首页> 外文会议>International Workshop on Requirements Engineering and Law >Conceptualizing a responsibility based approach for elaborating and verifying RBAC policies conforming with CobiT framework requirements
【24h】

Conceptualizing a responsibility based approach for elaborating and verifying RBAC policies conforming with CobiT framework requirements

机译:概念化基于责任的责任,符合COBIT框架要求的详细说明和验证RBAC政策

获取原文

摘要

The objective of this paper is to present the first results toward the definition of a two steps approach for aligning business level requirements issued from corporate framework such as CobiT down to technical policies such as the access rights modeled by RBAC. To achieve that, our approach is based on the concept of employees' responsibility. Using this concept is motivated by the importance and the omnipresence of the responsibility all along the company frameworks, from the CEO responsibilities such as in the financial sector as defined by Sarbanes-Oxley Act down to the responsibility at the operation layer such as the one of a trader who must follow stock quotes for private banking. The approach is illustrated based on an example, which highlights how access rights are assigned to employees having responsibilities defined at the CobiT framework layer.
机译:本文的目的是介绍第一个结果,以定义一项两个步骤方法,用于对准从公司框架发出的企业水平要求,如Cobit Down达到RBAC建模的访问权限等技术策略。为实现这一目标,我们的方法是基于员工责任的概念。使用这一概念是由公司框架的重要性和责任的重要性和全能,从首席执行官队伍中,如萨班斯 - 奥克斯利所定义的金融部门的责任,这使得在诸如之一的操作层的责任下必须遵循私人银行股票的贸易商。基于示例来说明该方法,该示例突出显示访问权限将访问权限分配给具有在Cobit框架层中定义的职责的员工。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号