Abstract

Assessing the impact of system modifications in regulated computing environments, such as on cloud platforms or on-premise servers, may be challenging, as some methods can rely on siloed tools or subjective manual reviews that may lead to inefficient re-validation or compliance risks. A system may utilize a heterogeneous graph model to create a unified digital representation of a validated system, which can integrate entities such as code, data, infrastructure, and regulatory requirements. For example, when a change is proposed, a change propagation simulator can analyze potential effects by performing a weighted traversal of the graph to determine a multi-dimensional impact radius and a corresponding risk vector. Based on this analysis, a targeted and risk-based validation plan may be generated to provide a data-driven method for managing change control and supporting the maintenance of system compliance.

Creative Commons License

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.

Share

COinS