A tool for managing security policies in organisations

  • Authors:
  • Anna V. Álvarez;Karen A. García;Raúl Monroy;Luis A. Trejo;Jesús Vázquez

  • Affiliations:
  • Tecnológico de Monterrey, Atizapán de Zaragoza, Estado de México, Mexico;Tecnológico de Monterrey, Atizapán de Zaragoza, Estado de México, Mexico;Tecnológico de Monterrey, Atizapán de Zaragoza, Estado de México, Mexico;Tecnológico de Monterrey, Atizapán de Zaragoza, Estado de México, Mexico;Banco de México, México D.F., Mexico

  • Venue:
  • IWSEC'06 Proceedings of the 1st international conference on Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security policies are rules aimed at protecting the resources of an organisation from the risks associated with computer usage. Designing, implementing and maintaining security policies are all error prone and time consuming. We report on a tool that helps managing the security policies of an organisation. Security policies are formalised using first-order logic with equality and the unique names assumption, closely following the security policy language suggested in [1]. The tool includes a link to an automated theorem prover, Otter [2], and to a model finder, Mace [2], used to formally verify a set of formal security policies. It also includes a GUI and a number of links to read information and security policies from organisation databases and access control lists.