Risk-centred role engineering within identity data audits - continuous improvement of the rights structure and possible risk accumulations
Autor(en):
Zusammenfassung
Success and costs of audits in identity management largely depend on the structure of the underlying access control model. Auditing access rights includes the determination of actuality and adequacy of provided access rights. In order to ease audit and administration of access rights, role mining approaches have provided several solutions for identifying a minimal set of roles based upon either existing usage data, or business data. However, these approaches have focused on homogeneous, static environments. When facing dynamic, heterogeneous environments, such as infrastructure administration or smart systems, the accompanied noise of access rights provisioning hinder the determination of adequacy and actuality of access rights. With application of static approaches, accumulation of access risks at users may arise due to inadequate access rights, or aggregation of access roles. These issues are however mostly neglected by current approaches. Within this contribution we propose a method based upon the design structure matrix approach, which enables the identification of role aggregations, and examination of access risk accumulation within aggregated roles, and their assigned users throughout continuous audits of the access control model.
- Vollständige Referenz
- BibTeX
Kurowski, S.,
(2016).
Risk-centred role engineering within identity data audits - continuous improvement of the rights structure and possible risk accumulations.
In:
Hühnlein, D., Roßnagel, H., Schunck, C. H. & Talamo, M.
(Hrsg.),
Bonn:
Gesellschaft für Informatik e.V..
(S. 117-133).
@inproceedings{mci/Kurowski2016,
author = {Kurowski, Sebastian},
title = {Risk-centred role engineering within identity data audits - continuous improvement of the rights structure and possible risk accumulations},
booktitle = {},
year = {2016},
editor = {Hühnlein, Detlef AND Roßnagel, Heiko AND Schunck, Christian H. AND Talamo, Maurizio} ,
pages = { 117-133 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Kurowski, Sebastian},
title = {Risk-centred role engineering within identity data audits - continuous improvement of the rights structure and possible risk accumulations},
booktitle = {},
year = {2016},
editor = {Hühnlein, Detlef AND Roßnagel, Heiko AND Schunck, Christian H. AND Talamo, Maurizio} ,
pages = { 117-133 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 978-3-88579-658-9
ISSN: 1617-5468
Datum: 2016
Sprache:
(en)
(en)
Typ: Text/Conference Paper

