Paper published in a book (Scientific congresses, symposiums and conference proceedings)
A Framework to Reason about the Legal Compliance of Security Standards
Bartolini, Cesare; Giurgiu, Andra; Lenzini, Gabriele et al.
2016In Proceedings of the Tenth International Workshop on Juris-informatics (JURISIN)
Peer reviewed
 

Files


Full Text
main.pdf
Author postprint (522.81 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Legal compliance; Legal requirements; Security standards; General Data Protection Regulation
Abstract :
[en] Achieving compliance with legal regulations is no easy task. Normally, laws state general requirements but do not provide clear parameters to determine when such requirements are met. On a different level, industrial standards and best practices define specific objectives that can be certified by means of auditing procedures from qualified bodies. Implementing a standard does not per se guarantee legal compliance, with the rare exception when the standard is also endorsed by the law itself. But standards and laws in the same domain may have overlaps and correlations, so adopting the former may provide an argument to demonstrate that adequate measures were taken to achieve legal compliance. In this paper, we introduce a framework that, using state-of-the-art Natural Language Semantics techniques, helps process legal documents and standards to build a knowledge base to store their logic representations, and the correlations between them. The knowledge base will help legal experts assess what requirements of the law are met by the standard and, consequently, recognize what requirements still need to be implemented to fill the remaining gaps. An application of the framework is exemplified by comparing a provision of the European General Data Protection Regulation against the ISO/IEC 27001:2013 standard.
Disciplines :
Engineering, computing & technology: Multidisciplinary, general & others
Author, co-author :
Bartolini, Cesare ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Giurgiu, Andra ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Lenzini, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Robaldo, Livio ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
External co-authors :
no
Language :
English
Title :
A Framework to Reason about the Legal Compliance of Security Standards
Publication date :
November 2016
Event name :
Tenth International Workshop on Juris-informatics (JURISIN)
Event place :
Kanagawa, Japan
Event date :
from 14-11-2016 to 15-11-2016
Audience :
International
Main work title :
Proceedings of the Tenth International Workshop on Juris-informatics (JURISIN)
Peer reviewed :
Peer reviewed
Focus Area :
Law / European Law
European Projects :
H2020 - 690974 - MIREL - MIREL - MIning and REasoning with Legal texts
Funders :
CE - Commission Européenne [BE]
Available on ORBilu :
since 04 November 2016

Statistics


Number of views
433 (38 by Unilu)
Number of downloads
505 (19 by Unilu)

Bibliography


Similar publications



Contact ORBilu