Re: Authorization Framework.

Sean Radford <[email protected]> Fri, 21 Jan 2005 12:52:53 +0000
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
Babu Kopparam wrote:

>Hi Experts,
>
>I am working for product company which own around 80 products.
>My role is to provide security framework to all the teams.
>
>  
>
Good thing. Security is not really unique to any application and so a 
solution to 'plug in' an existing framework/system should be sought. 
This is the ethos to the Componenet (& Service Orientated) Architectures 
that are more and more being utilised.

>I have proposed RBAC (referring NIST's specification) as the suitable
>solution for Authorization.
>
>  
>
This depends on you application needs. Traditional RBAC has grown out of 
the historical need for a system administrator to manage a system (as 
they were the only ones to have the IT skills to do so). More a more the 
access decision should be pushed down to the end-users who are 
responsible for the data/process.

>I want to know if my selection is right OR is there any other widely
>used method.
>
>Can you provide some links to gather more information about the same.
>
>Thanks in advance,
>-Babu.
>
>  
>


-- 
Dr. Sean Radford, MBBS, MSc
[email protected]
http://bladesys.demon.co.uk/