This is not the document you are looking for? Use the search form below to find more!

Report home > Computer / Internet

Conceptualizing a Responsibility based Approach for Elaborating and Verifying RBAC Policies Conforming with CobiT Framework Requirements

0.00 (0 votes)
Document Description
The objective of this paper is to present the first results toward the definition of a two steps approach for aligning business level requirements issued from corporate framework such as CobiT down to technical policies such as the access rights modeled by RBAC. To achieve that, our approach is based on the concept of employees’ responsibility. Using this concept is motivated by the importance and the omnipresence of the responsibility all along the company frameworks, from the CEO responsibilities such as in the financial sector as defined by Sarbanes-Oxley Act down to the responsibility at the operation layer such as the one of a trader who must follow stock quotes for private banking. The approach is illustrated based on an example, which highlights how access rights are assigned to employees having responsibilities defined at the CobiT framework layer.
File Details
Submitter
  • Name: Christophe Feltus
Embed Code:

Add New Comment




Related Documents

Conceptualizing a Responsibility based Approach for Elaborating and Verifying RBAC Policies Conforming with CobiT Framework Requirements

by: Christophe Feltus, 1 pages

The objective of this paper is to present the first results toward the definition of a two steps approach for aligning business level requirements issued from corporate framework such as CobiT down ...

Conceptual Framework of a Principle-based Approach for Life Insurance Products from the American Academy of Actuaries' Universal Life Work Group

by: andrea, 43 pages

This document establishes a conceptual framework for a standard for the valuation of reserves for life insurance policies under a principle-based approach (Approach) as defined below for the products ...

Professional Selling: A Trust-Based Approach, 4th Edition, Thomas N. Ingram, Raymond W. LaForge, Ramon A. Avila, Charles H. Schwepker, Jr., Michael R. Williams, CENGAGE, IM+TB

by: mysmandtb, 9 pages

Solution Manuals and Test Banks I have huge collection of solution manuals and test banks. I strive to provide you unbeatable prices with excellent support. So, I assure you that you won’t be ...

Professional Selling: A Trust-Based Approach, 4th Edition, Thomas N. Ingram, Raymond W. LaForge, Ramon A. Avila, Charles H. Schwepker, Jr., Michael R. Williams, CENGAGE, IM+TB

by: mysmandtb, 9 pages

Solution Manuals and Test Banks I have huge collection of solution manuals and test banks. I strive to provide you unbeatable prices with excellent support. So, I assure you that you won’t be ...

A portlet-API based approach for application integration

by: florus, 36 pages

A portlet-API based approach for application integration

A systems-based approach to public service quality

by: hulyah, 19 pages

Thedelivery of public services in developing countries is over-centralised. One of the reasons for this is the presence of centralised decision-making apparatus, which distances power from ...

Smart Card Based Protocol For Secure And Controlled Access Of Mobile Host In Foreign Network

by: harumi, 30 pages

Smart Card Based Protocol for Secure and Controlled Access Of Mobile Host in IPv6 Compatible Foreign Network 954203020 ??? 954203039 ??? 954203057 ??? Outline(1/1) ...

A Communications-Based Technique for Interdisciplinary Design Team Management

by: shinta, 13 pages

Many design failures are attributable to commonly understood mechanisms, suggesting that they are not due to a real lack of expertise within an interdisciplinary design team but ...

A Relationship-Based Approach to Early Intervention

by: danae, 9 pages

Every relationship has the potential and power to enhance other associated relationships (Gilkerson & Taylor Ritzler, in press; Weston et al, 1997). Administrative support can set the tone for ...

Breakaway Lanyards: A Risk-free Alternative For Students And Factory Personnel

by: aaronvalenzu23, 1 pages

Breakaway Lanyards are typically utilized by university and university college students to hold their identity cards or badges, and involve a breakaway characteristic necessary for ensuring the ...

