QOMPLIANCE: Declarative Data-Centric Policy Compliance

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Authors

External Research Organisations

  • Delft University of Technology
  • IBM Zurich Research Laboratory
View graph of relations

Details

Original languageEnglish
Title of host publicationProceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (electronic)9798350341072
ISBN (print)979-8-3503-4108-9
Publication statusPublished - 2023
Event2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023 - Nadi, Fiji
Duration: 4 Dec 20236 Dec 2023

Abstract

Data compliance is essential in industry applications to ensure that organizations do not run afoul of data protection and privacy legislation. Geographically distributed data is an especially relevant topic because of recent developments in cross-border data protection agreements, e.g., between the United States and the European Union. We report our experience of designing and implementing QOMPLIANCE, a system for automated data-centric compliance evaluation in cloud environments. Our approach fills a gap in the research for higher-level data-centric compliance systems with a particular focus on geographically distributed data. Its declarative and extensible policy model allows for defining policies that can govern data movements across borders and is intended to be understandable without explicit knowledge of the governed data by employing a tag-based abstraction layer. The particular challenge is to automate data-centric policy compliance on data movements in a maintainable manner. QOMPLIANCE analyzes SQL-defined data movements to extract what data is being addressed and combines this information with additional attributes to statically match policies. Policies decide whether data movements are allowed and specify requirements on the query and the execution that should be enforced. We provide a qualitative comparison between our approach and related work, and we performed a performance analysis which shows that compliance evaluation can be done in seconds for large sets of policies.

Keywords

    compliance, data processing, policies

ASJC Scopus subject areas

Cite this

QOMPLIANCE: Declarative Data-Centric Policy Compliance. / Oudejans, Daan; Zorin, Anton; Rellermeyer, Jan S.
Proceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023. Institute of Electrical and Electronics Engineers Inc., 2023.

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Oudejans, D, Zorin, A & Rellermeyer, JS 2023, QOMPLIANCE: Declarative Data-Centric Policy Compliance. in Proceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023. Institute of Electrical and Electronics Engineers Inc., 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023, Nadi, Fiji, 4 Dec 2023. https://doi.org/10.1109/CSDE59766.2023.10487688
Oudejans, D., Zorin, A., & Rellermeyer, J. S. (2023). QOMPLIANCE: Declarative Data-Centric Policy Compliance. In Proceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023 Institute of Electrical and Electronics Engineers Inc.. https://doi.org/10.1109/CSDE59766.2023.10487688
Oudejans D, Zorin A, Rellermeyer JS. QOMPLIANCE: Declarative Data-Centric Policy Compliance. In Proceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023. Institute of Electrical and Electronics Engineers Inc. 2023 doi: 10.1109/CSDE59766.2023.10487688
Oudejans, Daan ; Zorin, Anton ; Rellermeyer, Jan S. / QOMPLIANCE : Declarative Data-Centric Policy Compliance. Proceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023. Institute of Electrical and Electronics Engineers Inc., 2023.
Download
@inproceedings{094e7b85948041488e777147dd23d6f1,
title = "QOMPLIANCE: Declarative Data-Centric Policy Compliance",
abstract = "Data compliance is essential in industry applications to ensure that organizations do not run afoul of data protection and privacy legislation. Geographically distributed data is an especially relevant topic because of recent developments in cross-border data protection agreements, e.g., between the United States and the European Union. We report our experience of designing and implementing QOMPLIANCE, a system for automated data-centric compliance evaluation in cloud environments. Our approach fills a gap in the research for higher-level data-centric compliance systems with a particular focus on geographically distributed data. Its declarative and extensible policy model allows for defining policies that can govern data movements across borders and is intended to be understandable without explicit knowledge of the governed data by employing a tag-based abstraction layer. The particular challenge is to automate data-centric policy compliance on data movements in a maintainable manner. QOMPLIANCE analyzes SQL-defined data movements to extract what data is being addressed and combines this information with additional attributes to statically match policies. Policies decide whether data movements are allowed and specify requirements on the query and the execution that should be enforced. We provide a qualitative comparison between our approach and related work, and we performed a performance analysis which shows that compliance evaluation can be done in seconds for large sets of policies.",
keywords = "compliance, data processing, policies",
author = "Daan Oudejans and Anton Zorin and Rellermeyer, {Jan S.}",
note = "Publisher Copyright: {\textcopyright} 2023 IEEE.; 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023 ; Conference date: 04-12-2023 Through 06-12-2023",
year = "2023",
doi = "10.1109/CSDE59766.2023.10487688",
language = "English",
isbn = "979-8-3503-4108-9",
booktitle = "Proceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
address = "United States",

}

Download

TY - GEN

T1 - QOMPLIANCE

T2 - 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023

AU - Oudejans, Daan

AU - Zorin, Anton

AU - Rellermeyer, Jan S.

N1 - Publisher Copyright: © 2023 IEEE.

PY - 2023

Y1 - 2023

N2 - Data compliance is essential in industry applications to ensure that organizations do not run afoul of data protection and privacy legislation. Geographically distributed data is an especially relevant topic because of recent developments in cross-border data protection agreements, e.g., between the United States and the European Union. We report our experience of designing and implementing QOMPLIANCE, a system for automated data-centric compliance evaluation in cloud environments. Our approach fills a gap in the research for higher-level data-centric compliance systems with a particular focus on geographically distributed data. Its declarative and extensible policy model allows for defining policies that can govern data movements across borders and is intended to be understandable without explicit knowledge of the governed data by employing a tag-based abstraction layer. The particular challenge is to automate data-centric policy compliance on data movements in a maintainable manner. QOMPLIANCE analyzes SQL-defined data movements to extract what data is being addressed and combines this information with additional attributes to statically match policies. Policies decide whether data movements are allowed and specify requirements on the query and the execution that should be enforced. We provide a qualitative comparison between our approach and related work, and we performed a performance analysis which shows that compliance evaluation can be done in seconds for large sets of policies.

AB - Data compliance is essential in industry applications to ensure that organizations do not run afoul of data protection and privacy legislation. Geographically distributed data is an especially relevant topic because of recent developments in cross-border data protection agreements, e.g., between the United States and the European Union. We report our experience of designing and implementing QOMPLIANCE, a system for automated data-centric compliance evaluation in cloud environments. Our approach fills a gap in the research for higher-level data-centric compliance systems with a particular focus on geographically distributed data. Its declarative and extensible policy model allows for defining policies that can govern data movements across borders and is intended to be understandable without explicit knowledge of the governed data by employing a tag-based abstraction layer. The particular challenge is to automate data-centric policy compliance on data movements in a maintainable manner. QOMPLIANCE analyzes SQL-defined data movements to extract what data is being addressed and combines this information with additional attributes to statically match policies. Policies decide whether data movements are allowed and specify requirements on the query and the execution that should be enforced. We provide a qualitative comparison between our approach and related work, and we performed a performance analysis which shows that compliance evaluation can be done in seconds for large sets of policies.

KW - compliance

KW - data processing

KW - policies

UR - http://www.scopus.com/inward/record.url?scp=85190604997&partnerID=8YFLogxK

U2 - 10.1109/CSDE59766.2023.10487688

DO - 10.1109/CSDE59766.2023.10487688

M3 - Conference contribution

AN - SCOPUS:85190604997

SN - 979-8-3503-4108-9

BT - Proceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering, CSDE 2023

PB - Institute of Electrical and Electronics Engineers Inc.

Y2 - 4 December 2023 through 6 December 2023

ER -

By the same author(s)