INCITS 459-2011

Information Technology – Requirements for the Implementation and Interoperability of Role Based Access Control


 

 

非常抱歉,我们暂时无法提供预览,您可以试试: 免费下载 INCITS 459-2011 前三页,或者稍后再访问。

如果您需要购买此标准的全文,请联系:

点击下载后,生成下载文件时间比较长,请耐心等待......

 

标准号
INCITS 459-2011
发布日期
2011年01月14日
实施日期
2016年12月14日
废止日期
中国标准分类号
/
国际标准分类号
/
发布单位
ANSI - American National Standards Institute
引用标准
27
适用范围
"The System and Administrative Functional Specification clause [clause 6] in INCITS 359-2004 (R2009) specifies the features that are required of an RBAC system. These features fall into three categories: administrative operations@ administrative reviews@ and system level functionality. This standard specifies the implementation of RBAC systems. It describes the packaging of features through the selection of functional components and feature options within a component@ beginning with a core set of RBAC features that shall be included in all packages. Other components that may be selected in arriving at a relevant package of features pertain to role hierarchies@ static constraints (e.g.@ Static Separation of Duty or SSD)@ and dynamic constraints (e.g.@ Dynamic Separation of Duty or DSD). These are defined in Section 4. This standard specifies that compliant RBAC products shall include an audit and reporting function. This function is not present in INCITS 359-2004 (R2009)@ but shall be available in compliant RBAC products. This standard also specifies interoperability requirements that facilitate the exchange of RBAC system data between two systems. Interoperability is here defined as the ability of two systems to participate in the exchange of RBAC definition data in a non-operational state. To address this@ the standard describes options for the interchange of RBAC elements (e.g.@ roles@ permissions@ users) and for functional interoperability among RBAC services and applications. The standard recognizes a distinction between ""Business Role"" and ""IT Role."" Business roles are those commonly found in the business environment@ e.g.@ an individual's role in the organization. This role is not necessarily implemented in any information technology (IT) system. Thus@ a business role is a job function of an individual within an organization. IT roles are those roles that are implemented in an IT system. These roles may reflect business roles@ but may also be unique to the IT system because of the particular permissions present in the system. IT roles may themselves be classified into structural roles and functional roles. This distinction is described in Annex C. The scope of this standard covers IT roles and not necessarily business roles. This standard is concerned with the implementation and translation of access privileges within IT systems. In recognition of the fact that systems and components may not include all features described in INCITS 359-2004 (R2009)@ the definitions of components that derive from INCITS 359-2004 (R2009) may be only partially implemented in RBAC products. The use of this standard is intended for implementations of the RBAC infrastructure. Role definition processes (role engineering) may be addressed in a future standard. This standard provides a generalized syntax and data model for developing use cases for implementation of interoperable RBAC systems."




Copyright ©2007-2022 ANTPEDIA, All Rights Reserved
京ICP备07018254号 京公网安备1101085018 电信与信息服务业务经营许可证:京ICP证110310号