<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Improving Operational Risk Management Systems by Formalizing the Basel II Regulation with Goal Models and the ISO/IEC 15504 Approach</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>André Rifaut</string-name>
          <email>Andre.Rifaut@tudor.lu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Christophe Feltus</string-name>
          <email>Christophe.Feltus@tudor.lu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Centre de Recherche Public Henri Tudor</institution>
          ,
          <addr-line>29, Avenue John F.Kennedy, L-1855 Luxembourg-Kirchberg</addr-line>
          ,
          <country country="LU">Luxembourg</country>
        </aff>
      </contrib-group>
      <fpage>831</fpage>
      <lpage>837</lpage>
      <abstract>
        <p>The bankruptcy of financial institutions shows the rapid changes in the risks profiles of financial systems and processes. Although financial institutions have always managed the operational risks, the profile of this kind of risks is changing due to the increasing international competitive pressure and the evolution of the financial institutions' operational systems relying more and more on IT systems. This paper reports the results of the joint research with the CSSF [1] focusing on the formalization of both the Basel II Accord and compliant operational risk management (ORM) systems implementations. This formalization uses concepts of the ISO/IEC 15504 process assessment standard and the concepts of strategy and policy. This structure of the model ensures the traceability between the Basel II Accord and compliant ORM systems implementations, improves the formal validation of those systems and is more adequate to represent all organizational levels of financial institutions.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1 Introduction</title>
      <p>
        In Luxemburg, the stability of the financial system is at the core of the economic
stability of the country. The CSSF [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], which is the official authority for financial
institutions supervision, has the responsibility to define financial regulations and
ensure their fulfillment. This task is not easy because more and more international
regulations are introduced, such as the IFRS [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], Sarbanes-Oxley Act (SoX) [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and the
Basel II Accord [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Audit managers, risk managers (including security managers),
and compliance managers have developed standards addressing those regulations. For
instance, COSO [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], CobIT [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], ITIL [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] and ERM [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] are governance and risk
management standards. However, up to now there is nearly no integration between the
regulations themselves and also between those standards. A joint research with the
CSSF aims at defining a method for ensuring a correct implementation of financial
systems compliant to Basel II regulation. The results [
        <xref ref-type="bibr" rid="ref21 ref6">6,21</xref>
        ] are based on quality
methods and techniques, mainly goal-based models and analyses used in
goaloriented requirements engineering (GORE) [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The originality of the work lies in the
formalization of the Basel II Accord and Operational Risk Management (ORM)
systems by using concepts of the ISO/IEC 15504 process assessment standard [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] and
the concepts of strategy and policy. This gives an adequate structure of the models at
all organizational levels of financial institutions, ensures the formal traceability
between the Basel II Accord and ORM systems, and improves their formal validation.
      </p>
      <p>
        This paper summarizes and extends the results of the joint research with the CSSF,
focusing on the formalization of both Basel II Accord and compliant (ORM) systems
implementations. For a deeper understanding of the concepts presented here, see
complementary information on the research results, the ISO/IEC 15504 standard, the
Basel II Accord, and other standards such as ITIL on the CSSF website [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] (freely
available). The next section presents the main goals of this research and the
preliminary results. Section 3 shows the technique that has been created in the context of the
real case study concerning the Basel II Accord regulation and its implementation in
financial institutions. The last section summarizes the main results of this project and
presents the future works planned in the follow-up research projects.
2 The Implementation of ORM Systems Compliant to Basel II.
The Basel Committee has defined the operational risk as follows: it is the risk of loss
resulting from inadequate or failed internal processes, people and systems or from
external events. (§644 in [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]). As such, the operational risk encompasses all risks
occurring at the operational and technical levels (see Fig. 1), in particular, all risks of
the IT Software Engineering (SE) Processes (risks that concern project management,
requirements analysis, design, security, ...). The methods used in IT SE (e.g. for
safety and security analyses) do not cover the analysis of this very broad scope of
risks.
