SlideShare a Scribd company logo
ReMoLa: Responsibility Model Language to Align
Access Rights with Business Process Requirements
Christophe Feltus, Michaël Petit, Eric Dubois
Fifth IEEE International Conference on Research Challenges in Information
Science, May 19-21 2011, Guadeloupe - French West Indies, France
 Governance requirements
 1st statement :The responsibility of the employees
involved in the processes must be strictly defined and
correctly assigned to the employee:
 In ISO IEC 38500:2008 – Corporate Governance of ICT
 In Sarbanes-Oxley Act’s – Title III corporate responsibilities
 In Basel II – Responsibility of the board of directors
 2nd statement : One of the requirements is to have
access rights strictly aligned with the business process
 ISO 27000, CobiT, etc.
 Aligning access rights with BP
 Responsibility model
 Presentation of the main concepts of the model
 Links between these concepts
 Alignment method
 Presentation of the method
 Definition of the responsibilities, Assignment of the responsibilities,
Provisioning of the access rights
 Proof-of-concept
 Analyze of the System Acceptance from ISO/IEC 27002/2005,
Code of practice for information security management.
 Definition of the responsibilities
 Conclusions and future works
 Responsibility model
 Presentation of the main concepts of the model
 Links between these concepts
 Alignment method
 Presentation of the method
 Definition of the responsibilities, Assignment of the responsibilities,
Provisioning of the access rights
 Proof-of-concept
 Analyze of the System Acceptance from ISO/IEC 27002/2005,
Code of practice for information security management.
 Definition of the responsibilities
 Conclusions and future works

Recommended for you

Patient’s right
Patient’s rightPatient’s right
Patient’s right

Patients at Hospital Changkat Melintang have rights that respect their personal dignity, values, and preferences. They have the right to receive considerate care without discrimination. They also have the right to effective communication, involvement in treatment decisions, privacy and confidentiality, pain management, and understanding of medical charges. If patients have concerns about their care, the hospital provides processes to lodge and address complaints.

Patients rights and responsibilities
Patients rights and responsibilitiesPatients rights and responsibilities
Patients rights and responsibilities

Col.( Dr) Dayananda on the Rights of Patients. First hand experiences as a Doctor and Medical Administrator in the Army and without.

Unit 201 Employee Rights & Responsibilities
Unit 201 Employee Rights & Responsibilities Unit 201 Employee Rights & Responsibilities
Unit 201 Employee Rights & Responsibilities

This document discusses employment rights and responsibilities legislation in the United Kingdom. It covers the main pieces of legislation such as the Employment Rights Act 1996, the Employment Relations Act 2004, and the Employment Act 2008. It describes the key rights and responsibilities outlined in these acts, such as minimum wage, holiday and sick leave, maternity and paternity leave, and protections against unfair dismissal. The document also discusses requirements for providing statements of employment and equality and diversity policies in the workplace.

Presentation of the Responsibility model
 Elaboration of the model
 Employee, right, obligation, commitment
Presentation of the Responsibility model
 4 types of obligation
 In order to refine the model, we use the CobiT RACI chart
that describes 4 types of obligation
 Responsible: an employee who performs a task
 Accountable: an employee that directs and makes authorization
 Consulted: an employee that makes consultancy to permit a task
to be done
 Informed: an employee that is informed about the achievement
of a task
Presentation of the Responsibility model
Responsible Accountable
 Responsibility model
 Presentation of the main concepts of the model
 Links between these concepts
 Alignment method
 Presentation of the method
 Definition of the responsibilities, Assignment of the responsibilities,
Provisioning of the access rights
 Proof-of-concept
 Analyze of the System Acceptance from ISO/IEC 27002/2005,
Code of practice for information security management.
 Definition of the responsibilities
 Conclusions and future works

Recommended for you

Crispin Porter + Bogusky employee handbook
Crispin Porter + Bogusky employee handbookCrispin Porter + Bogusky employee handbook
Crispin Porter + Bogusky employee handbook

This document is an employee handbook for Crispin Porter + Bogusky, an advertising agency. It welcomes new employees and explains that while some may love working there and others may hate it, the experience will be memorable. It defines the agency's broad view of advertising as anything that promotes their clients, not just traditional media. It emphasizes the agency's strong culture and the passion, confidence, and work ethic needed to generate great ideas even when original ideas fail. It frames the work as operating like a factory to produce marketing products and stresses the importance of execution over simply discussing ideas.

Employee Rights
Employee RightsEmployee Rights
Employee Rights

The document discusses various employee rights and responsibilities in the workplace. It covers statutory rights based on laws, contractual rights based on employment agreements, and implied rights based on promises made by employers. It also discusses employment-at-will, exceptions to at-will employment, wrongful discharge, constructive discharge, and ensuring fairness and due process. Finally, it outlines policies, procedures, rules, discipline processes, and other HR responsibilities regarding employees.

