DocumentCode
3643712
Title
Engineering Policies for Secure Interorganizational Information Flow
Author
Steffen Kunz;Benjamin Fabian;Daniel Marx;Sebastian Müller
Author_Institution
Inst. of Inf. Syst., Humboldt-Univ. zu Berlin, Berlin, Germany
fYear
2011
Firstpage
438
Lastpage
447
Abstract
Information flow between organizations has increased tremendously in recent years, for example in information federations of closely cooperating partners in a value chain. With this intensified exchange, information security becomes a major issue. In particular, coordinated access control policies must be derived by multiple organizations in a systematic fashion. However, current access-control modeling methodologies do not sufficiently address interorganizational information flow. In order to close this gap, we provide a methodology for engineering access control policies between multiple organizations, which is motivated and exemplified by a case study on information federation in the industrial service sector. Furthermore, we present a tool-supported approach for semi-automatic generation of interorganizational role-based access control policies derived from graphical business process models.
Keywords
"Access control","Information systems","Process control","Terminology","Companies"
Publisher
ieee
Conference_Titel
Enterprise Distributed Object Computing Conference Workshops (EDOCW), 2011 15th IEEE International
Print_ISBN
978-1-4577-0869-5
Type
conf
DOI
10.1109/EDOCW.2011.31
Filename
6037648
Link To Document