Network World
Thursday, January 8, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Model driven security: authorization/entitlement management needs to be manageable

This article outlines well why externalized authorization policies are the way forward. What it does not really clarify is that authorization management does not really provide that much value if the full complexity of all access rules across the IT environment is essentially aggregated into one place. There are numerous vendors in this space, and I believe this is where XACML may eventually provide vendor interoperability.

The more interesting question is how to actually manage these policies, i.e. how to make these authorization/entitlement management solutions actually manageable. Neither XACML and "normal" authorization management solutions provide any support for actually reducing the complexity significantly. This topic is called "Model Driven Security" (www.modeldrivensecurity.org, www.modeldrivensecurity.com). Gartner has put this topic onto the hype cycle.
We are currently the only real vendor in this space with our OpenPMF 2.0 technology (www.openpmf.com). It uses the concepts of Model Driven Architecture actually allow you to generate the rules that go into authorization management systems (e.g. XACML).
This may clarify things somewhat.

Dr. Ulrich Lang
CEO ObjectSecurity – World Leader in Model Driven Security Management
www.objectsecurity.com

Click to read the article this is in response to.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: