| Accepted Version Download ( PDF | 736kB) Repository staff only |
Monitoring Access Reviews by Crowd Labelling
Groll, Sebastian
, Kern, Sascha
, Fuchs, Ludwig and Pernul, Günther
(2021)
Monitoring Access Reviews by Crowd Labelling.
In: Fischer-Hübner, Simone and Lambrinoudakis, Costas and Kotsis, Gabriele and Khalil, Ismail and Tjoa, A. Min, (eds.)
Trust, Privacy and Security in Digital Business.
Lecture Notes in Computer Science, 12927.
Springer, Cham, pp. 3-17.
ISBN 978-3-030-86586-3, 978-3-030-86585-6.
Date of publication of this fulltext: 28 Sep 2022 04:38
Book section
DOI to cite this document: 10.5283/epub.52906
Abstract
Access reviews, i.e. the periodical security audit of access privileges, are a basic compliance and IT-security requirement for medium- and large-scale organizations. Assessing the quality of the reviewer's decisions ex-post can help to analyse the effectiveness of the measure and to identify structural or organizational shortcomings. Yet, current studies merely focus on improving the ...
Access reviews, i.e. the periodical security audit of access privileges, are a basic compliance and IT-security requirement for medium- and large-scale organizations. Assessing the quality of the reviewer's decisions ex-post can help to analyse the effectiveness of the measure and to identify structural or organizational shortcomings. Yet, current studies merely focus on improving the decision-making process itself. This paper develops a method for assessing the decision quality of access reviews by applying a solution from the crowd sourcing research realm. In order to achieve this, the problem of assessing decision quality of access reviews is generalized. It is shown that the abstract problem can be mapped to the problem of assessing the quality of crowd tagging decisions. Subsequently, an applicable solution of this research area is applied to access reviews. Furthermore, the selected approach is optimized to meet the specific challenges of access review data.
Alternative links to fulltext
Involved Institutions
Details
| Item type | Book section | ||||
| ISBN | 978-3-030-86586-3, 978-3-030-86585-6 | ||||
| Title of Book: | Trust, Privacy and Security in Digital Business | ||||
|---|---|---|---|---|---|
| Publisher: | Springer | ||||
| Place of Publication: | Cham | ||||
| Other Series: | Lecture Notes in Computer Science | ||||
| Volume: | 12927 | ||||
| Page Range: | pp. 3-17 | ||||
| Date | 1 September 2021 | ||||
| Institutions | Business, Economics and Information Systems > Institut für Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul) Informatics and Data Science > Department Information Systems > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul) | ||||
| Identification Number |
| ||||
| Keywords | Access Reviews; Decision Quality; Crowd Sourcing; Identity and Access Management; Compliance | ||||
| Dewey Decimal Classification | 000 Computer science, information & general works > 004 Computer science | ||||
| Status | Published | ||||
| Refereed | Yes, this version has been refereed | ||||
| Created at the University of Regensburg | Yes | ||||
| Item ID | 52906 |
Download Statistics
Download Statistics