      </p>
      <p>The need for practical techniques is critical in order to help business units’
manager to efficiently implement the core business processes that are under their
responsibility. Indeed, not only the Basel II Accord is imposing constraints on those core
financial processes, but also the other regulations (e.g. SoX, IFRS) are interfering on
the same processes. Moreover, each regulation stresses the importance on different
but inter-related aspects. For instance, SoX stresses the importance on the reporting
system also concerned by the ORM of Basel II Accord. In addition to that, decisions
about ORM system implementation must be made at all organizational levels :
strategic, tactical, operational and technical. The existence of operational risks within every
business process imposes a tight integration between new ORM systems and each
business process, increasing the complexity of modeling and implementing ORM
systems. Last but not least, those regulations are difficult to understand due to their
lack of structure and lack of completeness. For instance, in the Basel II Accord there
is no definition of important concepts such as “ORM system”, “loss”, “loss event”,
“unexpected loss”, ...</p>
      <p>
        Requirements engineering and goal-oriented methods. The GORE methods can
overcome the difficulties presented in the preceding section by formalizing the Basel
II Accord and the implementation of ORM systems. These methods can be used to
analyze and model systems at all organizational levels, from Business Models up to
architectures [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Goal-oriented modeling languages are appropriate for that broad
range of models and they support formal analyses [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>However, in the case of the ORM system, it is difficult to manage all of those large
models and complex analyses. Moreover, for validation purposes, it is important to
refer to the concepts used in organizations, such as strategic objectives, strategies and
plans, key indicators, policies, SLAs, ... Within the context of the Basel II Accord,
additional structuring mechanisms have to be created on top of the usual
goaloriented concepts.</p>
      <p>Tleecvhelnical</p>
      <p>Strategic B
level</p>
      <p>Tactical
Operaletivoenlal
level
usiness
value
usiness
Bprocesses</p>
      <p>
        Procedures
E.g. in the IT domain:
applications, components, …
The general framework given in the Figure 1, represented by the pyramid, is a
standard view of the organization [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] used in financial institutions (and other activity
sectors). The four organizational layers [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] – strategic, tactical, operational and technical
levels – use concepts adapted to handle decisions at their corresponding abstraction
level. For each level, from top to bottom, those concepts are mainly: business value
[
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], business processes, procedures and technical artifacts [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] (such as IT
applications in the IT domain).
      </p>
      <p>ISO/IEC 15504 process assessment model. A first part of the structure is given by
separating the description of the core activities of each business process from the
activities related to the generic aspects (capabilities) of the business process such as
activity planning, work product control, management of the documentation
concerning the business process itself, performance measurement, performance
improvement, ...</p>
      <p>
        As explained in [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], the benefits of this separation of concerns has proven to be
very useful for the design of the goal models and during their verification and their
validation. This separation of concerns is formally defined in the ISO/IEC 15504
standard. This new standard has been designed to be applicable to any business
processes for assessments purposes [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ].
Objectives, strategies, policies and indicators. Those concepts (bottom of Figure 1)
detail complementary aspects needed for designing business value, business
processes, procedures and technical artifacts. They are similar to organizational
concepts needed in order to structure and formalize the links between each of the
organizational levels [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>When refining models at the higher levels of the hierarchy into models at the lower
levels of the hierarchy and when verifying the link between two successive
organizational levels, it is necessary to distinguish the main objectives to be fulfilled from the
strategy describing the approach to fulfill these objectives and from the roles and
responsibilities (policies) of the resources that will implement the strategies. Indicators
are defined when there is a need for some monitoring, control, supervision or
measurement concerning objectives, strategies or policies. Strategies and policies must be
consistent with each other and they must fulfill the objectives.</p>
      <p>
        The formal definition of those 4 concepts is based on goal-oriented models [
        <xref ref-type="bibr" rid="ref4 ref5 ref6">4,5,6</xref>
        ].
