首页> 外文期刊>International journal of business information systems >Incorporating social-cultural contexts in role enqineerinq: an activity theoretic approach
【24h】

Incorporating social-cultural contexts in role enqineerinq: an activity theoretic approach

机译:在角色扮演中融入社会文化背景:一种活动理论方法

获取原文
获取原文并翻译 | 示例
           

摘要

Roles are convenient and powerful concept for facilitating access to distributed systems and for enforcing access management polices. Role-based access control (RBAC) is one of the most convenient and widely used role engineering models across enterprises. However, traditional role design process only factors in functional and job requirements of any user. Several threats arise due to insecure and inefficient design of roles when social and interaction dynamics in an organisational setting are ignored, where most activities are carried out a dynamic environment. Activity theory (AT) is one of the most applied and researched theories in context of understanding human actions, interactions with environments and dynamics against different social entities. The first section of the paper presents an overview of role engineering and AT concepts. Building on the concepts, the paper then presents methods in which AT can be applied for efficient and secure role engineering processes. A case study, carried out at a US based midsize financial institution, is also presented to demonstrate 1 how traditional role engineering processes give way to threats 2 how using AT methods can uncover some of the risks in role engineering process to mitigate risks.
机译:角色是方便和强大的概念,用于促进对分布式系统的访问和执行访问管理策略。基于角色的访问控制(RBAC)是整个企业中最便捷,使用最广泛的角色工程模型之一。但是,传统的角色设计过程仅影响任何用户的功能和工作要求。当忽略组织环境中的社交和互动动态时,由于角色的不安全和低效的设计而产生了一些威胁,而大多数活动是在动态环境中进行的。在理解人类行为,与环境的相互作用以及针对不同社会实体的动力的背景下,活动理论(AT)是应用最广泛且研究最多的理论之一。本文的第一部分概述了角色工程和AT概念。然后,在此概念的基础上,本文提出了可以将AT应用于有效且安全的角色工程过程的方法。还介绍了在美国的一家中型金融机构进行的案例研究,以证明1传统角色工程流程如何让位给威胁2使用AT方法如何发现角色工程流程中的某些风险以减轻风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号