{"title":"A survey to determine federal agency needs for a role-based access control security product","authors":"C. Smith","doi":"10.1109/SESS.1997.595975","DOIUrl":null,"url":null,"abstract":"This paper is an overview of a study done for the National Institute of Standards and Technology (NIST) to determine what potential market there is for a role-based access control (RBAC) product. Thirty security managers from 27 large civil federal organizations were interviewed using a six-page questionnaire. Their security needs were identified and it was concluded that these organizations desired an RBAC product to complement their mandatory and discretionary access control products. The results of the main reference study (Smith et al., 1996) will be used by NIST personnel as an input to the formulation of standards for future RBAC products.","PeriodicalId":345428,"journal":{"name":"Proceedings of IEEE International Symposium on Software Engineering Standards","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1997-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of IEEE International Symposium on Software Engineering Standards","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SESS.1997.595975","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7
Abstract
This paper is an overview of a study done for the National Institute of Standards and Technology (NIST) to determine what potential market there is for a role-based access control (RBAC) product. Thirty security managers from 27 large civil federal organizations were interviewed using a six-page questionnaire. Their security needs were identified and it was concluded that these organizations desired an RBAC product to complement their mandatory and discretionary access control products. The results of the main reference study (Smith et al., 1996) will be used by NIST personnel as an input to the formulation of standards for future RBAC products.
本文概述了为美国国家标准与技术研究所(NIST)所做的一项研究,该研究旨在确定基于角色的访问控制(RBAC)产品的潜在市场。来自27个大型民事联邦组织的30名安全管理人员接受了一份6页的问卷调查。确定了他们的安全需求,得出的结论是,这些组织需要一个RBAC产品来补充他们的强制性和酌情访问控制产品。主要参考研究的结果(Smith et al., 1996)将被NIST人员用作制定未来RBAC产品标准的输入。