Patient rights ppt
Patient rights pptPatient rights ppt
Patient rights ppt

The document discusses patient rights and consumer protection laws in India. It outlines the Patient's Bill of Rights adopted in 1998 to protect ethics in healthcare. The key rights include privacy, informed consent, and quality care without discrimination. It also describes the Consumer Protection Act of 1986, which established forums to address consumer grievances in defective goods and services. Under the Act, medical services are included, allowing for compensation in cases of medical negligence.

Presentation of the Alignment method
 Our approach
 2 layers Business/Technical and 2 levels Language/Instantiation
 Method:
 Definition of the responsibilies from business layer
 Assignement of the responsibilities
 AR provisioning
Presentation of the Alignment method
 Mapping BP / ReMoLa in order to elaborate responsibilities
 Instantiation of Task/Obligation,
Accountabilities, Right Step 2 Step 1
e.g. CobiT,
ISO 15504
Presentation of the Alignment method
BP owner
Responsibil. DelegatorEmployee Employee’s manager RBAC Administrator
Step 3
 Mapping of ReMoLa with one AC Model
 Role Based Access Control
 To simplify the management of granting permissions to
 3 main elements :
 User, Role and Permission
 2 main functions :
 User-role
assignment (URA)
 Permission-role
assignment (PRA)
Presentation of the Alignment method

Recommended for you

rights and legal aspects of disability in India
rights and legal aspects of disability in Indiarights and legal aspects of disability in India
rights and legal aspects of disability in India

The document discusses laws and policies related to disability rights in India. It provides an overview of the Indian Lunacy Act (1912), Mental Health Act (1987), Rehabilitation Council of India Act (1992), Persons with Disabilities Act (1995), National Trust Act (1999), Right to Education Act (2010) and the United Nations Convention on the Rights of Persons with Disabilities. The key goals of these acts and policies are to empower and integrate persons with disabilities, ensure equal opportunities, and promote their full participation and independent living in society.

Employment Rights & Responsibilities Presentation
Employment Rights & Responsibilities PresentationEmployment Rights & Responsibilities Presentation
Employment Rights & Responsibilities Presentation

The document discusses health and safety responsibilities for employees and employers. It states that employers are responsible for implementing risk assessments, emergency procedures, training, and cooperating with other employers. Employees are responsible for taking reasonable care of their own safety, reporting any injuries or illnesses, and informing employers of anything affecting their ability to work. The document also outlines sick pay rights, maternity pay eligibility and amounts, and working hours regulations including limits for average weekly hours and definitions of work vs non-work time.

396849 developing-business-it-solutions
396849 developing-business-it-solutions396849 developing-business-it-solutions
396849 developing-business-it-solutions

This document provides an overview of developing business/IT solutions and the systems development process. It discusses the traditional systems development cycle as well as prototyping and end user approaches. The systems development cycle involves conception, design, and implementation of systems to meet business needs. It outlines the key stages of systems investigation, analysis, design, implementation, and maintenance. It also discusses evaluating hardware, software, and service acquisition. The goal is to use a systematic approach to analyze needs and design effective IT solutions to address business opportunities.

developing-business-it-solutionsit governance
RBAC Role is a type of responsibility : an employee assigned to that
responsibility gets all the permissions needed by that responsibility.
Although if RBAC Role is a business role : an employee assigned to
that role is not obligatory assigned responsible for all the tasks of
the role. He receives to many permissions.
Presentation of the Alignment method
 Responsibility model
 Presentation of the main concepts of the model
 Links between these concepts
 Alignment method
 Presentation of the method
 Definition of the responsibilities, Assignment of the responsibilities,
Provisioning of the access rights
 Proof-of-concept
 Analyze of the System Acceptance from ISO/IEC 27002/2005,
Code of practice for information security management.
 Definition of the responsibilities
 Conclusions and future works
Proof-of-concept : System Acceptance
 Audit of the employees’ access rights for the process:
System Acceptance
 Audit observations :
 5 employees with a set of rights and assigned to a business role
 Are these rights strictly
necessary for the employees ?
Employees Rights
Carla Access to all
Access to the list of requirements
Access to migration priorities
Allow participating in migration meetings
Access to the migration risks
Access to operational efficiencies requirements
Access to migration priorities
Allow to participate migration meetings
Access migration risk analysis
Access to preparation template
Access to testing template
Access to the training support
Time to participate to training
Access to the system manual
Access to the set of security controls in place
Access to the list of errors
Bob Access to the tests results
Employees Business roles
Carla Chief information officer
Alice Employee assigned to the System Acceptance process
Emma System Acceptance process manager
Denis Project leader
Bob System architect
 Definition of the responsibilities
 Identification of the tasks that compose the System Acceptance
 Based on the task semantic,
the associations with a RACI
obligations are possible.
 Based upon the type of
obligation, the specific
responsibility model can be
taken into consideration
 Alice needs access rights, commitment, is answerable,…
Proof-of-concept : System Acceptance
Tasks Obligation
Ensure that the requirements and criteria for acceptance of
new systems are clearly defined, agreed, documented, and
Provide acceptance for the migration of new information
systems, upgrades, and new versions
Ensure the operational efficiency of the proposed system
Preparation and testing of routine operating procedures to
defined standards
Training in the operation or use of new systems I
Agreed set of security controls in place A
Appropriate tests should be carried out to confirm that all
acceptance criteria have been fully satisfied
Consider error recovery and restart procedures, and
contingency plans
Responsibility of Alice