For the indicators, our work is based on the Goal-Question-Metric method (GQM)
[
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. Policies give a description of the roles and responsibilities (in accordance with
[
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and policy management [
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref23">15,16,17,23</xref>
        ]) and allow detailing the authorizations,
obligations (and their delegations), accountabilities, and separations of duties [
        <xref ref-type="bibr" rid="ref23 ref24">23,
24</xref>
        ]. Strategies give a description of the main approach or steps to fulfill given
objectives. Our work follows [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] where strategies are integrated with goal-oriented
analysis. For the sake of separation of concerns, responsibilities (and related aspects) are
not defined in strategies but only in policies. Note that in financial institutions, the
description of policies recalls its related objectives and strategies. This is also
sometimes the case for strategies that gives a short description of their corresponding
policies (i.e. description of roles and responsibilities). However, it is found essential to
separate those descriptions when designing and analyzing those policies and
strategies.
      </p>
      <p>Example: contribution of ITIL to the implementation of the ORM system. This
example shows the usefulness of the separation of concerns when analyzing the Basel
II regulation. The main problem for financial institutions is not to comply with the
Basel II regulation, but to have efficient business processes fulfilling business goals
that are also compliant to the Basel II regulation.</p>
      <p>
        The current case study describes a financial institution that implements ITIL [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ],
an IT service management standard, for aligning the service provided by IT
applications to the business goals through the use of Service Level Agreements. The analysis
aims to answer the following question: what are the contributions of the IT service
management implementation to the Basel II regulation?
      </p>
      <p>In order to answer that question, the contributions of the IT service management
goal-model to the Basel II goal-model must be analyzed. Only the core of each goal
models is to be compared. Indeed, the generic aspects (capabilities) add only quality
aspects concerning the ORM and the IT service management and do not address the
main goals of the ORM and IT service management processes. The analysis of the
goal model is simplified. This can be seen in the Figure 2: the left part of the diagram
shows a part of the Basel II Accord formalization of ORM and the right part presents
a partial IT service management system implementation using ITIL. The diagram
shows only a part of the models from the strategic level (topmost) up to the
operational level (bottom). Only objectives are shown for the strategic level and the
operational level. In between, at the tactical level, the objectives and indicators of business
processes are shown.</p>
      <p>
        The links between the two models are formally analyzed [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. For instance, Basel II
and ITIL share the business goal of reducing the impact of incidents. When drilling
down from the strategic level to the tactical level, the traceability links offered by the
goal refinements shows that the ITIL goal imposing the incidents are tracked and
recorded contributes to the Basel II indicator of the operational risk assessment. In
this case, our structuring mechanisms allowed an efficient analysis because the focus
excluded generic aspects and also excluded the policy and strategy aspects of both
Basel II and IT service management.
4
      </p>
    </sec>
    <sec id="sec-2">
      <title>Conclusions and Future Works</title>
      <p>
        Building upon a method that has been defined within the setting of a real-case
study in financial institutions, the Basel II Accord, new results are presented in this
paper aiming at giving a simple but integrated set of concepts – goals, indicators,
policies and strategies – which can be used to design financial systems compliant to
regulations and structure their analysis in relationship with the artifacts commonly
used in financial institutions – business value models, business processes models,
procedures and technical artifacts. The formalization of goals, indicators, policies and
strategies independently from each other allows analyzing and recording the design
decisions across all organizational levels, making easier the link with the regulation.
The main advantage of this method is that it keeps the structuring power of the
ISO/IEC 15504 capability model that can be used to discover weaknesses and
operational risks in the business process implementation with the method explained in [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ].
Based on the same techniques as in [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], a prototype implementation is under
development.
      </p>
      <p>
        The current and future works of the authors focus on a constructive method aiming
at giving an effective support for financial business process design (compliant to
regulations), establishment, assessment, improvement, governance and benchmarking
[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. In particular, a risk and value analysis method is under development adapted to
process assessment, improvement and governance. Some support is also given to
another research made by experts in DPM [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. The aim of those experts is to ground
digital policy management in sound non-federated distributed IT systems that
enforces policies fulfillment even outside the traditional IS frontier of each institution.
Finally, the current project with the CSSF is still in progress with results that are
extended to the IFRS [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] concerning the management of unquoted assets (IFRS-IAS39)
[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. In addition to model this regulation and the systems compliant to it, the
relationship between IFRS-IAS 39 and Basel II can be analyzed and alternative compliant
implementations of integrated systems can also be designed.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1. CSSF: Commission de Surveillance du Secteur Financier.
