Twelfth International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises Verification of Access Control Coherence in Information System during Modifications Linz, Austria June 09-June 11 ISBN: 0-7695-1963-6
The paper deals with management of access control in an information system. It is suggested that the security of an information system should be a task solved on two principal levels: system development level and security administration level. Consequently, the responsibility for creating e?ective security measures for an information system ought to lie with both the application developer and the global administration. Moreover, sets of security constraints should be formulated also on those two levels.The paper de?nes requirements and obligations of each level using adapted tools based on the role-based access control (RBAC) model and employing the object-oriented conception method with UML (Unified Modeling Language).It is shown how the process of addition of a new application to an information system may be automated and how the administrator can be assisted in detecting incoherences or/and determining new relations between the elements existing in a system, such as roles or permissions.
Citation:
Gilles Goncalves, Fred Hemery, Aneta Poniszewska, "Verification of Access Control Coherence in Information System during Modifications," wetice, pp.232, Twelfth International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises, 2003 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||