Reference : A Framework to Reason about the Legal Compliance of Security Standards
Scientific congresses, symposiums and conference proceedings : Paper published in a book
Engineering, computing & technology : Multidisciplinary, general & others
Law / European Law
http://hdl.handle.net/10993/28786
A Framework to Reason about the Legal Compliance of Security Standards
English
Bartolini, Cesare mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) >]
Giurgiu, Andra mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) >]
Lenzini, Gabriele mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Robaldo, Livio mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) >]
Nov-2016
Proceedings of the Tenth International Workshop on Juris-informatics (JURISIN)
Yes
No
International
Tenth International Workshop on Juris-informatics (JURISIN)
from 14-11-2016 to 15-11-2016
Kanagawa
Japan
[en] Legal compliance ; Legal requirements ; Security standards ; General Data Protection Regulation
[en] Achieving compliance with legal regulations is no easy task. Normally, laws state general requirements but do not provide clear parameters to determine when such requirements are met. On a different level, industrial standards and best practices define specific objectives that can be certified by means of auditing procedures from qualified bodies. Implementing a standard does not per se guarantee legal compliance, with the rare exception when the standard is also endorsed by the law itself. But standards and laws in the same domain may have overlaps and correlations, so adopting the former may provide an argument to demonstrate that adequate measures were taken to achieve legal compliance. In this paper, we introduce a framework that, using state-of-the-art Natural Language Semantics techniques, helps process legal documents and standards to build a knowledge base to store their logic representations, and the correlations between them. The knowledge base will help legal experts assess what requirements of the law are met by the standard and, consequently, recognize what requirements still need to be implemented to fill the remaining gaps. An application of the framework is exemplified by comparing a provision of the European General Data Protection Regulation against the ISO/IEC 27001:2013 standard.
Researchers ; Professionals ; Others
http://hdl.handle.net/10993/28786
H2020 ; 690974 - MIREL - MIREL - MIning and REasoning with Legal texts

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Open access
main.pdfAuthor postprint510.56 kBView/Open

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.