Role Engineering - The Cornerstone of Role-Based Access Control
Published by CA on Jun 25, 2008
Role-based access control (RBAC) is becoming the norm for managing entitlements within commercial systems and applications. RBAC can play a significant role in establishing a model for enforcing security within organizations. It simplifies entitlement management by using roles (as opposed to users) as authorization subjects. Having a holistic approach to role definition can help alleviate certification-related regulatory compliance challenges, and should be considered an integral part of any IAM initiative.
|