• DocumentCode
    3643712
  • Title

    Engineering Policies for Secure Interorganizational Information Flow

  • Author

    Steffen Kunz;Benjamin Fabian;Daniel Marx;Sebastian Müller

  • Author_Institution
    Inst. of Inf. Syst., Humboldt-Univ. zu Berlin, Berlin, Germany
  • fYear
    2011
  • Firstpage
    438
  • Lastpage
    447
  • Abstract
    Information flow between organizations has increased tremendously in recent years, for example in information federations of closely cooperating partners in a value chain. With this intensified exchange, information security becomes a major issue. In particular, coordinated access control policies must be derived by multiple organizations in a systematic fashion. However, current access-control modeling methodologies do not sufficiently address interorganizational information flow. In order to close this gap, we provide a methodology for engineering access control policies between multiple organizations, which is motivated and exemplified by a case study on information federation in the industrial service sector. Furthermore, we present a tool-supported approach for semi-automatic generation of interorganizational role-based access control policies derived from graphical business process models.
  • Keywords
    "Access control","Information systems","Process control","Terminology","Companies"
  • Publisher
    ieee
  • Conference_Titel
    Enterprise Distributed Object Computing Conference Workshops (EDOCW), 2011 15th IEEE International
  • Print_ISBN
    978-1-4577-0869-5
  • Type

    conf

  • DOI
    10.1109/EDOCW.2011.31
  • Filename
    6037648