Recommended for you

ITIL V3 Overview
ITIL V3 OverviewITIL V3 Overview
ITIL V3 Overview

This document provides an overview of ITIL (Information Technology Infrastructure Library) concepts including the ITIL service lifecycle. It defines key terms like service, service management, and discusses ITIL versions 2 and 3. It also covers ITIL principles such as focusing on customer satisfaction and the strategic role of IT. Process models, organizational roles, and the five stages of the ITIL service lifecycle are outlined.

itil v3
Unit 4 standards.ppt
Unit 4 standards.pptUnit 4 standards.ppt
Unit 4 standards.ppt

The document provides information on various models, frameworks, standards and methodologies related to information security. It discusses models and frameworks, noting that a model is abstract while a framework provides more specific guidance. It defines standards and methodology. It then summarizes several specific models/frameworks - ISO 27001, COBIT, and SSE-CMM. It also outlines some methodologies for information security assessment - IAM, IEM, and SIPES, describing their objectives and phases.

System Development Life Cycle
System Development Life CycleSystem Development Life Cycle
System Development Life Cycle

The document discusses the system development life cycle (SDLC), which includes 5 stages: system planning, system analysis, system design, system implementation, and system operation. The accountant plays an important role in several of these stages. In system planning, accountants provide expertise in evaluating feasibility and ensuring careful planning. In system analysis, accountants are important players in designing controls. In system design, accountants ensure accounting considerations are included. In implementation, accountants help with training and follow-up studies. In operation, accountants participate in post-implementation reviews and periodic system reviews.

 Right to task association
 In most of the business
frameworks, and in ISO 27002
as well, rights are not explicitly
 Need for fine grain analysis
to engineer rights that
are needed to perform a task.
Proof-of-concept : System Acceptance
Tasks Rights
Ensure that the requirements and
criteria for acceptance of new
systems are clearly defined, agreed,
documented, and tested
Access to the list of requirements
Access to the agreement
Access to the test results
Provide acceptance for the
migration of new information
systems, upgrades, and new
Access to migration priorities
Access to migration meetings
Access migration risk analysis
Ensure the operational efficiency of
the proposed system design
Access to operational efficiencies
requirements list
Preparation and testing of routine
operating procedures to defined
Access to preparation template
Access to testing template
Training in the operation or use of
new systems
Access to the training support
Time to participate to training
Access to the system manual
Agreed set of security controls in
Access to the set of security
controls in place
Appropriate tests should be carried
out to confirm that all acceptance
criteria have been fully satisfied
No access required
Consider error recovery and restart
procedures, and contingency plans
Access to the list of errors
 Audit conclusions
 Observation :Alice is an employee assigned to the System Acceptance process
and she gets access because of her Business Role
 the list of requirements,
 migration priorities,
 allow participation in migration meetings,
 migration risks
 access to operation efficiencies requirements list
 Using ReMoLa :Alice is responsible for Providing acceptance for the migration
of new information systems, upgrades, and new versions and needs only the
following rights:
 access to migration priorities,
 allow participating in migration meetings,
 access to migration risks.
Proof-of-concept : System Acceptance
 Responsibility model
 Presentation of the main concepts of the model
 Links between these concepts
 Alignment method
 Presentation of the method
 Definition of the responsibilities, Assignment of the responsibilities,
Provisioning of the access rights
 Proof-of-concept
 Analyze of the System Acceptance from ISO/IEC 27002/2005,
Code of practice for information security management.
 Definition of the responsibilities
 Conclusions and future works
Conclusions and future works
 Business needs for a better alignement of the employees’
responsibility from the management frameworks down to
the technical rules
 Our approach :
 Step 1: Definition of the responsibilities :
 Business Role, Activities, Tasks, Obligations  Responsibilities
 Step 2 : Responsibility to employee assignment
 Step 2 : Rights to responsibility association
 Future works
 Complementary validations using case studies – One ongoing and
one begins in June
 Looking forward for integration within ArchiMate and others EA.

