Categorizing Access Management Challenges.ppt
《Categorizing Access Management Challenges.ppt》由会员分享,可在线阅读,更多相关《Categorizing Access Management Challenges.ppt(51页珍藏版)》请在麦多课文档分享上搜索。
1、Categorizing Access Management Challenges,Rob Carter, Duke University Scott Fullerton, University of Wisconsin,Overview,Whats all the fuss about, anyway? Maybe theres an approach we can use Overview and survey of higher ed use cases Breakin up big rocks Trying the approach on for size Some edge case
2、s from out in the wild,Whats all the fuss about?,Why is access management like the weather? Everyone talks about it, but (almost) no one seems to be doing anything about it But why,Whats all the fuss about?,Access management is a complex problem Lots of moving parts; lots of stakeholders; high stake
3、s Viewed monolithically, it can seem utterly intractable Access management is difficult to sell Everyone wants it, but no one wants to deal with it The problem space is huge Every resource, every application, has a need for access management,Whats all the fuss about?,How do you solve a problem like
4、Maria? Maria, who is the Dean of Medicine and wants to implement what she thinks is a simple rule In the campus purchasing system principal investigators should be able to approve purchases,Whats all the fuss about?,How do you solve a problem like Maria? Maria, who is the dean of Medicine and wants
5、to implement what she thinks is a simple rule In the campus purchasing system principal investigators should be able to approve purchases up to $100,000 for research projects,Whats all the fuss about?,How do you solve a problem like Maria? Maria, who is the dean of Medicine and wants to implement wh
6、at she thinks is a simple rule In the campus purchasing system principal investigators should be able to approve purchases up to $100,000 for research projects provided they have completed training on University purchasing processes and have filed the appropriate conflict of interest documentation,W
7、hats all the fuss about?,How do you solve a problem like Maria? Maria, who is the dean of Medicine and wants to implement what she thinks is a simple rule In the campus purchasing system principal investigators should be able to approve purchases up to $100,000 for research projects provided they ha
8、ve completed training on University purchasing processes and have filed the appropriate conflict of interest documentation until July 1, 2010,Whats all the fuss about?,The large print giveth (and the small print taketh away) And thats only one of thousands of scenarios,Whats all the fuss about?,its
9、no wonder the problem can seem intractable,Maybe theres an approach,Start from use cases or user stories Usually short (at least to begin with) Describe scenarios in terms the actors understand Help define the problem space as well as provide fodder for analysis Help ensure that solutions actually a
10、ddress real world problems,Maybe theres an approach,Evaluate, analyze, and decompose Try to break down use cases into common constituent parts Evaluate the breakdown; identify unique features and possibly some common features,Maybe theres an approach,Compare, abstract, and organize Look for similari
11、ties across cases Even dramatically different situations may yield to similar treatment Start to categorize the similarities; taxonomize,Maybe theres an approach,Identify classes of solutions; lather, rinse, repeat Consider the resources you might use to build solutions, and start to associate poten
12、tial solutions with categories of problems, applying one or more solutions associated with the category to new problems identified in that category, refining your categories and solutions as you gain experience, or to quota Zippy the Pinhead: “If it WIGGLES, SQUISH it!”,Maybe theres an approach,Use
13、Case Survey,If you didnt get to see them https:/spaces.internet2.edu/display/CAMPJune2009/Use+Cases+Organized+by+Area+of+Interest Use cases categorized by where they arise Good for surveying purposes,Use Case Survey,Business Operations Cases Deal With,Money, budgets, purchases, accounts Human Resour
14、ces and management Employee relationships Employee identities,Business Operations Cases Address,Organizational structure Delegation PCI compliance Audit,Use Case Survey,Academic / Research Cases Deal With,Learners, instructors, facultyClasses, registration Research products Collaborators Pedagogy Ev
15、aluation (testing, grading),Academic / Research Cases Address,Faculty hierarchy Course hierarchy FERPA Research collaboration Accreditation,Use Case Survey,Residential Life Cases Deal With,Students, staff, advisors Housing Safety Physical access,Residential Life Cases Address,Multiple affiliations T
16、ransient privileges Short privilege lifecycles,Use Case Survey,Library Use Cases Deal With,Patrons, Librarians Catalogs and collections Collaborators Professional organizations,Library Use Cases Address,Privacy Anonymity Blended identity Federations,Use Case Survey,Medical Center Use Cases Deal With
17、,Physicians, nurses, patients Medical records Referrals and consultations Controlled substances,Medical Center Use Cases Address,Urgency and Expediency Credentialing and qualifications HIPAA Oversight,Use Case Survey,Use cases from these six areas seem disjoint Different actors and objects Different
18、 activities Different concerns and complexities But of course, we wouldnt be talking,Analytic Approach,Lines of decomposition Subjects Grantor, grantee, resource Functions or Permissions Approve, update, authorize, add, delete, view, etc. Constraints Time limits; extents; scope,Analytic Approach,Sub
19、jects How are they (or could they be identified?) Ad Hoc List? Authoritative Source? Algorithmic? Self-described? Are they singleton or multiple?,Analytic Approach,Functions or Permissions Are permissions Singletons? Collections? Are permissions defined by Business role or activity? Inheritance or d
20、elegation? Ad hoc or Fiat? (but not GM ),Analytic Approach,Constraints Are grants to be limited in time? in scope? in extent? Are limits controlled by Fiat? Business role? Hierarchical position? Prerequisites?,Categorization,We might imagine, then, using this decomposition to classify use cases base
21、d on some common features, eg.: Single grantor, single grantee, single permission by fiat with no constraints (I give my car keys to my wife) Single grantor, multiple grantees identified by authoritative sources, multiple permissions by business role with no constraints (I allow my students into my
22、wiki without restriction) Multiple grantors identified by , multiple grantees identified ad hoc, single permission with no constraints (Deans can designate visitors who have access to the faculty club pool),Categorization,Business Case #4 Wellness Program Participation - A universitys HR department
23、offers a health and wellness program for university staff and faculty. The program is entirely voluntary. Participation requires a commitment by the employee to engage in a short online health awareness exercise, in return for which the university offers participants discounts on services at the uni
24、versity health club as well as periodic special offers from area business deemed by the university to be offering wellness-supporting services. A new employee in the physical plant hears about the program during an HR orientation and visits a web site to sign up. Once enrolled in the program, the em
25、ployee has access to the programs web portal and receives weekly email reminders about training opportunities and special offers.,Authority rests with HR department (business role) Grantor and grantee are the same, self-identified but constrained by authoritative source (only staff and faculty) Depe
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- CATEGORIZINGACCESSMANAGEMENTCHALLENGESPPT
