Obtaining secure business process models from an enterprise architecture considering security requirements

2021 ◽  
Vol ahead-of-print (ahead-of-print) ◽  
Author(s):  
Luis San Martín ◽  
Alfonso Rodríguez ◽  
Angélica Caro ◽  
Ignacio Velásquez

PurposeSecurity requirements play an important role in software development. These can be specified both in enterprise architecture models and in business processes. Enterprises increasingly carry out larger amounts of business processes where security plays a major role. Business processes including security can be automatically obtained from enterprise architecture models by applying a model-driven architecture approach, through a CIM to CIM transformation. The aim of this article is to present the specification of transformation rules for the correspondence between enterprise architecture and business process model elements focusing on security.Design/methodology/approachThis work utilizes motivational aspects of the ArchiMate language to model security in the business layer of enterprise architectures. Next, a set of transformation rules defined with the Atlas Transformation Language are utilized to obtain the correspondence of the enterprise architecture elements in a business process, modelled with a security extension of BPMN.FindingsA total of 19 transformation rules have been defined. These rules are more complex than element to element relations, as they take into consideration the context of the elements for establishing the correspondence. Additionally, the prototype of a tool that allows the automatic transformation between both models has been developed.Originality/valueThe results of this work demonstrate the possibility to tackle complex transformations between both models, as previous literature focuses on semantic correspondences. Moreover, the obtained models can be of use for software developers applying the model-driven approach.

2019 ◽  
Vol 25 (5) ◽  
pp. 908-922 ◽  
Author(s):  
Remco Dijkman ◽  
Oktay Turetken ◽  
Geoffrey Robert van IJzendoorn ◽  
Meint de Vries

Purpose Business process models describe the way of working in an organization. Typically, business process models distinguish between the normal flow of work and exceptions to that normal flow. However, they often present an idealized view. This means that unexpected exceptions – exceptions that are not modeled in the business process model – can also occur in practice. This has an effect on the efficiency of the organization, because information systems are not developed to handle unexpected exceptions. The purpose of this paper is to study the relation between the occurrence of exceptions and operational performance. Design/methodology/approach The paper does this by analyzing the execution logs of business processes from five organizations, classifying execution paths as normal or exceptional. Subsequently, it analyzes the differences between normal and exceptional paths. Findings The results show that exceptions are related to worse operational performance in terms of a longer throughput time and that unexpected exceptions relate to a stronger increase in throughput time than expected exceptions. Practical implications These findings lead to practical implications on policies that can be followed with respect to exceptions. Most importantly, unexpected exceptions should be avoided by incorporating them into the process – and thus transforming them into expected exceptions – as much as possible. Also, as not all exceptions lead to longer throughput times, continuous improvement should be employed to continuously monitor the occurrence of exceptions and make decisions on their desirability in the process. Originality/value While work exists on analyzing the occurrence of exceptions in business processes, especially in the context of process conformance analysis, to the best of the authors’ knowledge this is the first work that analyzes the possible consequences of such exceptions.


2021 ◽  
Vol 6 (3) ◽  
pp. 170
Author(s):  
Hilman Nuril Hadi

Business process model was created to make it easier for business process stakeholders to communicate and discuss the structure of the process more effectively and efficiently. Business process models can also be business artifacts and media that can be analyzed further to improve and maintain organizational competitiveness. To analyze business processes in a structured manner, the effect/results of the execution of business processes will be one of the important information. The effect/result of the execution of certain activities or a business process as a whole are useful for managing business processes, including for improvements related to future business processes. This effect annotation approach needs to be supported by business process modeling tools to assist business analysts in managing business processes properly. In previous research, the author has developed a plugin that supports business analysts to describe the effects semantically attached to activities in the Business Process Model and Notation (BPMN) business process model. In this paper, the author describes the unit testing process and its results on the plugin of semantic effect annotation that have been developed. Unit testing was carried out using the basic path testing technique and has obtained three test paths. The results of unit test for plugin are also described in this paper.


2014 ◽  
Vol 11 (2) ◽  
pp. 461-480 ◽  
Author(s):  
Nuno Castela ◽  
Paulo Dias ◽  
Marielba Zacarias ◽  
José Tribolet

Business process models are often forgotten after their creation and its representation is not usually updated. This appears to be negative as processes evolve over time. This paper discusses the issue of business process models maintenance through the definition of a collaborative method that creates interaction contexts enabling business actors to discuss about business processes, sharing business knowledge. The collaboration method extends the discussion about existing process representations to all stakeholders promoting their update. This collaborative method contributes to improve business process models, allowing updates based in change proposals and discussions, using a groupware tool that was developed. Four case studies were developed in real organizational environment. We came to the conclusion that the defined method and the developed tool can help organizations to maintain a business process model updated based on the inputs and consequent discussions taken by the organizational actors who participate in the processes.


