...
首页> 外文期刊>Revista Eletrnica de Sistemas de Informao >EVALUATING TOOLS FOR EXECUTION AND MANAGEMENT OF AUTHORIZATION BUSINESS RULES
【24h】

EVALUATING TOOLS FOR EXECUTION AND MANAGEMENT OF AUTHORIZATION BUSINESS RULES

机译:执行和管理授权业务规则的评估工具

获取原文
           

摘要

Information security is an essential subject for commercial and government organizations, and its deployment should be supported by software tools, both at design time (when authorization business rules are planned and designed) and at run time (when authorization business rules are applied and monitored). An authorization business rule (or authorization rules, for short) is a rule that states which operations may be executed on each data item by each user. Therefore, information security supporting tools should include features for editing, managing, and assuring the application and monitoring of authorization rules. These features may be structured in a framework composed by rule management and rule execution components. In real scenarios, evaluating and selecting tools to support organization business processes is typically handled by prospecting activities that are conducted in an ad-hoc way, and therefore are very time-consuming and hard to track. However, the rapid evolution of business scenarios, the increasing demand for traceability in business-IT alignment and the great number of IT solutions available for being evaluated require prospecting activities to be more systematic, traceable and quickly adapted to different scenarios. This work proposes a set of criteria and a systematic method for evaluating tools for management and execution of authorization rules. We have applied our approach in a real scenario. The results demonstrated that BRMS (Business Rule Management Systems) tools can be used for authorization rule management, and Oracle DBMS is the most suitable tool for authorization rules storage and execution.
机译:信息安全是商业和政府组织的基本主题,在设计时(计划和设计授权业务规则时)和运行时(当应用和监视授权业务规则时),信息部署都应由软件工具支持。 。授权业务规则(或简称为授权规则)是规定每个用户可以对每个数据项执行哪些操作的规则。因此,信息安全支持工具应包括用于编辑,管理和确保应用程序以及监视授权规则的功能。这些特征可以在由规则管理和规则执行组件组成的框架中构造。在实际场景中,评估和选择支持组织业务流程的工具通常是通过以特殊方式进行的勘探活动来处理的,因此非常耗时且难以跟踪。但是,业务场景的快速发展,对业务与IT的可追溯性的需求不断增长,以及可供评估的大量IT解决方案,要求勘探活动必须更加系统,可追溯并能快速适应不同的场景。这项工作为评估用于管理和执行授权规则的工具提出了一套标准和一种系统的方法。我们已经在实际场景中应用了我们的方法。结果表明,BRMS(业务规则管理系统)工具可用于授权规则管理,而Oracle DBMS是最适合授权规则存储和执行的工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号