DocumentCode
78366
Title
Security Policy Alignment: A Formal Approach
Author
Pieters, Wolter ; Dimkov, T. ; Pavlovic, D.
Author_Institution
Energy & Ind. Group, Delft Univ. of Technol., Delft, Netherlands
Volume
7
Issue
2
fYear
2013
fDate
Jun-13
Firstpage
275
Lastpage
287
Abstract
Security policy alignment concerns the matching of security policies specified at different levels in socio-technical systems, and delegated to different agents, technical and human. For example, the policy that sales data should not leave an organization is refined into policies on door locks, firewalls and employee behavior, and this refinement should be correct with respect to the original policy. Although alignment of security policies in socio-technical systems has been discussed in the literature, especially in relation to business goals, there has been no formal treatment of this topic so far in terms of consistency and completeness of policies. Wherever formal approaches are used in policy alignment, these are applied to well-defined technical access control scenarios instead. Therefore, we aim at formalizing security policy alignment for complex socio-technical systems in this paper, and our formalization is based on predicates over sequences of actions. We discuss how this formalization provides the foundations for existing and future methods for finding security weaknesses induced by misalignment of policies in socio-technical systems.
Keywords
authorisation; formal specification; organisational aspects; complex socio-technical systems; door locks; employee behavior; firewalls; formal approach; organization; security policy alignment; security weaknesses; well-defined technical access control scenarios; Access control; Authorization; Formal specifications; Organizational aspects; Sociotechnical systems; Attack trees; security logics; security policies; security policy alignment; security policy refinement; socio-technical systems; system models;
fLanguage
English
Journal_Title
Systems Journal, IEEE
Publisher
ieee
ISSN
1932-8184
Type
jour
DOI
10.1109/JSYST.2012.2221933
Filename
6363516
Link To Document