TY - JOUR
T1 - Comprehensive life cycle support for access rules in information systems
T2 - The CEOSIS project
AU - Rinderle-Ma, Stefanie
AU - Reichert, Manfred
PY - 2009/8
Y1 - 2009/8
N2 - The definition and management of access rules (e.g. to control access to business documents and business functions) is a fundamental task in any enterprise information system (EIS). While there exists considerable work on how to specify and represent access rules, only little research has been spent on access rule changes. Examples include the evolution of organisational models with need for subsequent adaptation of related access rules as well as direct access rule modifications (e.g. to state a previously defined rule more precisely). This paper presents a comprehensive change framework for the controlled evolution of role-based access rules in EIS. First, we consider changes of organisational models and elaborate how they affect existing access rules. Second, we define change operations which enable direct adaptations of access rules. In the latter context, we define the formal semantics of access rule changes based on operator trees. Particularly, this enables their unambiguous application, i.e. we can precisely determine which effects are caused by respective rule changes. This is important, for example, to be able to efficiently and correctly adapt user worklists in process-aware information systems. Altogether this paper contributes to comprehensive life cycle support for access rules in (adaptive) EIS.
AB - The definition and management of access rules (e.g. to control access to business documents and business functions) is a fundamental task in any enterprise information system (EIS). While there exists considerable work on how to specify and represent access rules, only little research has been spent on access rule changes. Examples include the evolution of organisational models with need for subsequent adaptation of related access rules as well as direct access rule modifications (e.g. to state a previously defined rule more precisely). This paper presents a comprehensive change framework for the controlled evolution of role-based access rules in EIS. First, we consider changes of organisational models and elaborate how they affect existing access rules. Second, we define change operations which enable direct adaptations of access rules. In the latter context, we define the formal semantics of access rule changes based on operator trees. Particularly, this enables their unambiguous application, i.e. we can precisely determine which effects are caused by respective rule changes. This is important, for example, to be able to efficiently and correctly adapt user worklists in process-aware information systems. Altogether this paper contributes to comprehensive life cycle support for access rules in (adaptive) EIS.
KW - Access control
KW - Access rule life cycle
KW - Change
KW - Enterprise information system
UR - http://www.scopus.com/inward/record.url?scp=70449688135&partnerID=8YFLogxK
U2 - 10.1080/17517570903045609
DO - 10.1080/17517570903045609
M3 - Article
AN - SCOPUS:70449688135
SN - 1751-7575
VL - 3
SP - 219
EP - 251
JO - Enterprise Information Systems
JF - Enterprise Information Systems
IS - 3
ER -