2014 ◽  
Vol 17 (2) ◽  
Author(s):  
Jonas Montilva ◽  
Judith Barrios ◽  
Isabel Besembel ◽  
William Montilva

The successful application of Information Technologies (IT) in an organization depends on the business processes used for managing such technologies. It is widely recognized that the use of the Enterprise Architecture (EA) practice for organizing these technologies into a framework is a key factor for achieving a better IT - business alignment. This article presents a business process model for the IT Management that can be used in medium and large organizations as a framework for modelling and analysing their IT management processes. The main difference between the described model and others found in the literature is that our model places EA concept at the centre of the organization of IT Management activities. It provides a better definition, organization and comprehension of the essential and support IT management activities. The described model is being used in several organizations as a referential framework to improve their current IT Management processes.


2020 ◽  
pp. 464-478
Author(s):  
Loubna El Faquih ◽  
Mounia Fredj

In recent years, business process modeling has increasingly drawn the attention of enterprises. As a result of the wide use of business processes, redundancy problems have arisen and researchers introduced the variability management, in order to enhance the business process reuse. The most approach used in this context is the Configurable Process Model solution, which consists in representing the variable and the fixed parts together in a unique model. Due to the increasing number of variants, the configurable models become complex and incomprehensible, and their quality is therefore impacted. Most of research work is limited to the syntactic quality of process variants. The approach presented in this paper aims at providing a novel method towards syntactic verification and semantic validation of configurable process models based on ontology languages. We define validation rules for assessing the quality of configurable process models. An example in the e-healthcare domain illustrates the main steps of our approach.


The implementation of several modern concepts of enterprise architecture creation is analyzed and real-time business process generation is described. Cloud-based self-generated business service is constructed as a basis of the resulting concept with an aim to increase the flexibility of enterprise and introduce AaaS (architecture as a service). Under particular business request in form of correctly formulated strategic goal the generation of business process model is produced. The result of the generation is cross-cutting business process architecture model, which is approved or rejected/corrected by business owner expertise. During generation all necessary requirements for supporting resources, such as information, know-how, intellectual and professional skills, inputs and outputs, quality and operational risk limitations, control and monitoring, are formed. All formed requirements have to be satisfied by appropriate selections from the cloud facilities and again approved. Finally, after several iterations, the business model will be able to be realized in reality and could be executed with predicted results. Briefly, that means that certain sets of valued and weighted business process replicas are located in clouds and served in clouds. Thus, enterprise architecture becomes a regular service from clouds extending row of SOA in the name of AaaS. In addition, the advanced view on the topic is provided with an attempt to install a virtual SOA torrent that catches services from the internet and makes them available to customers and represents a business service basis for real-time business processes.


2019 ◽  
Vol 25 (7) ◽  
pp. 1867-1890 ◽  
Author(s):  
Megashnee Munsamy ◽  
Arnesh Telukdarie ◽  
Johannes Fresner

Purpose Sustainability is an accepted measure of business performance, with reductions in energy demand a commonly practised sustainability initiative by multinational corporations (MNCs). Traditional energy models have limited scope when applied to the entire MNC as the models exhibit high data and time intensity, high technical proficiency, specificity of application and omission of non-manufacturing activities. The purpose of this paper is to propose a process centric energy model (PCEM), which adopts a novel approach of applying business processes for business energy assessment and optimisation. Business processes are a fundamental requirement of MNCs across all sectors. The defining features of the proposed model are genericity, reproducibility, minimum user input data, reduced modelling time and energy evaluation of non-manufacturing activities. The approach forwards the adoption of Industry 4.0, a subset of which focuses on business process automation or part thereof. Design/methodology/approach A quantitative approach is applied in development of the PCEM. The methodology is demonstrated by application to the procure to pay and electroplating business processes. Findings The PCEM quantifies and optimises the business energy demand and associated carbon dioxide emissions of the procure to pay and electroplating business processes, validating the application of business processes. The application demonstrates minimum user inputs as only equipment operational parameters are required and minimum modelling time as business process models and optimisation options are pre-defined requiring only user modification. As MNCs have common business processes across multiple sites, once a business process energy demand is quantified, its inputs are applied as the default in the proceeding sites, only requiring updating. The model has no specialist skills requirement enabling business wide use and eliminating costs associated with training and expert’s services. The business processes applied in the evaluation are developed by the researchers and are not as comprehensive as those in actual MNCs, but is sufficiently detailed to accurately calculate an MNC energy demand. The model databases are not exhaustive of all resources found in MNCs. Originality/value This paper provides a new approach to MNC business energy assessment and optimisation. The model can be applied to MNEs across all sectors. The model allows the integration of manufacturing and non-manufacturing activities, as it occurs in practice, providing holistic business energy assessment and optimisation. The model analyses the impacts of the adoption of Industry 4.0 technologies on business energy demand, CO2 emission and personnel hours.


