• DocumentCode
    3408676
  • Title

    Policy-Based Management and Sharing of Sensitive Information Among Government Agencies

  • Author

    Ager, Tryg ; Johnson, Christopher ; Kiernan, Jerry

  • Author_Institution
    IBM Almaden Res. Center, San Jose, CA
  • fYear
    2006
  • fDate
    23-25 Oct. 2006
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    We propose a set of policy-based technologies to enable increased information sharing among government agencies without compromising information security or individual privacy. Our approach includes: (1) fine-grained access controls that support deny and filter semantics to satisfy complex policy conditions; (2) a sticky policy capability that allows consolidation of information from multiple sources subject to the original disclosure policies of each source; (3) a curation organization that enables agencies to apply and manipulate item-level security classifications and disclosure policies; (4) an auditing system that accounts for the curation history of each information item; and (5) a provenance auditing method that traces derivations of information over time to support evaluations of information quality. Our goal is to present a vision for solving outstanding information sharing problems in government agencies and provide direction for the development of future government information systems
  • Keywords
    authorisation; data privacy; database management systems; government data processing; government policies; information management; public information systems; security of data; auditing system; curation organization; disclosure policy; filter semantics; fine-grained access control; government agencies; government information system; individual privacy; information consolidation; information security; item-level security classification; policy-based management; policy-based technologies; provenance auditing method; sensitive information sharing; Control systems; Data security; Databases; Government; Information filtering; Information filters; Information security; Management information systems; Privacy; Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2006. MILCOM 2006. IEEE
  • Conference_Location
    Washington, DC
  • Print_ISBN
    1-4244-0617-X
  • Electronic_ISBN
    1-4244-0618-8
  • Type

    conf

  • DOI
    10.1109/MILCOM.2006.302517
  • Filename
    4086701