• DocumentCode
    2119592
  • Title

    An Access Control Model for Organisational Management in Enterprise Architecture

  • Author

    Gaaloul, Khaled ; Proper, Henderik A.

  • Author_Institution
    Centre de Rech. Public Henri Tudor, Luxembourg, Luxembourg
  • fYear
    2013
  • fDate
    3-4 Oct. 2013
  • Firstpage
    37
  • Lastpage
    43
  • Abstract
    Enterprise architecture (EA) aims to provide management with appropriate indicators and controls to steer and model service-oriented enterprises. EA offers a suitable operating platform to support an organisation´s future goals and the roadmap for moving towards this vision. Despite significant research interest in the domain, common enterprises architecture frameworks lack of access control mechanisms supporting security requirements within organisations. Security has become a matter of paramount concern when managing organisations resources such as stakeholders´ authorisation or sensitive data. In this paper, we propose an innovative approach for managing organisational resources in enterprise architecture. In doing so, we reason about task-based resources in the EA language ArchiMate. The idea is to build a conceptual model supporting access control when modelling a business process (set of tasks) in ArchiMate. We then map the common concepts with the role-based access control model (RBAC) to specify the required authorisation policies as part of the security specifications and guidelines in EA. Finally, a case study illustration will be used for the evaluation as part of the research approach.
  • Keywords
    authorisation; corporate modelling; organisational aspects; resource allocation; service-oriented architecture; EA language ArchiMate; RBAC; access control mechanisms; authorisation policies; business process modelling; enterprise architecture frameworks; organisation resource management; role-based access control model; security guidelines; security requirements; security specifications; sensitive data; service-oriented enterprise model; stakeholder authorisation; task-based resources; Authorization; Business; Information systems; Standards; Unified modeling language; Access control; ArchiMate; Authorisation; Enterprise architecture; RBAC; Task;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Semantics, Knowledge and Grids (SKG), 2013 Ninth International Conference on
  • Conference_Location
    Beijing
  • Type

    conf

  • DOI
    10.1109/SKG.2013.12
  • Filename
    6816582