Content Preview
Conceptualizing a Responsibility based Approach for Elaborating and Verifying
RBAC Policies Conforming with CobiT Framework Requirements
Toward a Business/IT Alignment Method based on the Translation of Business to Application Roles

Christophe Feltus, Eric Dubois
Michael Petit
Public Research Center Henri Tudor
PReCISE Research Centre,
Luxembourg-Kirchberg,
Faculty of Computer Science, University of Namur,
Luxembourg
Belgium
christophe.feltus@tudor.lu, eric.dubois@tudor.lu
mpe@info.fundp.ac.be


Abstract--The objective of this paper is to present the first
requests traceability of this alignment of permission and
results toward the definition of a two steps approach for
rights according to business needs. In practice, this alignment
aligning business level requirements issued from corporate
between the business view and the technical view is
framework such as CobiT down to technical policies such as
problematic and the traceability of the right assigned to the
the access rights modeled by RBAC. To achieve that, our
employee according to the business specifications too.
approach is based on the concept of employees' responsibility.
In most companies, the management of employees'
Using this concept is motivated by the importance and the
permissions and rights is done by using the central concept
omnipresence of the responsibility all along the company
of a role, which permits to manage a large amount of users
frameworks, from the CEO responsibilities such as in the
on the one hand and the permissions assigned to the role on
financial sector as defined by Sarbanes-Oxley Act down to the
the other hand. Role engineering is the process to define
responsibility at the operation layer such as the one of a trader
roles, which ought to be affected to a set of users who have
who must follow stock quotes for private banking. The
approach is illustrated based on an example, which highlights

the same function in the company. The Role Based Access
how access rights are assigned to employees having
Control (RBAC [4]) has emerged as a reference model in
responsibilities defined at the CobiT framework layer.
this discipline. RBAC models two main types of
assignments, which are the user-role assignment and the
Keywords-Alignment; CobiT; Responsibility; Traceability;
permission-role assignment. That means that a role is defined
Access right; RBAC; Requirement engineering.
with a set of permissions and that users are assigned to his
role to get the permissions.
I.
INTRODUCTION
Using the concept of role presents weaknesses due to the
In all the company's layers, standards and norms define
difficulty to align the role defined at the business layer
business activities. Those activities are called strategic
(business role) and at the same time the roles used at the IT
activities at the higher layer such as the activity to report the
layer to operate IT transactions (application role). This
company's results at the board of directors, management
weakness brings out two kinds of situations. Firstly, the
activities at the intermediary layer like activities to manage
company restricts its number of application roles to the
the budget of a company unit, or operational activities at the
amount of business roles. In this first case, the company
lower layer such as the activity to encode customers' data.
works with a limited number of roles and employees receive,
For all of those activities, implementation rules (e.g.: access
by the way, more permissions and rights than they need. In
right policies) must accordingly be defined. For instance, at
the second case, the company defines as many application
the higher layer, the CEO needs to have access to strategic
roles as IT transaction possibilities. In this second case, the
data to prepare the company report, at the intermediary layer,
company works with many roles, which renders the access
the unit managers need to have access to the accounting
right management difficult and decreases the advantages of
software to manage the budget and at the lower layer, and
according to RBAC specifications. This problem mainly
secretaries need access to the customer database.
emerges due to the misalignment between business role and
Meanwhile governance standards and norms [1, 2, 3]
application role. The business roles gather employees with
request a strict alignment between these business layer
the same function who can have different tasks to perform,
activities and the corresponding rights. This strict alignment
although application roles gather employees with the same
affords e.g. to respect the principle of least privilege and, by
tasks to perform but this could be assigned to different
consequence, to provide to the employees with strict rights,
business role.
which are indispensable to achieve their goals. For instance,
Based on the review of the literature, we have observed
it is not permitted to give access to the customer database to
that the concept of responsibility is central to the business
the whole team of secretaries if only one of them is
models and that it can be model with concepts from the
concerned with the customers' records. The financial sector
business view like the employee's obligations and
is particularly sensitive to this requirement and additionally
accountabilities, and concepts from the technical view like

Download
Conceptualizing a Responsibility based Approach for Elaborating and Verifying RBAC Policies Conforming with CobiT Framework Requirements

 

 

Your download will begin in a moment.
If it doesn't, click here to try again.

Share Conceptualizing a Responsibility based Approach for Elaborating and Verifying RBAC Policies Conforming with CobiT Framework Requirements to:

Insert your wordpress URL:

example:

http://myblog.wordpress.com/
or
http://myblog.com/

Share Conceptualizing a Responsibility based Approach for Elaborating and Verifying RBAC Policies Conforming with CobiT Framework Requirements as:

From:

To:

Share Conceptualizing a Responsibility based Approach for Elaborating and Verifying RBAC Policies Conforming with CobiT Framework Requirements.

Enter two words as shown below. If you cannot read the words, click the refresh icon.

loading

Share Conceptualizing a Responsibility based Approach for Elaborating and Verifying RBAC Policies Conforming with CobiT Framework Requirements as:

Copy html code above and paste to your web page.

loading