{"title":"The PEI framework for application-centric security","authors":"R. Sandhu","doi":"10.4108/ICST.COLLABORATECOM2009.8382","DOIUrl":null,"url":null,"abstract":"This paper motivates the fundamental importance of application context for security. It then gives an overview of the PEI framework for application-centric security and outlines some of the lessons learned in applying this framework. PEI stands for Policy, Enforcement and Implementation, signifying three distinct layers at which security policy and design decisions need to be made. The framework was introduced by this author in 2006. It is closely related to the earlier OM-AM framework also introduced by this author in 2000.","PeriodicalId":318752,"journal":{"name":"2009 Proceedings of the 1st International Workshop on Security and Communication Networks","volume":"35 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-05-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"15","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 Proceedings of the 1st International Workshop on Security and Communication Networks","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4108/ICST.COLLABORATECOM2009.8382","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 15
Abstract
This paper motivates the fundamental importance of application context for security. It then gives an overview of the PEI framework for application-centric security and outlines some of the lessons learned in applying this framework. PEI stands for Policy, Enforcement and Implementation, signifying three distinct layers at which security policy and design decisions need to be made. The framework was introduced by this author in 2006. It is closely related to the earlier OM-AM framework also introduced by this author in 2000.