Legal compliance; Legal requirements; Security standards; General Data Protection Regulation
Résumé :
[en] Achieving compliance with legal regulations is no easy task. Normally, laws state general requirements but do not provide clear parameters to determine when such requirements are met. On a different level, industrial standards and best practices define specific objectives that can be certified by means of auditing procedures from qualified bodies. Implementing a standard does not per se guarantee legal compliance, with the rare exception when the standard is also endorsed by the law itself. But standards and laws in the same domain may have overlaps and correlations, so adopting the former may provide an argument to demonstrate that adequate measures were taken to achieve legal compliance. In this paper, we introduce a framework that, using state-of-the-art Natural Language Semantics techniques, helps process legal documents and standards to build a knowledge base to store their logic representations, and the correlations between them. The knowledge base will help legal experts assess what requirements of the law are met by the standard and, consequently, recognize what requirements still need to be implemented to fill the remaining gaps. An application of the framework is exemplified by comparing a provision of the European General Data Protection Regulation against the ISO/IEC 27001:2013 standard.
Disciplines :
Ingénierie, informatique & technologie: Multidisciplinaire, généralités & autres
Auteur, co-auteur :
BARTOLINI, Cesare ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
GIURGIU, Andra ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
LENZINI, Gabriele ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
ROBALDO, Livio ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
A Framework to Reason about the Legal Compliance of Security Standards
Date de publication/diffusion :
novembre 2016
Nom de la manifestation :
Tenth International Workshop on Juris-informatics (JURISIN)
Lieu de la manifestation :
Kanagawa, Japon
Date de la manifestation :
from 14-11-2016 to 15-11-2016
Manifestation à portée :
International
Titre de l'ouvrage principal :
Proceedings of the Tenth International Workshop on Juris-informatics (JURISIN)
Peer reviewed :
Peer reviewed
Focus Area :
Law / European Law
Projet européen :
H2020 - 690974 - MIREL - MIREL - MIning and REasoning with Legal texts