Abstract: |
In the field of risk management for access control systems, especially in database management systems, the access control policy is not too much explored as most researchers a priori hypothesize its reliability and validity. Access control policy is exposed to many irregularities throughout its evolution. During its lifecycle, it presents anomalies related to changes in its expression compared to what was initially established at an early stage or when it was designed. Our research leads to a risk management approach, with a particular focus on non-compliance anomalies found in the access control policy during its evolution. The correlation between these anomalies is also taken into consideration in order to optimize the proposed approach. Ultimately, we intend to produce a global and comprehensive risk management system based on the principles defined by the international standard. A system that manages the correlation between non-conformity anomalies is designed upstream to provide the necessary input for our new risk management approach that, as the main contribution, will also consider and overcome the effects induced by the correlation between anomalies found in the ACP expression. |