Direkt zum Inhalt

Kern, Sascha ; Baumer, Thomas ; Fuchs, Ludwig ; Pernul, Günther

Maintain High-Quality Access Control Policies: An Academic and Practice-Driven Approach

Kern, Sascha , Baumer, Thomas , Fuchs, Ludwig und Pernul, Günther (2023) Maintain High-Quality Access Control Policies: An Academic and Practice-Driven Approach. In: DBSec 2023, 19.-21. Jul 2023, Sophia Antipolis, France.

Veröffentlichungsdatum dieses Volltextes: 18 Jul 2024 07:09
Konferenz- oder Workshop-Beitrag


Zusammenfassung

Organizations encounter great difficulties in maintaining high-quality Access Control Policies (ACPs). Policies originally modeled and implemented with good quality deteriorate over time, leading to inaccurate authorization decisions and reduced policy maintainability. As a result, security risks arise, delays prevent users from carrying out tasks, and ACP management becomes more expensive and ...

Organizations encounter great difficulties in maintaining high-quality Access Control Policies (ACPs). Policies originally modeled and implemented with good quality deteriorate over time, leading to inaccurate authorization decisions and reduced policy maintainability. As a result, security risks arise, delays prevent users from carrying out tasks, and ACP management becomes more expensive and error-prone. In contrast to the initial modeling of ACPs, their long-term maintenance has been addressed scarcely by existing research. This work addresses this research gap with three contributions: First, we provide a detailed problem analysis based on a literature survey and six real-world practitioner expert interviews. Second, we propose a framework that supports organizations in implementing and performing ACP maintenance. Third, we present a maintenance case study in which we implemented maintenance capabilities for a real-world ACP dataset that allowed us to significantly improve its quality.



Beteiligte Einrichtungen


Details

DokumentenartKonferenz- oder Workshop-Beitrag (Paper)
ISBN978-3-031-37586-6
Buchtitel:Data and Applications Security and Privacy XXXVII
Verlag:Springer
Ort der Veröffentlichung:Cham
Sonstige Reihe:Lecture Notes in Computer Science
Band:13942
Seitenbereich:S. 223-242
Datum12 Juli 2023
InstitutionenWirtschaftswissenschaften > Institut für Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Informatik und Data Science > Fachbereich Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Identifikationsnummer
WertTyp
10.1007/978-3-031-37586-6_14DOI
Verwandte URLs
URLURL Typ
https://devise.ur.deProjekt
Stichwörter / KeywordsIdentity management, Access control, Access control policies, Data quality, Policy maintenance, Security management
Dewey-Dezimal-Klassifikation000 Informatik, Informationswissenschaft, allgemeine Werke > 004 Informatik
300 Sozialwissenschaften > 330 Wirtschaft
StatusVeröffentlicht
BegutachtetJa, diese Version wurde begutachtet
An der Universität Regensburg entstandenZum Teil
URN der UB Regensburgurn:nbn:de:bvb:355-epub-586603
Dokumenten-ID58660

Bibliographische Daten exportieren

Nur für Besitzer und Autoren: Kontrollseite des Eintrags

nach oben