Recommended for you

Ch 2-RE-process.pptx
Ch 2-RE-process.pptxCh 2-RE-process.pptx
Ch 2-RE-process.pptx

This document discusses the requirements engineering (RE) process. It defines a process as a set of organized activities that transforms inputs to outputs. The RE process involves problem analysis and product description tasks that run iteratively. Key activities in the RE process include requirements elicitation, analysis, specification, validation and management. The document also discusses factors like process models, actors, variability, safety requirements, support tools, improvement and maturity levels.

Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management

This document proposes an innovative approach called SIM (Secure Identity Management) that aims to make access management policies closer aligned with business objectives. It does this in two ways: 1) By focusing the policy engineering process on business goals and responsibilities defined in processes, using concepts from the ISO/IEC 15504 standard. This links capabilities and accountabilities to process outcomes and work products. 2) By defining a multi-agent system architecture to automate the deployment of policies across heterogeneous IT components and devices. The agents provide autonomy and ability to adapt rapidly according to context. The approach was prototyped using open source components and aims to improve how access rights are defined according to business needs and deployed across an organization

Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management

This document proposes an innovative approach called SIM (Secure Identity Management) that aims to define access control policies in a way that is closely aligned with business objectives. It does this by linking concepts from the ISO/IEC 15504 process-based model for organizing work to concepts of responsibility. The approach also defines a multi-agent system architecture to automate the deployment of access policies across an organization's heterogeneous IT components and devices. This provides autonomy and adaptability. The goal is to improve how access rights are defined according to business needs and how those rights are deployed throughout the IT infrastructure.

sim an innovative business oriented approach for adistributed access management
Thank you ! Questions ?

More Related Content

Viewers also liked

Patients Bill of Rights
Patients Bill of RightsPatients Bill of Rights
Patients Bill of Rights
Iasosol- NABH Quality presentation
Iasosol- NABH Quality presentationIasosol- NABH Quality presentation
Iasosol- NABH Quality presentation
Legal rights of a patient
Legal rights of a patientLegal rights of a patient
Legal rights of a patient
Health Education Library for People
Patient’s right
Patient’s rightPatient’s right
Patient’s right
Lee Oi Wah
Patients rights and responsibilities
Patients rights and responsibilitiesPatients rights and responsibilities
Patients rights and responsibilities
Unit 201 Employee Rights & Responsibilities
Unit 201 Employee Rights & Responsibilities Unit 201 Employee Rights & Responsibilities
Unit 201 Employee Rights & Responsibilities
Crispin Porter + Bogusky employee handbook
Crispin Porter + Bogusky employee handbookCrispin Porter + Bogusky employee handbook
Crispin Porter + Bogusky employee handbook
Employee Rights
Employee RightsEmployee Rights
Employee Rights
Patient rights ppt
Patient rights pptPatient rights ppt
Patient rights ppt
Sandhya M
rights and legal aspects of disability in India
rights and legal aspects of disability in Indiarights and legal aspects of disability in India
rights and legal aspects of disability in India
Neeraja Cj
Employment Rights & Responsibilities Presentation
Employment Rights & Responsibilities PresentationEmployment Rights & Responsibilities Presentation
Employment Rights & Responsibilities Presentation

Viewers also liked (11)

Patients Bill of Rights
Patients Bill of RightsPatients Bill of Rights
Patients Bill of Rights
Iasosol- NABH Quality presentation
Iasosol- NABH Quality presentationIasosol- NABH Quality presentation
Iasosol- NABH Quality presentation
Legal rights of a patient
Legal rights of a patientLegal rights of a patient
Legal rights of a patient
Patient’s right
Patient’s rightPatient’s right
Patient’s right
Patients rights and responsibilities
Patients rights and responsibilitiesPatients rights and responsibilities
Patients rights and responsibilities
Unit 201 Employee Rights & Responsibilities
Unit 201 Employee Rights & Responsibilities Unit 201 Employee Rights & Responsibilities
Unit 201 Employee Rights & Responsibilities
Crispin Porter + Bogusky employee handbook
Crispin Porter + Bogusky employee handbookCrispin Porter + Bogusky employee handbook
Crispin Porter + Bogusky employee handbook
Employee Rights
Employee RightsEmployee Rights
Employee Rights
Patient rights ppt
Patient rights pptPatient rights ppt
Patient rights ppt
rights and legal aspects of disability in India
rights and legal aspects of disability in Indiarights and legal aspects of disability in India
rights and legal aspects of disability in India
Employment Rights & Responsibilities Presentation
Employment Rights & Responsibilities PresentationEmployment Rights & Responsibilities Presentation
Employment Rights & Responsibilities Presentation