          <article-title>The firsts results of the joint project are freely downloadable</article-title>
          at http://www.cssf.lu/index.php?
          <source>id=130 (accessed April</source>
          <year>2006</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2. IFRS: International Financial Reporting Standards,
          <string-name>
            <surname>IASCF</surname>
          </string-name>
          , USA.
          <source>SoX: Sarbanes Oxley Act of</source>
          <year>2002</year>
          , USA. COSO:
          <string-name>
            <surname>Internal Control - Integrated Framework</surname>
            ,
            <given-names>CSOTC</given-names>
          </string-name>
          , USA. CobiT®:
          <article-title>Control Objectives for Information and related Technology, ISACA, USA</article-title>
          . ERM:
          <string-name>
            <surname>Enterprise Risk Management - Integrated Framework</surname>
            ,
            <given-names>CSOTC</given-names>
          </string-name>
          , USA.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. Basel Committee on Banking Supervision, “International Convergence of Capital Measurement and Capital Standards”; BIS; Basel,
          <year>June 2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>A. van Lamsweerde</surname>
          </string-name>
          ,
          <article-title>"Goal-Oriented Requirements Engineering: A Guided Tour"</article-title>
          .
          <source>Invited minitutorial, Proc. RE</source>
          '
          <fpage>01</fpage>
          - International Joint Conference on Requirements Engineering, Toronto, IEEE,
          <year>August 2001</year>
          , pp.
          <fpage>249</fpage>
          -
          <lpage>263</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>P.</given-names>
            <surname>Giorgini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Maiden</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Mylopoulos</surname>
          </string-name>
          , E. Yu (eds.), “Tropos/i*: Applications, variations and Extensions”,
          <source>Cooperative Information Systems Series</source>
          , MIT Press,
          <year>2006</year>
          (forthcoming).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>André</given-names>
            <surname>Rifaut</surname>
          </string-name>
          , “
          <article-title>Goal-Driven Requirements Engineering for Supporting the ISO 15504 Assessment Process”</article-title>
          ,
          <source>EuroSPI</source>
          <year>2005</year>
          , Budapest.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7. ISO/IEC 15504,
          <string-name>
            <surname>“Information</surname>
          </string-name>
          Technology - Process assessment”,
          <source>(parts 1-5)</source>
          ,
          <fpage>2003</fpage>
          -
          <lpage>2006</lpage>
          (
          <article-title>see website [1] for details about this standard).</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Anthony</surname>
            ,
            <given-names>R. N.</given-names>
          </string-name>
          <article-title>Planning and Control Systems: A Framework for Analysis</article-title>
          . Harward University, Boston, USA,
          <year>1965</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Henderson</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Venkatraman</surname>
          </string-name>
          , N., “
          <article-title>Strategic alignment: Leveraging technology for transforming organizations”</article-title>
          .
          <source>IBM Systems Journal</source>
          ,
          <year>1999</year>
          ,
          <volume>38</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10. Osterwalder and
          <string-name>
            <surname>Pigneur.</surname>
          </string-name>
          <article-title>An Ontology for e-business models</article-title>
          . In “
          <article-title>Value Creation from EBusiness Models”</article-title>
          , Wendy Currie ed.,
          <source>Butterworth-Heinenmann. Apr</source>
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Robson</surname>
            <given-names>W</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Strategic</surname>
            <given-names>Management</given-names>
          </string-name>
          <source>and Information Systems</source>
          , Pitman,
          <year>1997</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Chaffey</surname>
          </string-name>
          et al. (
          <year>2005</year>
          )
          <article-title>- Business Information Systems: Technology, Development and Management for the E-business</article-title>
          , Prentice Hall.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13. Van Solingen, “The Goal/Question/Metric Method:
          <article-title>A Practical Guide For Quality Improvement of Software Development”</article-title>
          ,
          <string-name>
            <surname>McGraw-Hill</surname>
          </string-name>
          ,
          <year>Jan</year>
          .
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>René</surname>
            <given-names>Wies</given-names>
          </string-name>
          , “
          <article-title>Using a Classification of Management Policies for Policy Specification and Policy Transformation”</article-title>
          .