2014 ◽  
Vol 20 (6) ◽  
pp. 794-815 ◽  
Author(s):  
Xinwei Zhu ◽  
Jan Recker ◽  
Guobin Zhu ◽  
Flávia Maria Santoro

Purpose – Context-awareness has emerged as an important principle in the design of flexible business processes. The goal of the research is to develop an approach to extend context-aware business process modeling toward location-awareness. The purpose of this paper is to identify and conceptualize location-dependencies in process modeling. Design/methodology/approach – This paper uses a pattern-based approach to identify location-dependency in process models. The authors design specifications for these patterns. The authors present illustrative examples and evaluate the identified patterns through a literature review of published process cases. Findings – This paper introduces location-awareness as a new perspective to extend context-awareness in BPM research, by introducing relevant location concepts such as location-awareness and location-dependencies. The authors identify five basic location-dependent control-flow patterns that can be captured in process models. And the authors identify location-dependencies in several existing case studies of business processes. Research limitations/implications – The authors focus exclusively on the control-flow perspective of process models. Further work needs to extend the research to address location-dependencies in process data or resources. Further empirical work is needed to explore determinants and consequences of the modeling of location-dependencies. Originality/value – As existing literature mostly focusses on the broad context of business process, location in process modeling still is treated as “second class citizen” in theory and in practice. This paper discusses the vital role of location-dependencies within business processes. The proposed five basic location-dependent control-flow patterns are novel and useful to explain location-dependency in business process models. They provide a conceptual basis for further exploration of location-awareness in the management of business processes.


2016 ◽  
Vol 22 (3) ◽  
pp. 566-593 ◽  
Author(s):  
Julio Cesar Sampaio do Prado Leite ◽  
Flavia Maria Santoro ◽  
Claudia Cappelli ◽  
Thais Vasconcelos Batista ◽  
Fabiana Jack Nogueira Santos

Purpose – The purpose of this paper is to propose a representation scheme based on the i* strategic actor model to represent the process owner information and show how to incorporate this approach into the event driven process chain and Business Process Modeling Notation-BPMN meta-models and also into the aspect-oriented business process modeling (BPM) context. Design/methodology/approach – The authors use a case study in a real setting to evaluate the proposal and a controlled experiment to get more evidence about its relevance. Findings – The authors presented evidence both from a case study in a real-world library showing the importance of representing – previously unavailable – process owner information, and from an experiment which involved participants analyzing the same models of the case study, confirming the preliminary evidences. It is important to stress the recognition that the proposed representation provided more transparency, in terms of ownership, than the usual BPM models. These benefits are due to the combination of the aspect-oriented approach and the strategic actor model, providing ownership information in a more transparent way. Originality/value – The authors not only argue the importance of clearly established process ownership, both of the core process and the aspectual process, but also the authors presented an approach to represent the actor involved in process and aspect ownership as an instantiation of the i* strategic actor. Using this approach, the process owner can be defined in terms of actors instead of the activities performed. It is also possible to define the aspect owner and to include the aspectual process concept in the business process model.


Author(s):  
Olga Korzachenko ◽  
Vadim Getman

Improvement of Business-Activities in Telecommunication Enterprises by the eTOM Business-Process Structural Model Implementation For now, in front of telecommunication branch enterprises of Ukraine, there is a problem of activity improvement with the purpose of granting high-quality services and maintenance of competitive position, both on internal, and on a foreign market. To solve this problem, telecommunication companies appropriate to use the mechanisms of business-oriented process management and improvement of end-to-end business-processes. The purpose of this article is a choice of effective business-process model that will allow telecommunications companies to provide modern, high quality and cost competitive services. During research, conditions of the telecommunication branch enterprises of Ukraine were investigated and key problems of their activity were revealed. Existing business-process models have been considered and analyzed and the optimal model was chosen, according to the put criteria. By results of the analysis a conclusion was drawn, that to the enterprises for business-process modeling is expedient for using eTOM - high-level system business-oriented model aimed for providing of any technological services, including IT. As advantages from introduction eTOM at the Ukrainian enterprises were analyzed.


Sign in / Sign up

Export Citation Format

Share Document