TAILIEUCHUNG - Proposal for Fast-Tracking NIST Role-Based Access Control Standard

Lots of users and privileges scattered over many platforms and applications. Who are the valid users? What are they entitled to access? How do you keep access rights up-to-date? How do you specify and enforce policy? | Proposal for Fast-Tracking NIST Role-Based Access Control Standard David Ferraiolo Rick Kuhn National Institute of Standards and Technology Gathersburg, Maryland Ravi Sandhu George Mason University Fairfax, Virginia Agenda Why an RBAC Standard? Is the Standard Ready to Go? Some of the Vendors Offering RBAC Products Accurate Configuration Control Over User Privileges Lots of users and privileges scattered over many platforms and applications. Who are the valid users? What are they entitled to access? How do you keep access rights up-to-date? How do you specify and enforce policy? Wherever I go, I ask two questions: What is the most important asset of your company? They kind of hem and haw. If I’m talking to a bank they might initially say my holdings; if I’m talking to a manufacturer company, they might say my incredible manufacturing plant. But when you really push them, it will get down to the answer being my people. Whether it’s their employees, their customers, their contractors, or their partners, ultimately it’s the people. Why? Gartner has done studies that state that over 85% of any information about a corporation is inside somebody’s head. Only 15% of the corporation’s information is actually in repositories, in databases, on the web, in some kind of a manual infrastructure. So if 85% of the intelligence around how companies work is in people’s head, it’s pretty easy to see why people are the most important asset of a company. Then the next question I ask is “what’s your biggest challenge?” You get everything from Greenspan’s killing me, we just had an earthquake 2 days ago and that’s killing me, to XYZ Corporation, my competitor, did this and that’s really killing me. But when you really circle around it, it’s change. If you really think about it, what company have you ever worked for that has not required you to rethink or change how you do something, who you do it with, what tools you get to use? Every time there is a government regulation change, .

TỪ KHÓA LIÊN QUAN
TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.