A Financial Institution's Legacy Mainframe Access Control System in Light of the Proposed NIST RBAC Standard

  • Authors:
  • Andrew D. Marshall

  • Affiliations:
  • -

  • Venue:
  • ACSAC '02 Proceedings of the 18th Annual Computer Security Applications Conference
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we describe a mainframe access controlsystem (DENT) and its associated delegated administrationtool (DSAS) that were used in a financial institution for over20 years to control access to banking transaction products.The fir st part of this paper describes the design and oper-ationof DENT/DSAS as an example of a long-lived accesscontrol system in a financial institution.A standard for Role-Based Access Control (RBAC) hasrecently been proposed by the United States National Insti-tuteof Standards and Technology (NIST). The second partof this paper discusses how the functionality of DENT/DSAScould be achieved by applying its principles of operationwithin the NIST model. In so doing we also evaluate theproposed standard by validating it against the requirementsembodied in a successful access control system.We conclude with some observations about the designof DENT/DSAS and suggestions for changes in the pro-posedRBAC standard to accommodate some features ofDENT/DSAS that it does not appear to support.