Formal Analysis of Segregation of Duties ( SoD ) in Accounting: A Computational Approach

Formal Analysis of Segregation of Duties ( SoD ) in Accounting: A Computational Approach
复制标题

DOI:
10.1111/abac.12190
复制
发表时间:
2020-06
期刊:
Abacus
影响因子:
--
通讯作者:
Rosemary Kim;J. Gangolly;S. Ravi;D. Rosenkrantz
Rosemary Kim;J. Gangolly;S. Ravi;D. Rosenkrantz
中科院分区:
其他
文献类型:
--
作者:
Rosemary Kim;J. Gangolly;S. Ravi;D. Rosenkrantz

文献摘要

相似文献

这项研究考察了会计系统设计和实施中职责分工的计算框架。该框架由基于工作流图的会计系统中的工作流模型、会计系统中参与者所扮演的角色的偏序模型和SoD规则的规范组成。我们开发了一套适用于四种规则的算法,这些规则可以用于执行规则。对于排除任务类型冲突的SOD规则,我们的结果表明,虽然遵从性验证可以有效地执行,但找到符合SOD的任务分配在计算上是困难的。对于这些情况,我们提出了一种整数线性规划(ILP)公式,用于使用公有的ILP求解器来寻找合规的分配。对于剩下的三个SoD规则,我们演示了测试给定作业的符合性以及查找符合性作业的有效方法。[摘自作者]
This study examines a computational framework for segregation of duties (SoD) in the design as well as implementation of accounting systems. The framework consists of a model of workflows in accounting systems based on workflow graphs, a partial order model of roles performed by the actors in the accounting system, and a specification of SoD rules. We develop a set of algorithms for four SoD rules that can be used in the enforcement of SoD. For the SoD rule that precludes task type conflicts, our results show that while compliance verification can be carried out efficiently, finding an SoD compliant assignment of tasks is computationally intractable. For those situations, we present an integer linear programming (ILP) formulation for finding compliant assignments using public domain ILP solvers. For the remaining three SoD rules, we demonstrate efficient ways of testing compliance for a given assignment as well as finding compliant assignments. [ABSTRACT FROM AUTHOR]