Dimensions of Compliance
§
Correctness:
A norm should be applied in accordance with its intended meaning, rationale and usage.
§
Justification:
The application of a given norm - or the lack thereof - should be justified, depending on its relevance and priority in the specific situation.
§
Consistency:
Certain norms may be related and dependent on each others application. In this case a group of norms needs to be applied as a package, since applying one norm only would not be sufficient. Furthermore, such related norms should be applied in a coherent way.
§
Completeness:
All (mandatory) norms should be adhered to, as opposed to adhering only to a convenient subset.
§
Correctness check:
Verifies whether a given norm (prescription) is applied by the regulatee in a way that is in accordance with its intended meaning, rationale and usage. In other words, this check verifies whether the application of the norm deviates from the norm as it was intended by the policy maker.
§
Justification check:
Verifies whether the (lack of) application of a given norm (prescription) is justified, depending on its relevance in the specific situation. The justification check's actual execution is dependent upon certain conditions. First, if the application of a norm deviates from its intended application (which is determined by the correctness check), it needs to be ascertained whether the alteration is justified. Second, if a norm is not applied, it needs to be ascertained whether it is justified not to apply it. Third, if a norm is applied correctly, it needs to be checked whether it is indeed justified to apply it. This last sub-check aims to avoid 'blind' conformance that could harm the goals of the enterprise or the regulatee (e.g. a unit, project or individual employee) in the specific situation. In short, the justification check verifies whether the regulatee has made the appropriate choice when deciding to apply, alter or not to apply a given norm.
§
Consistency check:
Verifies whether, if a given norm is applied, required related norms are also applied. Some norms, especially those at lower abstraction levels, might need to be implemented as a package. For example, so-called counterpart norms are interdependent. Another focus of the check is to verify whether the norms' applications do not contradict each other, but instead culminate in a consistent and balanced result.
§
Completeness check:
Verifies whether all the norms are applied. Minimally, the norms that have been marked as mandatory (perhaps dependent on specific situations) need to be applied.
Sources: §
Foorthuis, R.M., Steenbergen, M. van, Brinkkemper, S., Bruls, W. (2015).
A Theory Building Study of Enterprise Architecture Practices and Benefits.
Information Systems Frontiers. DOI: 10.1007/s10796-014-9542-1. §
Foorthuis, R.M. (2012).
Project Compliance with Enterprise Architecture.
Doctoral dissertation (PhD thesis). Utrecht University, Department of Information and Computing Sciences, Organization and Information. ISBN: 978-90-393-5834-4. §
Foorthuis, R.M., Hofman, F., Brinkkemper, S., Bos, R. (2012).
Compliance Assessments of Projects Adhering to Enterprise Architecture.
Journal of Database Management, Vol. 23, No. 2, pp. 44-71. §
Foorthuis, R.M., Bos, R. (2011). A Framework for Organizational Compliance Management Tactics. In: C. Salinesi and O. Pastor (Eds.), CAiSE 2011 Workshops (GRCIS 2011), LNBIP 83, pp. 259–268. Berlin: Springer-Verlag.
§
Foorthuis, R.M., Steenbergen, M. van, Mushkudiani, N., Bruls, W., Brinkkemper, S., Bos, R. (2010). On Course, But Not There Yet: Enterprise Architecture Conformance and Benefits in Systems Development. In: Proceedings of the Thirty First International Conference on Information Systems (ICIS 2010), St. Louis, Missouri, USA.
§
Foorthuis, R.M., Hofman, F., Brinkkemper, S., Bos, R. (2009). Assessing Business and IT Projects on Compliance with Enterprise Architecture. In: Proceedings of GRCIS 2009, CAiSE Workshop on Governance, Risk and Compliance of Information Systems.
Updated: February 7th 2015 Ralph Foorthuis
|