Capturing Organizational Policies & Compliance

Post Reply
bpavao
Posts: 1
Joined: 05 Mar 2009, 22:19

I'm trying to identify is how we could capture Policies and Compliance details that are associated with the "How" things can be done, as well as the "What" needs to be done when doing certain processes.

The business model we're using the tool to model is a Credit Card Servicer / Processor so there is quite a bit of compliance documentation and rules that define and affect our every day processes.

Any help is greatly appreciated.

Also, looking forward to the example implementation once it's ready, it'll be great to compare against how I've begun capturing the data so far. So far the tool is doing a great job of pulling the team together, and helping our conversations become more productive.
john.gaul
Posts: 4
Joined: 24 Feb 2009, 11:06

It's good to hear your enthusiasm for Essential - improving your productivity so soon after its launch.

With regard to the capturing of policy and compliance details: though not explicitly supported by the out-of-the-box metamodel, it's something that we would be keen to incorporate in the form of extensions to the metamodel. Depending on the details of your requirements, it may be that they can be supported by the base metamodel with some simple extensions, to capture links such as
- process A ensures compliance of process B according to policy X

It would be great to get your input on this. I would suggest considering the following when eliciting the requirements:
What questions do you need to be able to answer about your organisational policies and compliance?
What information needs to be captured to answer those questions?
Some concrete examples would help to clarify this further.

We have dealt with policy before through the EA Support part of the meta model (although these are yet to be released) and based on this, we would recommend managing policies for particular 'domains' separately, e.g. Security Policy in a Security 'domain' or Information Lifecycle Policy in an Information Lifecycle Domain. Leading on from this, which areas (domains) do you need for compliance and policy that we should be looking to add to the meta model?

We're very happy to open this up for discussion here on the forum and would encourage anyone with similar requirements to give their views.

Regards

John (Essential Project Team)
Post Reply