Abstract

Compliance of processes in enterprises to internal policies and external regulations could be critical because failing to follow them could result in great losses, but manual compliance auditing is difficult and prone to errors and oversight. In this paper, we present a method for formally verifying the properties of Integrated Change Control processes using temporal logic. We express the process in terms of states, and then we formulate some of its key properties, such as prerequisites, reachability, definiteness, and cycles, using a temporal logic called Computation Tree Logic. The properties to verify in the case study we present are taken from actual change control process auditing practice in a large business in the food industry. We formally verify those properties using a model-checking tool. We end up with a formally verified Integrated Change Control process and more robust assurance of its correctness than can be reached for its informal counterpart. To the best of our knowledge, this has not been done before.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call