(ISC)² Twitter Updates

  • (ISC)² Twitter Updates

    About the
    (ISC)² Blog

    • (ISC)² believes in the importance of open dialogue and collaboration, between both (ISC)², its certified members and members of business and society.

      (ISC)² established this blog to provide a voice to its certified members, who have significant knowledge and valuable insights to share that can benefit the information security industry, the people in it and the public at large.

      The postings on this site are the author's own and don't necessarily represent
      (ISC)²'s positions, strategies or opinions. (ISC)² does not control, monitor, or endorse any links provided in this blog and makes no warranty or statement regarding the content on any linked website.

      Those who post comments to blogs should ensure their comments are focused on the topic at hand. (ISC)² reserves the right to remove any post or comment from this site.

      Should you find objectionable content in this blog, please notify us as soon as possible at blog@isc2.org.

      Please click here for FAQs.

      Please click here for the Blog guidelines.

    « Where Is Your Sensitive Data? | Main | Choosing the right security personnel »

    19 June 2008

    TrackBack

    TrackBack URL for this entry:
    http://www.typepad.com/services/trackback/6a00e54f109b67883400e5537880ab8834

    Listed below are links to weblogs that reference RBAC - How to Eat the Elephant:

    Comments

    Comments regarding the role model.
    Most people tend to think that the role model, the basis for RBAC, simply consolidate 80% of the access rights in groups that together correspond to one or more business functions as they are defined in the org-chart or HR system.
    The fact is that the role model should consist three layers:
    1. The role layer (as already discussed)
    2. The privileges layer – even in perfect role model, some access rights are left out side role definitions. Managing those is as important as managing the roles.
    3. Policies – after all there are role combinations that are toxic (cannot be granted together), or combinations that must be assigned as a group. Those policies of deployment are part of the role model

    Without those the role model is too shallow, but adding to the implementation project doesn't means that the elephant will grow to a size of dinosaur.
    Mature tools offer full discovery and management capabilities for full role model, that easily support the implementation, and more important increase the value of RBAC to the business people

    Azi Cohen
    The writer is the CEO of Eurekify, a provider of enterprise role management solution

    The comments to this entry are closed.

    Enter your email address:

    Delivered by FeedBurner

    Recent Contributors

    Past Contributors