Popis: |
This article presents the method EB 3 SEC, extension of EB 3 , a formal method based on process algebra. It is designed to specify functional security policies for information systems. Three security levels can be specified, enabling us to define access control rules for elementary actions (SQL statements), services or transactions and also business processes. As the functional aspect of information systems can also be defined in EB 3 , the global consistency of the system can be verified. The article ends by describing an implementation of the method. |