French Caldwell, J. A. W. (2013). Magic quadrant for en-
terprise governance, risk and compliance platforms
(Gartner).
G
´
omez-Sebasti
`
a, I.,
´
Alvarez-Napagao, S., V
´
azquez-
Salceda, J., and Felipe, L. O. (2012). Towards run-
time support for norm change from a monitoring per-
spective. In Ossowski, S., Toni, F., and Vouros,
G. A., editors, Proceedings of the First International
Conference on Agreement Technologies, AT 2012,
Dubrovnik, Croatia, October 15-16, 2012, volume
918 of CEUR Workshop Proceedings, pages 71–85.
CEUR-WS.org.
Governatori, G., Hoffmann, J., Sadiq, S., and Weber, I.
(2009). Detecting regulatory compliance for busi-
ness process models through semantic annotations.
In Ardagna, D., Mecella, M., and Yang, J., editors,
Business Process Management Workshops, volume 17
of Lecture Notes in Business Information Processing,
pages 5–17. Springer Berlin Heidelberg.
Governatori, G. and Rotolo, A. (2008a). Changing legal
systems: Abrogation and annulment part I: revision of
defeasible theories. In van der Meyden, R. and van der
Torre, L., editors, Deontic Logic in Computer Science,
9th International Conference, DEON 2008, Luxem-
bourg, Luxembourg, July 15-18, 2008. Proceedings,
volume 5076 of Lecture Notes in Computer Science,
pages 3–18. Springer.
Governatori, G. and Rotolo, A. (2008b). Changing legal
systems: Abrogation and annulment. part II: tempo-
ralised defeasible logic. In Boella, G., Pigozzi, G.,
Singh, M. P., and Verhagen, H., editors, Third Inter-
national Workshop on Normative Multiagent Systems
- NorMAS 2008, Luxembourg, July 15-16, 2008. Pro-
ceedings, pages 112–127.
Koehler, J. (2011). The process-rule continuum - can
BPMN & SBVR cope with the challenge? In Hofre-
iter, B., Dubois, E., Lin, K., Setzer, T., Godart, C.,
Proper, E., and Bodenstaff, L., editors, 13th IEEE
Conference on Commerce and Enterprise Comput-
ing, CEC 2011, Luxembourg-Kirchberg, Luxembourg,
September 5-7, 2011, pages 302–309. IEEE Computer
Society.
Liu, Y., M
¨
uller, S., and Xu, K. (2007). A static compliance-
checking framework for business process models.
IBM Systems Journal, 46(2):335–362.
Ly, L. T., Knuplesch, D., Rinderle-Ma, S., G
¨
oser, K.,
Pfeifer, H., Reichert, M., and Dadam, P. (2010).
Seaflows toolset - compliance verification made easy
for process-aware information systems. In Soffer, P.
and Proper, E., editors, Information Systems Evolution
- CAiSE Forum 2010, Hammamet, Tunisia, June 7-9,
2010, Selected Extended Papers, volume 72 of Lec-
ture Notes in Business Information Processing, pages
76–91. Springer.
Neiger, D., Churilov, L., zur Muehlen, M., and Rosemann,
M. (2006). Integrating risks in business process mod-
els with value focused process engineering. In Ljung-
berg, J. and Andersson, M., editors, Proceedings of
the Fourteenth European Conference on Information
Systems, ECIS 2006, G
¨
oteborg, Sweden, 2006, pages
1606–1615.
Racz, N., Weippl, E., and Seufert, A. (2011). Governance,
risk & compliance (GRC) software - an exploratory
study of software vendor and market research perspec-
tives. In Proceedings of the 2011 44th Hawaii Inter-
national Conference on System Sciences, HICSS ’11,
pages 1–10, Washington, DC, USA. IEEE Computer
Society.
Racz, N., Weippl, E. R., and Seufert, A. (2010). A frame
of reference for research of integrated governance,
risk and compliance (GRC). In Decker, B. D. and
Schaum
¨
uller-Bichl, I., editors, Communications and
Multimedia Security, 11th IFIP TC 6/TC 11 Interna-
tional Conference, CMS 2010, Linz, Austria, May 31
- June 2, 2010. Proceedings, volume 6109 of Lecture
Notes in Computer Science, pages 106–117. Springer.
Sadiq, S. W., Governatori, G., and Namiri, K. (2007). Mod-
eling control objectives for business process compli-
ance. In Alonso, G., Dadam, P., and Rosemann, M.,
editors, Business Process Management, 5th Interna-
tional Conference, BPM 2007, Brisbane, Australia,
September 24-28, 2007, Proceedings, volume 4714 of
Lecture Notes in Computer Science, pages 149–164.
Springer.
Sch
¨
afer, T., Fettke, P., and Loos, P. (2011). Towards an
integration of GRC and BPM - requirements changes
for compliance management caused by externally in-
duced complexity drivers. In Daniel, F., Barkaoui,
K., and Dustdar, S., editors, Business Process Man-
agement Workshops - BPM 2011 International Work-
shops, Clermont-Ferrand, France, August 29, 2011,
Revised Selected Papers, Part II, volume 100 of Lec-
ture Notes in Business Information Processing, pages
344–355. Springer.
Sinur, J. (2009). The art and science of rules vs. process
flows (Gartner Research Report G00166408).
Sunkle, S., Kholkar, D., Rathod, H., and Kulkarni, V.
(2014). Incorporating directives into enterprise TO-
BE architecture. In Grossmann, G., Hall
´
e, S.,
Karastoyanova, D., Reichert, M., and Rinderle-Ma,
S., editors, 18th IEEE International Enterprise Dis-
tributed Object Computing Conference Workshops
and Demonstrations, EDOC Workshops 2014, Ulm,
Germany, September 1-2, 2014, pages 57–66. IEEE.
Sunkle, S., Roychoudhury, S., and Kulkarni, V. (2013).
Using Intentional and System Dynamics Modeling
to Address WHYs in Enterprise Architecture. In
Cordeiro, J., Marca, D. A., and van Sinderen, M., edi-
tors, ICSOFT, pages 24–31. SciTePress.
Switzer, C. S., Suri, A., Kapoor, G., and Nazemoff, V.
(2013). Governance, risk management, and compli-
ance: Creating the right grc strategy for your company
Books24x7.
Vicente, P. and da Silva, M. M. (2011). A conceptual model
for integrated governance, risk and compliance. In
Mouratidis, H. and Rolland, C., editors, Advanced In-
formation Systems Engineering - 23rd International
Conference, CAiSE 2011, London, UK, June 20-24,
2011. Proceedings, volume 6741 of Lecture Notes in
Computer Science, pages 199–213. Springer.
Toward a Holistic Method for Regulatory Change Management
223