Separation of Duties in Computerized Information Systems

We describe a novel general-purpose mechanism for enforcing separation of duties in computerized information systems. This mechanism of transaction control expressions has close similarities to traditional controls in manual paper-based systems. It has the great bene t of intuitive simplicity, in both concept and implementation.

[1]  Ravi S. Sandhu,et al.  Recognizing Immediacy in an N-Tree Hierarchy and Its Application to Protection Groups , 1989, IEEE Trans. Software Eng..

[2]  Jim Gray,et al.  Notes on Data Base Operating Systems , 1978, Advanced Course: Operating Systems.

[3]  Paul A. Karger,et al.  Implementing commercial data integrity with secure capabilities , 1988, Proceedings. 1988 IEEE Symposium on Security and Privacy.

[4]  Simon R. Wiseman,et al.  A 'new' security policy model , 1989, Proceedings. 1989 IEEE Symposium on Security and Privacy.

[5]  Z. G. Ruthberg,et al.  Report of the Invitational Workshop on Data Integrity | NIST , 1989 .

[6]  Theodore M. P. Lee,et al.  Using mandatory integrity to enforce 'commercial' security , 1988, Proceedings. 1988 IEEE Symposium on Security and Privacy.

[7]  Ravi S. Sandhu,et al.  The NTree: a two dimension partial order for protection groups , 1988, TOCS.

[8]  Ravi Sandhu,et al.  Transaction control expressions for separation of duties , 1988, [Proceedings 1988] Fourth Aerospace Computer Security Applications.

[9]  Michael J. Nash,et al.  Some conundrums concerning separation of duty , 1990, Proceedings. 1990 IEEE Computer Society Symposium on Research in Security and Privacy.

[10]  K. J. Bma Integrity considerations for secure computer systems , 1977 .

[11]  David D. Clark,et al.  A Comparison of Commercial and Military Computer Security Policies , 1987, 1987 IEEE Symposium on Security and Privacy.

[12]  Joseph H. Wimbrow A Large Scale Interactive Administrative System , 1971, IBM Syst. J..

[13]  Abraham Silberschatz,et al.  Access-Right Expressions , 1983, TOPL.

[14]  Ron Weber,et al.  EDP Auditing: Conceptual Foundations and Practice , 1988 .