Stay ahead of the regulatory tsunami - Model driven compliance and governance
About this talk
This talk, presented by Jürgen Albert from Data in Motion, explores a model-driven approach to compliance that unifies and automates adherence to various regulatory frameworks including CRA, GDPR, NIS2, and DORA. The session details how these regulations can be mapped onto a cohesive representation of systems, data, and processes, allowing for a streamlined evaluation of overlapping requirements. It highlights the use of EMF-based models that depict APIs, data flows, and processes, as well as the integration of existing artefacts like SBOMs and CI/CD outputs to continuously generate compliance evidence throughout the software lifecycle. This innovative approach not only enhances compliance tracking and automated validation but also extends to governance scenarios, enabling organizations to maintain up-to-date compliance evidence instead of relying solely on static documentation.