翻訳と辞書
Words near each other
・ Organisation of Marxist–Leninist Communists of Greece
・ Organisation of Marxist–Leninists of Spain
・ Organisation of National Ex-Servicemen
・ Organisation of Serbian Students Abroad
・ Organisation of sport in Australia
・ Organisation of the Commissioner for Philately and Scripophily
・ Organisation of the Government of Singapore
・ Organisation of the League of Nations
・ Organisation of the Scottish Labour Party
・ Organisation of Toilers' Fedayan of Afghanistan
・ Organisation of Yemeni Revolutionary Resistors
・ Organisation of Young Free Algerians
・ Organisation pour la mise en valeur du fleuve Sénégal
・ Organisation Scientifique et Technique du Vol à Voile
・ Organisation Todt
Organisation-based access control
・ Organisational Learning Australia
・ Organisational routines
・ Organisational semiotics
・ Organisations associated with the Association of Southeast Asian Nations
・ Organisations with former royal patronage in Hong Kong
・ Organisationsforum Wirtschaftskongress
・ Organised and Financial Crime Agency of New Zealand
・ Organised Chaos
・ Organised Chaos LAN Party
・ Organised crime in Australia
・ Organised crime in Hong Kong
・ Organised crime in India
・ Organised crime in Pakistan
・ Organised Crime Task Force (Northern Ireland)


Dictionary Lists
翻訳と辞書 辞書検索 [ 開発暫定版 ]
スポンサード リンク

Organisation-based access control : ウィキペディア英語版
Organisation-based access control

In computer security, organization-based access control (OrBAC) is an access control model first presented in 2003. The current approaches of the access control rest on the three entities (''subject'', ''action'', ''object'') to control the access the policy specifies that some subject has the permission to realize some action on some object.
OrBAC allows the policy designer to define a security policy independently of the implementation. The chosen method to fulfill this goal is the introduction of an abstract level.
* Subjects are abstracted into roles. A role is a set of subjects to which the same security rule apply.
* Similarly, an activity is a set of actions to which the same security rule apply.
* And, a view is a set of objects to which the same security rule apply.
Each security policy is defined for and by an organization. Thus, the specification of the security policy is completely parameterized by the organization so that it is possible to handle simultaneously several security policies associated with different organizations. The model is not restricted to permissions, but also includes the possibility to specify prohibitions and obligations. From the three abstract entities (''roles, activities, views''), abstract privileges are defined. And from theses abstract privileges, concrete privileges are derived.
OrBAC is context sensitive, so the policy could be expressed dynamically. Furthermore, OrBAC owns concepts of hierarchy (''organization'', ''role'', ''activity'', ''view'', ''context'') and separation constraints. To design and implement security policies using the OrBAC model, the MotOrBAC tool has been developed. His simulation mode can be used to test a security policy. MotOrBAC also features a conflict detection function which helps the designer to find and solve conflicts.
==See also==

* Mandatory access control - MAC
* Discretionary access control - DAC
* Role-based access control - RBAC
* Bell–LaPadula model

抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)
ウィキペディアで「Organisation-based access control」の詳細全文を読む



スポンサード リンク
翻訳と辞書 : 翻訳のためのインターネットリソース

Copyright(C) kotoba.ne.jp 1997-2016. All Rights Reserved.