Similar to ReMoLa: Responsibility Model Language to Align Access Rights with Business Process Requirements

396849 developing-business-it-solutions
396849 developing-business-it-solutions396849 developing-business-it-solutions
396849 developing-business-it-solutions
Md. Mahabub Alam
ITIL V3 Overview
ITIL V3 OverviewITIL V3 Overview
ITIL V3 Overview
Allwyn George
Unit 4 standards.ppt
Unit 4 standards.pptUnit 4 standards.ppt
Unit 4 standards.ppt
System Development Life Cycle
System Development Life CycleSystem Development Life Cycle
System Development Life Cycle
Doma Ngonie
Ch 2-RE-process.pptx
Ch 2-RE-process.pptxCh 2-RE-process.pptx
Ch 2-RE-process.pptx
Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management
Luxembourg Institute of Science and Technology
Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management
Using Modelling and Simulation for Policy Decision Support in Identity Manage...
Using Modelling and Simulation for Policy Decision Support in Identity Manage...Using Modelling and Simulation for Policy Decision Support in Identity Manage...
Using Modelling and Simulation for Policy Decision Support in Identity Manage...
Health Informatics- Module 2-Chapter 1.pptx
Health Informatics- Module 2-Chapter 1.pptxHealth Informatics- Module 2-Chapter 1.pptx
Health Informatics- Module 2-Chapter 1.pptx
Arti Parab Academics
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Hilary Martin CV 07 16
Hilary Martin CV 07 16Hilary Martin CV 07 16
Hilary Martin CV 07 16
Hilary Martin
Methodology to align business and it policies use case from an it company
Methodology to align business and it policies   use case from an it companyMethodology to align business and it policies   use case from an it company
Methodology to align business and it policies use case from an it company
Methodology to align business and it policies use case from an it company
Methodology to align business and it policies   use case from an it companyMethodology to align business and it policies   use case from an it company
Methodology to align business and it policies use case from an it company
Luxembourg Institute of Science and Technology
Who govern my responsibilities sim a methodology to align business and it pol...
Who govern my responsibilities sim a methodology to align business and it pol...Who govern my responsibilities sim a methodology to align business and it pol...
Who govern my responsibilities sim a methodology to align business and it pol...
Luxembourg Institute of Science and Technology
Are You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls FrameworkAre You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls Framework
Ms – 05 management of machines and materials
Ms – 05 management of machines and materialsMs – 05 management of machines and materials
Ms – 05 management of machines and materials
Joint workshop on security modeling archimate forum and security forum
Joint workshop on security modeling archimate forum and security forumJoint workshop on security modeling archimate forum and security forum
Joint workshop on security modeling archimate forum and security forum
Luxembourg Institute of Science and Technology

Similar to ReMoLa: Responsibility Model Language to Align Access Rights with Business Process Requirements (20)

396849 developing-business-it-solutions
396849 developing-business-it-solutions396849 developing-business-it-solutions
396849 developing-business-it-solutions
ITIL V3 Overview
ITIL V3 OverviewITIL V3 Overview
ITIL V3 Overview
Unit 4 standards.ppt
Unit 4 standards.pptUnit 4 standards.ppt
Unit 4 standards.ppt
System Development Life Cycle
System Development Life CycleSystem Development Life Cycle
System Development Life Cycle
Ch 2-RE-process.pptx
Ch 2-RE-process.pptxCh 2-RE-process.pptx
Ch 2-RE-process.pptx
Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access managementSim an innovative business oriented approach for a distributed access management
Sim an innovative business oriented approach for a distributed access management
Using Modelling and Simulation for Policy Decision Support in Identity Manage...
Using Modelling and Simulation for Policy Decision Support in Identity Manage...Using Modelling and Simulation for Policy Decision Support in Identity Manage...
Using Modelling and Simulation for Policy Decision Support in Identity Manage...
Health Informatics- Module 2-Chapter 1.pptx
Health Informatics- Module 2-Chapter 1.pptxHealth Informatics- Module 2-Chapter 1.pptx
Health Informatics- Module 2-Chapter 1.pptx
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Lean Thinking Inside and Outside a Software Engineering Company (Dave Jackson)
Hilary Martin CV 07 16
Hilary Martin CV 07 16Hilary Martin CV 07 16
Hilary Martin CV 07 16
Methodology to align business and it policies use case from an it company
Methodology to align business and it policies   use case from an it companyMethodology to align business and it policies   use case from an it company
Methodology to align business and it policies use case from an it company
Methodology to align business and it policies use case from an it company
Methodology to align business and it policies   use case from an it companyMethodology to align business and it policies   use case from an it company
Methodology to align business and it policies use case from an it company
Who govern my responsibilities sim a methodology to align business and it pol...
Who govern my responsibilities sim a methodology to align business and it pol...Who govern my responsibilities sim a methodology to align business and it pol...
Who govern my responsibilities sim a methodology to align business and it pol...
Are You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls FrameworkAre You Ready? Implementing COSO's Updated Internal Controls Framework
Are You Ready? Implementing COSO's Updated Internal Controls Framework
Ms – 05 management of machines and materials
Ms – 05 management of machines and materialsMs – 05 management of machines and materials
Ms – 05 management of machines and materials
Joint workshop on security modeling archimate forum and security forum
Joint workshop on security modeling archimate forum and security forumJoint workshop on security modeling archimate forum and security forum
Joint workshop on security modeling archimate forum and security forum

