kirancodes.me
To Proof Maintenance & Beyond!

Continuous Compliance

Martin Kellogg, Martin Schäf, Serdar Tasiran, Michael D. Ernst

Abstract

Vendors who wish to provide software or services to large corporations and governments must often obtain numerous certificates of compliance. Each certificate asserts that the software satisfies a compliance regime, like SOC or the PCI DSS, to protect the privacy and security of sensitive data. The industry standard for obtaining a compliance certificate is an auditor manually auditing source code. This approach is expensive, error-prone, partial, and prone to regressions.

BibTeX
@inproceedings{Kellogg-al:ASE20,
  author    = {Martin Kellogg and
               Martin Sch{\"{a}}f and
               Serdar Tasiran and
               Michael D. Ernst},
  title     = {Continuous Compliance},
  booktitle = {ASE},
  pages     = {511--523},
  publisher = {{IEEE}},
  year      = {2020},
}

Related papers