Putting Context to Roles
Facebook Twitter LinkedIn

Managing the Complexity of Entitlements

Combined Session
Thursday, May 07, 2009 11:30—12:30
Location: GALAXIS

The idea of using business roles to manage the entitlements of IT users is appealing and widely accepted. The ANSI/INCITS standard for RBAC (role-based access control) provides a reference model for grouping entitlements into roles and assigning roles to users. The challenge for role engineering is to maximize role usability and to minimize the number of roles so that users do not get more entitlements than needed. The goal is to end up with substantially less roles than users. Experiences from typical IT environments show, however, that the number of existing entitlements is magnitudes higher than the number of users and the number of roles is not much less than the number of users. How can the complexity of entitlements be managed and at the same time the number of roles be kept to a minimum? Standard RBAC does not provide adequate means to achieve this goal.

The solution is to define generic business roles that are shaped by additional context information. Examples for such generic roles are employee, account manager, project member and project lead. Employees work in different departments and locations and their entitlements might differ for that reason. Therefore, the department and the location can be used as context information to tag the entitlements in the role definition. When the generic employee role is assigned to – for instance – Ms Moneypenny it is dynamically shaped to a London-MI5-employee role with the relevant entitlements only.

Putting context to roles helps to reduce the number of roles and thus makes user management easier. It pays off in higher security, increased efficiency and reduced administration costs.

Managing the Complexity of Entitlements
Presentation deck
Managing the Complexity of Entitlements
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Dr. Martin Dehn
Dr. Martin Dehn
KOGIT GmbH
Dr. Martin Dehn serves as Manager Consulting & Professional Services and Senior Solution Architect for KOGIT GmbH. His responsibilities for the Professional Services team include Customers...
Berthold Kerl
Berthold Kerl
Deutsche Bank AG
Berthold studied economics and computer science at the University of Nürnberg and graduated in 1988. Berthold has been with Deutsche Bank AG since 2002 where he performed in different roles:...
Alberto Ocello
Alberto Ocello
Crossideas
Alberto Ocello is a CrossIdeas founder and Chief Executive Officer. He was formerly the General Manager at Engiweb Security where he designed and led the product innovation of the IDEAS platform....
Deepak Taneja
Deepak Taneja
Aveksa
Deepak Taneja is the Founder and CTO of Aveksa, a security compliance software company. Prior to founding Aveksa, he was CTO and VP of Engineering at Netegrity. In this role, he was instrumental in...
Rudolf Wildgruber
Rudolf Wildgruber
Siemens IT Solutions and Services GmbH
Rudolf Wildgruber, graduated in computer science at the Technical University Munich in 1980 and worked for nearly 10 years for a medium-sized HW/SW manufacturer as systems engineer. From October...
Subscribe for updates
Please provide your email address