technical assistants, 10 clerical staff

The task ahead 12 Interviews at 5 levels covering variety of engineering fields Time available is limited to 3 working days 2 auditors CEO is non-technician, lawyer Managers: Former Hacker, MBA Students, Part-timer, timer, non-technical clerics 300 pages internal procedures and Management standard

Make conclusions nderstand Organizational Structure Identify Applicable Requirement Interpret Requirement In context Select Right Level in organization Select Right interviewee Gather facts Verify Common Understanding Move in Organization Link information Confirm findings

TBIS structure -organizational units-

Make conclusions derstand Organizational Structure Identify Applicable Requirement Interpret Requirement In context Select Right Level in organization Select Right interviewee Conduct interview, Gather facts Verify Common Understanding Move in Organization Link information Confirm findings

Selecting stored requirements

Make conclusions derstand Organizational Structure Identify Applicable Requirement erpret Requirement In context of a process Select Right Level in organization Select Right interviewee Gather facts Verify Common Understanding Move in Organization Link information Confirm findings

Selecting required processes and activities

Make conclusions derstand Organizational Structure Identify Applicable Requirement Interpret Requirement In context Select Right Level in organization Select Right interviewee Conduct interview, Gather facts Verify Common Understanding Move in Organization Link information Confirm findings

Recording an interview

Make conclusions derstand Organizational Structure Identify Applicable Requirement Interpret Requirement In context Select Right Level in organization Select Right interviewee Gather facts Refer to controlled concepts Move in Organization Link information Confirm findings

oncept verification quirement selection uirement verification Access to controlled concepts

Make conclusions derstand Organizational Structure Identify Applicable Requirement Interpret Requirement In context Select Right Level in organization Select Right interviewee Gather facts Verify Common Understanding Move in Organization Link information Confirm findings

Make conclusions derstand Organizational Structure Identify Applicable Requirement Interpret Requirement In context Select Right Level in organization Select Right interviewee Gather facts Verify Common Understanding Move in Organization Link information Confirm findings

The audit console in Protege Organizational Units

Make conclusions derstand Organizational Structure Identify Applicable Requirement Interpret Requirement In context Select Right Level in organization Select Right interviewee Gather facts Verify Common Understanding Move in Organization Review situations, Link information Confirm findings

Visualization of interview topics

Make conclusions derstand Organizational Structure Identify Applicable Requirement Interpret Requirement In context Select Right Level in organization Select Right interviewee Gather facts Verify Common Understanding Move in Organization Review situations, Link information Confirm findings

Summary - Key functions of an audit ontology Conduct systematically the audit Document audit process for obtaining audit evidence Evaluating evidence Determine the extent to which the audit criteria are fulfilled Protégé for systematic conduct and planning; Protégé as organizer Protégé as documentation tool Protégé as evaluation support tool Protégé for keeping track audit findings

Solutions for coping with complexity with a Protégé audit ontology. Protégé helps to organize concepts and make it possible to manage hundreds of them at a time. An audit ontology helps to identify conceptual clashes and helps to understand generic concepts in the context. Audit requirements are retrievable and their relationship are linked to concepts and required activities. Audit documentation can be prepared on the fly by using transformation for XML documents. Teams can exchange ontologies for improved communication. Organizational complexity can be managed by using an organizational model in the audit ontology

Usability of an audit ontology in protégé se/phase Description Benefits Obstacles dit planning Modeling of organization structure and organizational artifact Fast understanding by visualization and taxonomies Requires understanding of ontology concepts -site audit Creation of instances of organization concepts Linking artifacts Auditors have pre- defined concepts available Requires a reasonable degree of skill to use protégé Speed problems. dit cumentation Is required but not a purpose in itself Knowledge base stored in XML Audit findings and conclusions extracted Need customization of user interface/print/representation mmunication thin team Necessary for auditing in a team Instantaneous High technical requirement Understandability of knowledge representation -usability of owledge Currently not the focus of auditing; missed chance Domain vocabulary can be extended Usage in IT projects Part of system none

Future applications / expectations Expectation about features of protégé : Speed improvements (drawing, visualization) Possibility for customizing interface for knowledge acquisation Build-in in documentation customizing Implementation in OWL for reasoning and consistency Remote login and sharing ontology over distributed clients Import of industry ontologies SUO Mobile devices: tablet computer Protégé as server component for customized clients tool (files) for simplifying interface

Q/A