While I recently worked in the area of identity management, I had not much time for blogging. Now, our work has been published during the Wi2013 conference, which has been held in Leipzig from 27th of February to the 1st of March 2013. While this is a scientific paper, I have not much to say in addition to the paper’s content.
Abstract:
It is generally agreed upon the fact that the quality of Identity- and Access Management (IAM) data such as user accounts, access privileges or consistent user representation among different security domains is low. Growing user populations in medium- and large-sized organizations lead to a so called “identity chaos” in which over-privileged employees increase the risk of insider misuse. Recent governance and compliance mandates have amplified the importance of minimizing these risks. In order to fulfill these requirements, organizations focus on implementing role-based user management. To set up a role-based access control system, they face the challenge of modeling suitable roles for their employees. In this paper we show how the role modeling process can be improved by utilizing the so called access grid, a visualization technique to incorporate human interaction into the process of role creation.
If you’re interested, you can find the paper on http://epub.uni-regensburg.de/27930/
Meier, Stefan und Fuchs, Ludwig und Pernul, Günther (2013) Managing the Access Grid – A Process View to Minimize Insider Misuse Risks. In: Proceedings of the 11th International Conference on Wirtschaftsinformatik (WI2013), 27.2.-1.3.13, Leipzig.