More from Luxembourg Institute of Science and Technology

Smart-X: an Adaptive Multi-Agent Platform for Smart-Topics
Smart-X: an Adaptive Multi-Agent Platform for Smart-TopicsSmart-X: an Adaptive Multi-Agent Platform for Smart-Topics
Smart-X: an Adaptive Multi-Agent Platform for Smart-Topics
Luxembourg Institute of Science and Technology
Alignment of remmo with rbac to manage access rights in the frame of enterpri...
Alignment of remmo with rbac to manage access rights in the frame of enterpri...Alignment of remmo with rbac to manage access rights in the frame of enterpri...
Alignment of remmo with rbac to manage access rights in the frame of enterpri...
Luxembourg Institute of Science and Technology
Modeling enterprise risk management and secutity with the archi mate language
Modeling enterprise risk management and secutity with the archi mate languageModeling enterprise risk management and secutity with the archi mate language
Modeling enterprise risk management and secutity with the archi mate language
Luxembourg Institute of Science and Technology
Aligning access rights to governance needs with the responsibility meta model...
Aligning access rights to governance needs with the responsibility meta model...Aligning access rights to governance needs with the responsibility meta model...
Aligning access rights to governance needs with the responsibility meta model...
Luxembourg Institute of Science and Technology
Towards an innovative systemic approach of risk management
Towards an innovative systemic approach of risk managementTowards an innovative systemic approach of risk management
Towards an innovative systemic approach of risk management
Luxembourg Institute of Science and Technology
Towards a hl7 based metamodeling integration approach for embracing the priva...
Towards a hl7 based metamodeling integration approach for embracing the priva...Towards a hl7 based metamodeling integration approach for embracing the priva...
Towards a hl7 based metamodeling integration approach for embracing the priva...
Luxembourg Institute of Science and Technology
Solution standard de compensation appliquée à une architecture e business séc...
Solution standard de compensation appliquée à une architecture e business séc...Solution standard de compensation appliquée à une architecture e business séc...
Solution standard de compensation appliquée à une architecture e business séc...
Luxembourg Institute of Science and Technology
Strengthening employee’s responsibility to enhance governance of it – cobit r...
Strengthening employee’s responsibility to enhance governance of it – cobit r...Strengthening employee’s responsibility to enhance governance of it – cobit r...
Strengthening employee’s responsibility to enhance governance of it – cobit r...
Luxembourg Institute of Science and Technology
Service specification and service compliance how to consider the responsibil...
Service specification and service compliance  how to consider the responsibil...Service specification and service compliance  how to consider the responsibil...
Service specification and service compliance how to consider the responsibil...
Luxembourg Institute of Science and Technology
Responsibility aspects in service engineering for e government
Responsibility aspects in service engineering for e governmentResponsibility aspects in service engineering for e government
Responsibility aspects in service engineering for e government
Luxembourg Institute of Science and Technology
Reputation based dynamic responsibility to agent assignement for critical inf...
Reputation based dynamic responsibility to agent assignement for critical inf...Reputation based dynamic responsibility to agent assignement for critical inf...
Reputation based dynamic responsibility to agent assignement for critical inf...
Luxembourg Institute of Science and Technology
Remola responsibility model language to align access rights with business pro...
Remola responsibility model language to align access rights with business pro...Remola responsibility model language to align access rights with business pro...
Remola responsibility model language to align access rights with business pro...
Luxembourg Institute of Science and Technology
Process assessment for use in very small enterprises the noemi assessment met...
Process assessment for use in very small enterprises the noemi assessment met...Process assessment for use in very small enterprises the noemi assessment met...
Process assessment for use in very small enterprises the noemi assessment met...
Luxembourg Institute of Science and Technology
Preliminary literature review of policy engineering methods
Preliminary literature review of policy engineering methodsPreliminary literature review of policy engineering methods
Preliminary literature review of policy engineering methods
Luxembourg Institute of Science and Technology
Organizational security architecture for critical infrastructure
Organizational security architecture for critical infrastructureOrganizational security architecture for critical infrastructure
Organizational security architecture for critical infrastructure
Luxembourg Institute of Science and Technology
Open sst based clearing mechanism for e business
Open sst based clearing mechanism for e businessOpen sst based clearing mechanism for e business
Open sst based clearing mechanism for e business
Luxembourg Institute of Science and Technology
On designing automatic reaction strategy for critical infrastructure scada sy...
On designing automatic reaction strategy for critical infrastructure scada sy...On designing automatic reaction strategy for critical infrastructure scada sy...
On designing automatic reaction strategy for critical infrastructure scada sy...
Luxembourg Institute of Science and Technology
Noemi, a collaborative management for ict process improvement in sme experien...
Noemi, a collaborative management for ict process improvement in sme experien...Noemi, a collaborative management for ict process improvement in sme experien...
Noemi, a collaborative management for ict process improvement in sme experien...
Luxembourg Institute of Science and Technology
Multi agents system service based platform in telecommunication security inci...
Multi agents system service based platform in telecommunication security inci...Multi agents system service based platform in telecommunication security inci...
Multi agents system service based platform in telecommunication security inci...
Luxembourg Institute of Science and Technology
Multi agents based architecture for is security incident reaction
Multi agents based architecture for is security incident reactionMulti agents based architecture for is security incident reaction
Multi agents based architecture for is security incident reaction
Luxembourg Institute of Science and Technology

