Score
Designs, implements, and evaluates technical controls, processes, documentation, test plans, and continuous-monitoring practices needed to achieve and maintain compliance with regulatory frameworks; this includes preparing authorization packages, evidence, and remediation plans for FedRAMP and similar cloud/security standards.
Traditional compliance assessments rely on point-in-time audits and self-attestation, which struggle to enable continuous, cross-organizational, and traceable verification of security controls in multi-vendor environments. This work proposes a permissioned blockchain-based Third-Party Risk Assessment (TPRA) framework that transforms static compliance into a dynamic, repeatable, and verifiable continuous governance mechanism through smart contract–automated evaluation workflows, multi-party governance protocols, and longitudinal state tracking. The study contributes an actionable TPRA architecture, along with complementary compliance maturity metrics and a qualitative model, enabling quantification and long-term validation of security control implementation maturity across organizational boundaries and time periods.
This study addresses the lack of systematic comparative analysis in business process compliance monitoring, particularly for non-conformance checking techniques. Through a systematic literature review (SLR), process mining, compliance modeling, and qualitative comparative analysis, it maps real-world applications across domains, operational workflows, technical foundations, and result representations. The analysis identifies key implementation barriers—especially pervasive human dependence and the absence of standardized evaluation criteria. As the first structured survey framework dedicated to non-conformance checking, the study introduces a standardized, multi-dimensional evaluation framework that clarifies commonalities and distinctions across the technical landscape. It further proposes an extensible theoretical pathway and practical guidelines for automated compliance monitoring. This work provides a methodological foundation and strategic direction for both academic research and industrial deployment. (149 words)
Agile development methodologies struggle to comply with stringent airworthiness standards—such as DO-178C—in safety-critical aerospace software, due to inherent tensions between iterative flexibility and rigorous certification requirements. Method: This paper introduces CertiA360, an automated tool for end-to-end requirement traceability and compliance verification across agile iterations. Built upon DO-178C/DO-330, it features a certifiable architecture supporting dynamic requirement maturity assessment, change-driven verification and validation (V&V) closure, and bidirectional traceability. Contribution/Results: CertiA360 uniquely integrates lightweight agile practices—including user story mapping and incremental delivery—with high-assurance certification constraints, effectively bridging the gap between agility and regulatory rigidity. Empirical evaluation demonstrates a ~60% reduction in manual traceability effort, a 40% decrease in change-response cycle time, and full compliance with EASA/FAA tool qualification and process trustworthiness requirements.
This study addresses the challenges posed by the proliferation, complexity, and expanding scope of regulatory requirements in software engineering, which hinder their systematic integration into development processes. To tackle this issue, the paper proposes a viewpoint-centered, artifact-based approach to regulatory requirements engineering. The approach innovatively integrates viewpoint analysis with artifact modeling to develop the AM4RRE (Artifact Modeling for Regulatory Requirements Engineering) framework, which facilitates cross-functional collaboration and ensures consistency in compliance-driven design. Preliminary validation demonstrates that AM4RRE effectively bridges the gap between organizational regulatory processes and software development practices, enabling a shift from ad hoc compliance responses toward systematic integration. This foundational work paves the way for further empirical investigation into scalable and sustainable regulatory compliance in software engineering.
This work addresses the inefficiency and high cost of compliance testing in highly regulated domains, where current practices rely on manual translation of regulations into test cases by experts. While large language models (LLMs) offer automation potential, they often suffer from hallucination, and existing hybrid approaches still require significant human modeling effort. To overcome these limitations, the authors propose RAFT, a novel framework that explicitly extracts implicit regulatory knowledge from multiple LLMs and leverages an adaptive purification-aggregation strategy with dynamic prompt injection to automatically generate domain-specific meta-models, formalized requirements, and testability constraints—enabling fully automated, human-intervention-free compliance test generation. Experiments in financial, automotive, and power sectors demonstrate that RAFT achieves expert-level performance, significantly outperforming state-of-the-art methods while drastically reducing test case generation and review time.
This work addresses the inefficiency and inconsistency of manual compliance verification, particularly in indirect compliance scenarios involving third-party dependencies where accurate validation is challenging. To overcome these limitations, the paper proposes an automated compliance assessment framework based on Retrieval-Augmented Generation (RAG). The framework automatically extracts control questions from regulatory texts and aligns them with unstructured organizational documents, leveraging adaptive chunking, dynamic retrieval configuration, and in-context learning to significantly enhance assessment accuracy and relevance. Experimental results demonstrate that the system achieves an F1 score of 78% and a recall of 85% in real-world deployment, effectively reducing missed detections and substantially alleviating the burden of manual review.
本文提出AspisAI框架,通过将多种标准要求转化为机器可解释的模型并评估证据,解决多标准合规监测成本高、一致性差的问题。
本文提出一种模型,通过设计科学研究方法解决在软件工程中选择大型语言模型时面临的治理与合规难题,采用多层结构和评估协议以增强决策过程中的合规性。
This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.
This study addresses the challenges small and medium-sized enterprises face in fulfilling the full lifecycle compliance obligations of the EU Cyber Resilience Act by developing an open-source compliance platform. Methodologically, it introduces a "compliance chain" structure that seamlessly links risk assessments, controls, policies, and machine-attested evidence to technical documentation and EU declarations of conformity. Furthermore, the platform integrates ISO/IEC 27001, NIS2, and GDPR controls while incorporating AI-driven remediation and an automated evidence collection engine to enable end-to-end traceability. The proposed solution has been deployed across 43 organizations, and its efficacy in identifying and closing operational gaps was validated through an end-to-end SIEM/XDR case study.