A Framework for Organisational Control Principles

  • Authors:
  • Andreas Schaad;Jonathan D. Moffett

  • Affiliations:
  • -;-

  • Venue:
  • ACSAC '02 Proceedings of the 18th Annual Computer Security Applications Conference
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Organisational control principles, such as thoseexpressed in the separation of duties, supervision, reviewand delegation, support the main business goals andactivities of an organisation. Some of these principleshave previously been described and analysed within thecontext of role- and policy-based distributed systems, butlittle has been done with respect to the more generalcontext they are placed in and the analysis ofrelationships between them.This paper presents a framework in whichorganisational control principles can be formallyexpressed and analysed using the Alloy specificationlanguage and its constraint analysis tools.