• DocumentCode
    1994312
  • Title

    Conceptual foundations for a model of task-based authorizations

  • Author

    Thomas, Roshan K. ; Sandhu, Ravi S.

  • Author_Institution
    Dept. of Inf. Syst. & Syst. Eng., George Mason Univ., Fairfax, VA, USA
  • fYear
    1994
  • fDate
    14-16 Jun 1994
  • Firstpage
    66
  • Lastpage
    79
  • Abstract
    We describe conceptual foundations to address integrity issues in computerized information systems from the enterprise perspective. The motivation for this effort stems from the recognition that existing models are formulated at too low a level of abstraction, to be useful for modeling organizational requirements, policy aspects, and internal controls, pertaining to maintenance of integrity in information systems. In particular, these models are primarily concerned with the integrity of internal data components within computer systems, and thus lack the constructs necessary to model enterprise level integrity principles. The starting point in the investigation is the notion of authorization functions and tasks associated with business activities carried out in the enterprise. These functions identify the authorization requirements while the authorization tasks embody the concepts required to carry out such authorizations. We believe a model of task-based authorizations will bridge the existing gap between low-level models and very high level ones looking at integrity from a purely organizational and sociological perspective devoid of any direct links to computerized systems. The work described is preliminary and conceptual in nature, but is a necessary prerequisite for the eventual development of a formal model
  • Keywords
    authorisation; data integrity; information systems; security of data; social aspects of automation; authorization functions; authorization requirements; business activities; computerized information systems; conceptual foundations; enterprise level integrity principles; enterprise perspective; formal model; integrity issues; internal controls; internal data components; organizational requirements; policy aspects; sociological perspective; task-based authorizations; Authorization; Automation; Data engineering; Data processing; Distributed computing; Information security; Information systems; Protection; Software systems; Systems engineering and theory;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Foundations Workshop VII, 1994. CSFW 7. Proceedings
  • Conference_Location
    Franconia, NH
  • ISSN
    1063-6900
  • Print_ISBN
    0-8186-6230-1
  • Type

    conf

  • DOI
    10.1109/CSFW.1994.315946
  • Filename
    315946