          <source>In Proc. ISINM '95</source>
          ,
          <string-name>
            <surname>Santa</surname>
            <given-names>Barbara</given-names>
          </string-name>
          , California, May
          <year>1995</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <given-names>N.</given-names>
            <surname>Damianou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Dulay</surname>
          </string-name>
          , E. Lupu, and
          <string-name>
            <given-names>M.</given-names>
            <surname>Sloman</surname>
          </string-name>
          , “
          <article-title>The ponder policy specification language</article-title>
          ” In Morris Sloman, (ed),
          <source>Proc. of Policy Worshop</source>
          ,
          <year>2001</year>
          ,
          <string-name>
            <surname>Bristol</surname>
            <given-names>UK</given-names>
          </string-name>
          ,
          <year>January 2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <given-names>A.</given-names>
            <surname>Schaad</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Moffett</surname>
          </string-name>
          . “Delegation of obligations.”
          <source>In IEEE Policy Workshop</source>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <given-names>Qingfeng</given-names>
            <surname>He</surname>
          </string-name>
          and
          <string-name>
            <surname>Annie I. Antón</surname>
          </string-name>
          , “
          <article-title>Deriving Access Control Policies from Requirements Specifications and Database Designs”</article-title>
          ,
          <source>TR-2004-04</source>
          , Department of Computer Science, North Carolina State University Raleigh, NC
          <volume>27695</volume>
          -8207 USA,
          <year>September 02</year>
          ,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Rolland</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Prakash</surname>
          </string-name>
          ,
          <string-name>
            <surname>A</surname>
          </string-name>
          . Benjamen, “
          <article-title>A multi-model view of process modeling”</article-title>
          ,
          <source>Requirements Engineering Journal</source>
          , p.
          <fpage>169</fpage>
          -
          <lpage>187</lpage>
          ,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>ITIL: IT Infrastructure Library - Service Support</surname>
          </string-name>
          ,
          <article-title>Service Delivery, published by OGC, London. (see website [1] for details about this standard).</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <given-names>A.</given-names>
            <surname>Rifaut</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Picard</surname>
          </string-name>
          and
          <string-name>
            <given-names>B. Di</given-names>
            <surname>Renzo</surname>
          </string-name>
          , “
          <article-title>ISO/IEC 15504 Process Improvement to Support Basel II Compliance of Operational Risk Management in Financial Institutions”</article-title>
          , International Conference SPiCE
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <given-names>B.</given-names>
            <surname>Di Renzo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Hillairet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Picard</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Rifaut</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Bernard</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Hagen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Maar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Reinard</surname>
          </string-name>
          , “
          <article-title>Operational Risk management in Financial Institutions: Process Assessment in Concordance with Basel II”</article-title>
          , International Conference SPiCE
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>J.-H. Morin</surname>
            and
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Pawlak</surname>
          </string-name>
          , “
          <article-title>Towards a Global Framework for Corporate and Enterprise Digital Policy Management”</article-title>
          , SoftWars conference, Las Vegas, USA, Dec
          <volume>11</volume>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Sandhu</surname>
          </string-name>
          , R. S, “
          <article-title>Separation of duties in computerized information systems</article-title>
          .” In Database Security,
          <source>IV: Status and Prospects</source>
          ,
          <year>1991</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>David</surname>
            <given-names>F.</given-names>
          </string-name>
          <string-name>
            <surname>Ferraiolo</surname>
            , Ravi Sandhu,
            <given-names>Serban</given-names>
          </string-name>
          <string-name>
            <surname>Gavrila</surname>
          </string-name>
          , D. Richard Kuhn and Ramaswamy Chandramouli, “
          <article-title>Proposed NIST Standard for Role-Based Access Control”</article-title>
          ,
          <source>ACM Transactions on Information and System Security</source>
          , Vol.
          <volume>4</volume>
          , No. 3,
          <string-name>
            <surname>August</surname>
            <given-names>2001</given-names>
          </string-name>
          , Pages
          <fpage>224</fpage>
          -
          <lpage>274</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>