areas in an homogeneous way, iv) non-invasive so-
lutions (i.e. not requiring deployments in organiza-
tions), and v) a compliance management life cycle in-
cluding adapted activities for the specific context.
6 CONCLUSIONS
This work proposes a comprehensive approach to
compliance management in inter-organizational ser-
vice integration platforms. The approach defines a
compliance management life cycle for this specific
context and a common framework to homogeneously
manage compliance issues.
The life cycle includes four main phases: setup,
engineering, control and analysis. The engineer-
ing phase comprises compliance modeling, specifi-
cation, development and deployment. The control
phase comprises system-level compliance control and
business-level compliance control.
The common framework includes conceptual
models and components that allow managing aspects
of compliance through the whole life cycle and within
different compliance areas in an homogeneous way.
Future work consists in completing the specifica-
tion of the compliance policy language to be used in
the approach. This language is inspired in XACML,
extending it to not only deal with access control is-
sues. The example in (Gonz
´
alez and Ruggia, 2017)
shows how compliance policies would look like. In
addition, we plan to continue advancing in the eval-
uation of the technical feasibility of the approach
through the development of prototypes. Finally, we
aim to address other compliance areas such as privacy
in the e-health domain.
REFERENCES
Abin, J., Nemeth, H., and Friedmann, I. (2015). Sys-
tems architecture for a nationwide healthcare system.
In MEDINFO 2015: Proceedings of the 15th World
Congress on Health and Biomedical Informatics.
El Kharbili, M. (2012). Business process regulatory com-
pliance management solution frameworks: A compar-
ative evaluation. In Proceedings of the Eighth Asia-
Pacific Conference on Conceptual Modelling - Volume
130, APCCM ’12. Australian Computer Society, Inc.
Elgammal, A., Turetken, O., van den Heuvel, W.-J., and
Papazoglou, M. (2016). Formalizing and appling
compliance patterns for business process compliance.
Software & Systems Modeling, 15(1):119–146.
Golluscio, E., Thompson, J., and Guttridge, K. (2016). Mar-
ket Guide for Hybrid Integration Platform-Enabling
Technologies. Technical Report G00290089, Gartner.
Gonz
´
alez, L., Echevarr
´
ıa, A., Morales, D., and Ruggia, R.
(2016). An e-government interoperability platform
supporting personal data protection regulations. CLEI
Electronic Journal, 19:8 – 8.
Gonz
´
alez, L. and Ruggia, R. (2011). Addressing QoS issues
in service based systems through an adaptive ESB in-
frastructure. In 6th Workshop on Middleware for Ser-
vice Oriented Computing - MW4SOC’11. ACM Press.
Gonz
´
alez, L. and Ruggia, R. (2015). A reference ar-
chitecture for integration platforms supporting cross-
organizational collaboration. In Proceedings of 17th
International Conference on Information Integration
and Web-based Applications &Services. ACM Press.
Gonz
´
alez, L. and Ruggia, R. (2017). Towards a middle-
ware and policy-based approach to compliance man-
agement for collaborative organizations interactions.
In Proceedings of the 12th International Conference
on Software Technologies. SCITEPRESS.
Gonz
´
alez, L., Ruggia, R., Abin, J., Llamb
´
ıas, G., Sosa,
R., Rienzi, B., Bello, D., and
´
Alvarez, F. (2012).
A service-oriented integration platform to support a
joined-up e-government approach: The uruguayan ex-
perience. In Advancing Democracy, Government and
Governance, volume 7452 of Lecture Notes in Com-
puter Science. Springer Berlin Heidelberg.
Knuplesch, D., Reichert, M., Fdhila, W., and Rinderle-
Ma, S. (2013). On enabling compliance of cross-
organizational business processes. In Daniel, F.,
Wang, J., and Weber, B., editors, Business Pro-
cess Management, pages 146–154, Berlin, Heidel-
berg. Springer Berlin Heidelberg.
Koliadis and Ghose (2008). Service compliance: towards
electronic compliance programs. Technical report.
Pidre, S., Gonz
´
alez, Mendoza, R., Pinatares, M., Granja,
N., Serra, F., and Ruggia, R. (2017). A data quality
aware enterprise service bus for e-health integration
platforms. In 2017 XLIII Latin American Computer
Conference (CLEI). IEEE.
Sackmann, S. and K
¨
ahmer, M. (2008). Expdt: A
policy-based approach for automating compliance.
WIRTSCHAFTSINFORMATIK, 50(5):366–374.
Tran, Zdun, Holmes, Oberortner, Mulo, and Dustdar
(2012). Compliance in service-oriented architectures:
A model-driven and view-based approach. Informa-
tion and Software Technology, 54(6).
ICSOFT 2018 - 13th International Conference on Software Technologies
696