Peer-Verified Compliance for Elastic Service-Oriented Systems
Keywords:
Distributed Compliance Intelligence; Service Ecosystems; Professional Services; Enterprise Collaboration; Compliance Governance.Abstract
Enterprise service ecosystems often lack economic scaling due to the limited federated governance intelligence of stakeholders. They need a governance ecosystem framework with comprehensive compliance concepts for horizontal and vertical scalability of service enterprise ecosystems. A compliance governance ecosystem consists of partners, business owners, policies and control point decision functions, intelligence and processes. Partner policies combine local and community partner context for federated compliance preventing collateral information of services, processes or production, and incorporating service or process reuse. Partner owners peer-review service and process quality testing, although without strong business models these are rarely used for third-party service or process. Business owner policies reuse existing Federated Business Process Execution Language definitions.
Horizontal ecosystem scaling creates communities of interest to ensure local business policies are supported; vertical scaling creates more complex feedback points, enabling compliance on non-business enterprise services. The Federated Compliance Intelligence Theory introduces new definitions, a layered compliance governance ecosystem model and metrics to quantify scalability of the governance context compared with ecosystem-size scaling methods of computation, memory and bandwidth. SECURE understands owners, business policies, control points and their information context as layers of a compliance governance ecosystem, externalized from partner enterprise-internal compliance decisions into enterprise service ecosystems.C
References
1. Aksakalli, I. K., Çelik, T., Can, A. B., & Tekinerdogan, B. (2021). Deployment and communication patterns in microservice architectures: A systematic literature review. Journal of Systems and Software, 180, 111014.
2. Avritzer, A., Ferme, V., Janes, A., Russo, B., van Hoorn, A., Schulz, H., Menasché, D. S., & Rufino, V. (2020). Scalability assessment of microservice architecture deployment configurations: A domain-based approach leveraging operational profiles and load tests. Journal of Systems and Software, 165, 110564.
3. Paleti, S., Burugulla, J. K. R., Pandiri, L., Pamisetty, V., & Challa, K. (2022). Optimizing digital payment ecosystems: AI-enabled risk management, regulatory compliance, and innovation in financial services. Regulatory Compliance. And Innovation In Financial Services (June 15, 2022).
4. Berardi, D., Giallorenzo, S., Mauro, J., & Melis, A. (2022). Microservice security: A systematic literature review. PeerJ Computer Science, 8, e779.
5. Challagidad, P. S., & Birje, M. N. (2020). Multi-dimensional dynamic trust evaluation scheme for cloud environment. Computers & Security, 91, 101722.
6. Chandramouli, R., Butcher, Z., & Chetal, A. (2021). Attribute-based access control for microservices-based applications using a service mesh. NIST.
7. Han, C., Kim, T., Lee, W., & Shin, Y. (2024). S-ZAC: Hardening access control of service mesh using Intel SGX for zero trust in cloud. Electronics, 13(16), 3213.
8. Hassan, S., Bahsoon, R., & Buyya, R. (2022). Systematic scalability analysis for microservices granularity adaptation design decisions. Software: Practice and Experience, 52(6), 1378–1401.
9. Davuluri, P. S. L. (2023). AI-Augmented Sanctions Screening: Enhancing Accuracy and Latency in Real Time Compliance Systems. AI-Augmented Sanctions Screening: Enhancing Accuracy and Latency in Real Time Compliance Systems (December 15, 2023).
10. Haindl, P., Kochberger, P., & Sveggen, M. (2024). A systematic literature review of inter-service security threats and mitigation strategies in microservice architectures. IEEE Access, 12, 90252–90286.
11. Jiao, H., Wang, X., & Ding, W. (2020). Service oriented cloud computing trusted evaluation model. Journal of Information Processing Systems, 16(6), 1281–1292.
12. Lenarduzzi, V., Lomio, F., & Saarimäki, N. (2020). Does migrating a monolithic system to microservices decrease the technical debt? Journal of Systems and Software, 169, 110710.
13. Minna, F., & Massacci, F. (2023). SoK: Run-time security for cloud microservices. Computers & Security, 127, 103119.
14. Nasab, A. R., Shahin, M., Liang, P., Basiri, M. E., Hoseyni Raviz, S. A., Khalajzadeh, H., Waseem, M., & Naseri, A. (2021). Automated identification of security discussions in microservices systems: Industrial surveys and experiments. Journal of Systems and Software, 181, 111046.
15. Mukesh, A., & Aitha, A. R. (2021). Insurance Risk Assessment Using Predictive Modeling Techniques. International Journal of Emerging Research in Engineering and Technology, 2(4), 68-79.
