Von der individuellen zur organisatorischen benutzbaren Sicherheit : Partizipation und Interaktion für wirksame, effiziente und agile Berechtigungen

Autor: Bartsch, Steffen
Přispěvatelé: Bormann, Carsten, Sasse, Angela
Jazyk: angličtina
Rok vydání: 2012
Předmět:
Popis: Restrictions and permissions in information systems -- Authorization -- can cause problems for those interacting with the systems. Often, the problems materialize as an interference with the primary tasks, for example, when restrictions prevent the efficient completing of work and cause frustration. Conversely, the effectiveness can also be impacted when staff is forced to circumvent the measure to complete work -- typically sharing passwords among each other. This is the perspective of functional staff and the organization. There are further perspectives involved in the administration and development of the authorization measure. For instance, functional staff need to interact with policy makers who decide on the granting of additional permissions, and policy makers, in turn, interact with policy authors who actually implement changes. This thesis analyzes the diverse contexts in which authorization occurs, and systematically examines the problems that surround the different perspectives on authorization in organizational settings. Based on prior research and original research in secure agile development, eight principles to address the authorization problems are identified and explored through practical artifacts.
Databáze: OpenAIRE