ACM Home Page
Please provide us with feedback. Feedback
Observations on the role life-cycle in the context of enterprise security management
Full text PdfPdf (179 KB)
Source Symposium on Access Control Models and Technologies archive
Proceedings of the seventh ACM symposium on Access control models and technologies table of contents
Monterey, California, USA
SESSION: Role Engineering table of contents
Pages: 43 - 51  
Year of Publication: 2002
ISBN:1-58113-496-7
Authors
Axel Kern  Hermann-Heinrich-Gossen-Str. 3, 50858 Cologne, Germany
Martin Kuhlmann  Hermann-Heinrich-Gossen-Str. 3, 50858 Cologne, Germany
Andreas Schaad  University of York, York, YO10 5DD, UK
Jonathan Moffett  University of York, York, YO10 5DD, UK
Sponsor
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 10,   Downloads (12 Months): 109,   Citation Count: 17
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/507711.507718
What is a DOI?

ABSTRACT

Roles are a powerful and policy neutral concept for facilitating distributed systems management and enforcing access control. Models which are now subject to becoming a standard have been proposed and much work on extensions to these models has been done over the last years as documented in the recent RBAC/SACMAT workshops. When looking at these extensions we can often observe that they concentrate on a particular stage in the life of a role. We investigate how these extensions fit into a more general theoretical framework in order to give practitioners a starting point from which to develop role-based systems. We believe that the life-cycle of a role could be seen as the basis for such a framework and we provide an initial discussion on such a role life-cycle, based on our experiences and observations in enterprise security management. We propose a life-cycle model that is based on an iterative-incremental process similar to those found in the area of software development.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
Biddle B. and E. Thomas, Role Theory: Concepts and Research. New York: Robert E. Krieger Publishing Company, 1979.
 
2
Ferraiolo D. and R. Kuhn, "Role-Based Access Control." presented at 15th NCSC National Computer Security Conference, Baltimore, 1992.
3
 
4
 
5
Lupu E., "A Role-Based Framework for Distributed Systems Management." PhD Thesis: Department of Computing. London, Imperial College, 1998.
6
7
 
8
9
10
 
11
 
12
 
13
 
14
 
15
Balzert H., "Lehrbuch der Software-Technik II", Spektrum Akademischer Verlag, Heidelberg/Berlin, 1998.
16
17
18
 
19
20

CITED BY  17

Collaborative Colleagues:
Axel Kern: colleagues
Martin Kuhlmann: colleagues
Andreas Schaad: colleagues
Jonathan Moffett: colleagues