16. Nasab, A. R., Shahin, M., Hoseyni Raviz, S. A., Liang, P., Mashmool, A., & Lenarduzzi, V. (2023). An empirical study of security practices for microservices systems. Journal of Systems and Software, 198, 111563.
17. Pereira-Vale, A., Fernandez, E. B., Monge, R., Astudillo, H., & Márquez, G. (2021). Security in microservice-based systems: A multivocal literature review. Computers & Security, 103, 102200.
18. Rezaei Nasab, A., Shahin, M., Liang, P., & colleagues. (2023). Security practices and challenges in microservice systems. Journal of Systems and Software, 198, 111563.
19. Schneider, S., Diaz Ferreyra, N. E., Simhandl, G., Zdun, U., & Scandariato, R. (2022). Towards a security benchmark for the architectural design of microservice applications. In Proceedings of the 17th International Conference on Availability, Reliability and Security.
20. Inala, R. (2023). AI-powered investment decision support systems: Building smart data products with embedded governance controls. Journal for ReAttach Therapy and Developmental Diversities, 6(10), 2251-2266.
21. Schneider, S., & Scandariato, R. (2023). Automatic extraction of security-rich dataflow diagrams for microservice applications written in Java. Journal of Systems and Software, 202, 111722.
22. Söylemez, M., Tekinerdogan, B., & Tarhan, A. K. (2024). Microservice reference architecture design: A multi-case study. Software: Practice and Experience, 54(1), 58–84.
23. Solans, D., Pérez Hernández, M. de los S., & Muntés Mulero, V. (2020). Graph-based root cause analysis for service-oriented and microservice architectures. Journal of Systems and Software, 159.
24. Waseem, M., Liang, P., & Shahin, M. (2020). A systematic mapping study on microservices architecture in DevOps. Journal of Systems and Software, 170, 110798.
25. Zhong, C., & Zhang, H. (2022). Impacts, causes, and solutions of architectural smells in microservices: An industrial investigation. Software: Practice and Experience.
26. Raj, V., & Ravichandra, S. (2022). A service graph based extraction of microservices from monolith services of service-oriented architecture. Software: Practice and Experience, 52(7), 1661–1678.
27. Rezaei Nasab, A., Shahin, M., Liang, P., & colleagues. (2021). Security discussions and security decision-making in microservices systems. Journal of Systems and Software, 181, 111046.
28. Minna, F., Massacci, F., & colleagues. (2023). Runtime security and continuous trust evaluation for cloud microservices. Computers & Security, 127, 103119.
29. Hassan, S., Bahsoon, R., & Buyya, R. (2022). Scalability and granularity adaptation in microservice architectures. Software: Practice and Experience, 52(6), 1378–1401.
30. Soldani, J., Forti, S., & Brogi, A. (2024). Explaining microservices' cascading failures from their logs. Software: Practice and Experience, 54, 809–828.
31. Gottimukkala, V. R. R. (2024). Federated Learning Approaches for Fraud Detection in International Payment Systems. https://www. jisem-journal. com/download/118_JISEM. pdf.
32. Hu, K., Xu, M., Ye, K., & Xu, C. (2024). LSRAM: A lightweight autoscaling and SLO resource allocation framework for microservices based on gradient descent. Software: Practice and Experience.
33. Schneider, S., Scandariato, R., & colleagues. (2024). Security analysis and continuous assurance for microservice architectures. Journal of Systems and Software.
34. Avritzer, A., Ferme, V., Janes, A., Russo, B., van Hoorn, A., Schulz, H., Menasché, D. S., & Rufino, V. (2020). Operational-profile-based scalability analysis of microservice deployment configurations. Journal of Systems and Software, 165, 110564.
35. Xiao, S. (2022). SoK: Context and risk aware access control for zero trust systems. Security and Communication Networks, 2022, 7026779.
36. He, H., et al. (2022). A survey on zero trust architecture: Challenges and future trends. Wireless Communications and Mobile Computing, 2022, 6476274.
37. Firdous, N. S., Shah, S. W., Shaghaghi, A., Anwar, A., & Iqbal, M. (2022). Zero Trust Architecture (ZTA): A comprehensive survey. IEEE Access, 10.
38. Palavali, D. R., & Pothireddy, S. (2023). Policy everywhere: Zero trust API security through embedded enforcement in microservice meshes. International Journal of Information and Electronics Engineering, 13(4).
39. Alevizos, L., Ta, V. T., & Eiza, M. H. (2021). Augmenting zero trust architecture to endpoints using blockchain: A state-of-the-art review. arXiv.
40. Han, C., Kim, T., Lee, W., & Shin, Y. (2024). Zero-trust access control and security enforcement for cloud service-mesh environments. Electronics, 13(16), 3213.