Access control
Adequate information and system security is a fundamental responsibility of management. Access control plays a vital role in nearly all applications that handle financial, privacy, safety, or defense-related data. It involves determining the permissible actions of authorized users and managing every attempt made by a user to access system resources. While some systems grant complete access after successful authentication, most systems require more sophisticated and complex control mechanisms. In addition to authentication, access control considers how authorizations are structured. This may involve aligning authorizations with the organization’s structure or basing them on the sensitivity of documents and the clearance level of users accessing them.
When organizations plan to implement an access control system, they need to consider three crucial abstractions: access control policies, models, and mechanisms.
Access control policies are overarching requirements...