Computer access control policy choices
Computer access control policy choices
复制标题
计算机访问控制策略选择
DOI:
10.1016/0167-4048(90)90113-8
复制
发表时间:
1990
期刊:
影响因子:
--
通讯作者:
M. Abrams
中科院分区:
文献类型:
--
作者:
Ingrid M. Olson;M. Abrams
This paper provides a guide—a road map—for refining a high-level information dissemination/control policy into an implementable access control policy. This process involves determining the appropriate set of policy-oriented limitations and can take place at many levels, from a top-level corporate decision to a hardware implementation choice. The paper discusses many of the choices that need to be made in the process and some of the implications of making each decision. A discussion of the Generalized Framework for Access Control (GFAC), an ongoing research effort, presents a framework and new perspective for describing access controls. Discretionary Access Control and Mandatory Access Control are described within the GFAC framework, and two examples are given showing how changing some of the policy choices can represent a different policy which may meet a different set of access control requirements.