More from Luxembourg Institute of Science and Technology (20)

Smart-X: an Adaptive Multi-Agent Platform for Smart-Topics
Smart-X: an Adaptive Multi-Agent Platform for Smart-TopicsSmart-X: an Adaptive Multi-Agent Platform for Smart-Topics
Smart-X: an Adaptive Multi-Agent Platform for Smart-Topics
Alignment of remmo with rbac to manage access rights in the frame of enterpri...
Alignment of remmo with rbac to manage access rights in the frame of enterpri...Alignment of remmo with rbac to manage access rights in the frame of enterpri...
Alignment of remmo with rbac to manage access rights in the frame of enterpri...
Modeling enterprise risk management and secutity with the archi mate language
Modeling enterprise risk management and secutity with the archi mate languageModeling enterprise risk management and secutity with the archi mate language
Modeling enterprise risk management and secutity with the archi mate language
Aligning access rights to governance needs with the responsibility meta model...
Aligning access rights to governance needs with the responsibility meta model...Aligning access rights to governance needs with the responsibility meta model...
Aligning access rights to governance needs with the responsibility meta model...
Towards an innovative systemic approach of risk management
Towards an innovative systemic approach of risk managementTowards an innovative systemic approach of risk management
Towards an innovative systemic approach of risk management
Towards a hl7 based metamodeling integration approach for embracing the priva...
Towards a hl7 based metamodeling integration approach for embracing the priva...Towards a hl7 based metamodeling integration approach for embracing the priva...
Towards a hl7 based metamodeling integration approach for embracing the priva...
Solution standard de compensation appliquée à une architecture e business séc...
Solution standard de compensation appliquée à une architecture e business séc...Solution standard de compensation appliquée à une architecture e business séc...
Solution standard de compensation appliquée à une architecture e business séc...
Strengthening employee’s responsibility to enhance governance of it – cobit r...
Strengthening employee’s responsibility to enhance governance of it – cobit r...Strengthening employee’s responsibility to enhance governance of it – cobit r...
Strengthening employee’s responsibility to enhance governance of it – cobit r...
Service specification and service compliance how to consider the responsibil...
Service specification and service compliance  how to consider the responsibil...Service specification and service compliance  how to consider the responsibil...
Service specification and service compliance how to consider the responsibil...
Responsibility aspects in service engineering for e government
Responsibility aspects in service engineering for e governmentResponsibility aspects in service engineering for e government
Responsibility aspects in service engineering for e government
Reputation based dynamic responsibility to agent assignement for critical inf...
Reputation based dynamic responsibility to agent assignement for critical inf...Reputation based dynamic responsibility to agent assignement for critical inf...
Reputation based dynamic responsibility to agent assignement for critical inf...
Remola responsibility model language to align access rights with business pro...
Remola responsibility model language to align access rights with business pro...Remola responsibility model language to align access rights with business pro...
Remola responsibility model language to align access rights with business pro...
Process assessment for use in very small enterprises the noemi assessment met...
Process assessment for use in very small enterprises the noemi assessment met...Process assessment for use in very small enterprises the noemi assessment met...
Process assessment for use in very small enterprises the noemi assessment met...
Preliminary literature review of policy engineering methods
Preliminary literature review of policy engineering methodsPreliminary literature review of policy engineering methods
Preliminary literature review of policy engineering methods
Organizational security architecture for critical infrastructure
Organizational security architecture for critical infrastructureOrganizational security architecture for critical infrastructure
Organizational security architecture for critical infrastructure
Open sst based clearing mechanism for e business
Open sst based clearing mechanism for e businessOpen sst based clearing mechanism for e business
Open sst based clearing mechanism for e business
On designing automatic reaction strategy for critical infrastructure scada sy...
On designing automatic reaction strategy for critical infrastructure scada sy...On designing automatic reaction strategy for critical infrastructure scada sy...
On designing automatic reaction strategy for critical infrastructure scada sy...
Noemi, a collaborative management for ict process improvement in sme experien...
Noemi, a collaborative management for ict process improvement in sme experien...Noemi, a collaborative management for ict process improvement in sme experien...
Noemi, a collaborative management for ict process improvement in sme experien...
Multi agents system service based platform in telecommunication security inci...
Multi agents system service based platform in telecommunication security inci...Multi agents system service based platform in telecommunication security inci...
Multi agents system service based platform in telecommunication security inci...
Multi agents based architecture for is security incident reaction
Multi agents based architecture for is security incident reactionMulti agents based architecture for is security incident reaction
Multi agents based architecture for is security incident reaction

