Direkt zum Inhalt

Groll, Sebastian ; Kern, Sascha ; Fuchs, Ludwig ; Pernul, Günther

Monitoring Access Reviews by Crowd Labelling

Groll, Sebastian , Kern, Sascha , Fuchs, Ludwig and Pernul, Günther (2021) Monitoring Access Reviews by Crowd Labelling. In: Fischer-Hübner, Simone and Lambrinoudakis, Costas and Kotsis, Gabriele and Khalil, Ismail and Tjoa, A. Min, (eds.) Trust, Privacy and Security in Digital Business. Lecture Notes in Computer Science, 12927. Springer, Cham, pp. 3-17. ISBN 978-3-030-86586-3, 978-3-030-86585-6.

Date of publication of this fulltext: 28 Sep 2022 04:38
Book section
DOI to cite this document: 10.5283/epub.52906


Abstract

Access reviews, i.e. the periodical security audit of access privileges, are a basic compliance and IT-security requirement for medium- and large-scale organizations. Assessing the quality of the reviewer's decisions ex-post can help to analyse the effectiveness of the measure and to identify structural or organizational shortcomings. Yet, current studies merely focus on improving the ...

Access reviews, i.e. the periodical security audit of access privileges, are a basic compliance and IT-security requirement for medium- and large-scale organizations. Assessing the quality of the reviewer's decisions ex-post can help to analyse the effectiveness of the measure and to identify structural or organizational shortcomings. Yet, current studies merely focus on improving the decision-making process itself. This paper develops a method for assessing the decision quality of access reviews by applying a solution from the crowd sourcing research realm. In order to achieve this, the problem of assessing decision quality of access reviews is generalized. It is shown that the abstract problem can be mapped to the problem of assessing the quality of crowd tagging decisions. Subsequently, an applicable solution of this research area is applied to access reviews. Furthermore, the selected approach is optimized to meet the specific challenges of access review data.



Involved Institutions


Details

Item typeBook section
ISBN978-3-030-86586-3, 978-3-030-86585-6
Title of Book:Trust, Privacy and Security in Digital Business
Publisher:Springer
Place of Publication:Cham
Other Series:Lecture Notes in Computer Science
Volume:12927
Page Range:pp. 3-17
Date1 September 2021
InstitutionsBusiness, Economics and Information Systems > Institut für Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Informatics and Data Science > Department Information Systems > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Identification Number
ValueType
10.1007/978-3-030-86586-3_1DOI
KeywordsAccess Reviews; Decision Quality; Crowd Sourcing; Identity and Access Management; Compliance
Dewey Decimal Classification000 Computer science, information & general works > 004 Computer science
StatusPublished
RefereedYes, this version has been refereed
Created at the University of RegensburgYes
Item ID52906

Export bibliographical data

Owner only: item control page

nach oben