ACM Home Page
Please provide us with feedback. Feedback
Process-oriented approach for role-finding to implement role-based security administration in a large industrial organization
Full text PdfPdf (102 KB)
Source Symposium on Access Control Models and Technologies archive
Proceedings of the fifth ACM workshop on Role-based access control table of contents
Berlin, Germany
Pages: 103 - 110  
Year of Publication: 2000
ISBN:1-58113-259-X
Authors
Haio Roeckle  IT-Sicherheit GmbH, Universitaetsstr. 142, D-44795 Bochum, Germany
Gerhard Schimpf  Schumann Unternehmensberatung AG, Hermann-Heinrich-Gossen-Str 3, D-50858 Koeln, Germany
Rupert Weidinger  Siemens AG Information and Communication Networks, Hofmannstr. 51, D-81379 Muenchen, Germany
Sponsor
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 4,   Downloads (12 Months): 68,   Citation Count: 21
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/344287.344308
What is a DOI?

ABSTRACT

In this paper we describe the work in progress with a process-oriented approach for role-finding to implement Role-Based Security Administration. Our results stem from using a recently proposed role model and procedural model at Siemens AG ICN, a large industrial organization. The core of this paper presents the data model, which integrates business processes, role based security administration and access control. Moreover, a structured top-down approach is outlined which is the basis for derivation of suitable business roles from enterprise process models. A brief description is given on how these results may be used to first build the Role Catalog and then support the implementation of RBAC and a single point of administration and control, using a cross-platform administration tool.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

Awi
Bar
Bez
ES
FBK
 
FCK
Ferraiolo, D.F., Cugini, J.A., Kuhn, R.D.; Role-Based Access Control (RBAC): Features and Motivations; Proc. 11 th Annual Computer Security Applications, New Orleans, Louisiana (1995)
FH
 
Fly
Flynn, H.; ~Real-Life" Use of Roles for Access Control; Gartner Advisory, Monthly Research Review August 1998 (1998)
 
HDLG
Hummel, A.A., Deinhart, K., Lorenz, S., Gligor, V.D.; Role-Based Security Administration; Proc. Sicherheit in Informationssystemen (SIS '96), Vienna, Editors: K. Bauknecht, D. Karagiannis, S. Teufel (1996)
JGIL
 
Mah
Maher, A.; A Universe of One~; Siemens AG Information and Communication Networks, press conference February 7 th , 2000 (2000)
 
PS
Parker, T., Sundt, C.; Role-Based Access Control in Real Systems; Information Systems Security, Spring (1996)
 
Roe
Roeckle, H.; Rollenbasierter Zugriffsschutz, Automatisierte Bildung der Rollen im Unternehmen auf der Basis eines prozessorientierten Vorgehensmodells; IT-Sicherheit 2/99, datacontext fachverlag, Frechen (1999)
 
RoFi
Roeckle IT-Sicherheit GmbH; RollenFinder Benutzer Dokumentation; RoFi-Handb~cher, Rel. 1.0, Bochum (2000)
 
SAM
Schumann Unternehmensberatung AG; Security Administration Manager (SAM), Concepts and Facilities; SAM-Manuals, Rel. 2.4, Koeln (1999)
San
SBM
 
SCFY
SMF
 
SRM
Schumann Unternehmensberatung AG; SAM Request Manager (SAM/RM), User Manual; SAM/RM-Manuals, Rel. 2.1, Koeln (1999)
TBB

CITED BY  21

Collaborative Colleagues:
Haio Roeckle: colleagues
Gerhard Schimpf: colleagues
Rupert Weidinger: colleagues