Recently uploaded

Prada Group Reports Strong Growth in First Quarter …
Prada Group Reports Strong Growth in First Quarter …Prada Group Reports Strong Growth in First Quarter …
Prada Group Reports Strong Growth in First Quarter …
WEBINAR SLIDES: CCX for Cloud Service Providers
WEBINAR SLIDES: CCX for Cloud Service ProvidersWEBINAR SLIDES: CCX for Cloud Service Providers
WEBINAR SLIDES: CCX for Cloud Service Providers
Software development... for all? (keynote at ICSOFT'2024)
Software development... for all? (keynote at ICSOFT'2024)Software development... for all? (keynote at ICSOFT'2024)
Software development... for all? (keynote at ICSOFT'2024)
Shivam Pandit working on Php Web Developer.
Shivam Pandit working on Php Web Developer.Shivam Pandit working on Php Web Developer.
Shivam Pandit working on Php Web Developer.
Leading Project Management Tool Taskruop.pptx
Leading Project Management Tool Taskruop.pptxLeading Project Management Tool Taskruop.pptx
Leading Project Management Tool Taskruop.pptx
WhatsApp Tracker - Tracking WhatsApp to Boost Online Safety.pdf
WhatsApp Tracker -  Tracking WhatsApp to Boost Online Safety.pdfWhatsApp Tracker -  Tracking WhatsApp to Boost Online Safety.pdf
WhatsApp Tracker - Tracking WhatsApp to Boost Online Safety.pdf
Intro to Amazon Web Services (AWS) and Gen AI
Intro to Amazon Web Services (AWS) and Gen AIIntro to Amazon Web Services (AWS) and Gen AI
Intro to Amazon Web Services (AWS) and Gen AI
Ortus Solutions, Corp
Break data silos with real-time connectivity using Confluent Cloud Connectors
Break data silos with real-time connectivity using Confluent Cloud ConnectorsBreak data silos with real-time connectivity using Confluent Cloud Connectors
Break data silos with real-time connectivity using Confluent Cloud Connectors
FAST Channels: Explosive Growth Forecast 2024-2027 (Buckle Up!)
FAST Channels: Explosive Growth Forecast 2024-2027 (Buckle Up!)FAST Channels: Explosive Growth Forecast 2024-2027 (Buckle Up!)
FAST Channels: Explosive Growth Forecast 2024-2027 (Buckle Up!)
Roshan Dwivedi
AWS Cloud Practitioner Essentials (Second Edition) (Arabic) Course Introducti...
AWS Cloud Practitioner Essentials (Second Edition) (Arabic) Course Introducti...AWS Cloud Practitioner Essentials (Second Edition) (Arabic) Course Introducti...
AWS Cloud Practitioner Essentials (Second Edition) (Arabic) Course Introducti...
karim wahed
Cultural Shifts: Embracing DevOps for Organizational Transformation
Cultural Shifts: Embracing DevOps for Organizational TransformationCultural Shifts: Embracing DevOps for Organizational Transformation
Cultural Shifts: Embracing DevOps for Organizational Transformation
Mindfire Solution
What is OCR Technology and How to Extract Text from Any Image for Free
What is OCR Technology and How to Extract Text from Any Image for FreeWhat is OCR Technology and How to Extract Text from Any Image for Free
What is OCR Technology and How to Extract Text from Any Image for Free
ThaiPy meetup - Indexes and Django
ThaiPy meetup - Indexes and DjangoThaiPy meetup - Indexes and Django
ThaiPy meetup - Indexes and Django
akshesh doshi
ENISA Threat Landscape 2023 documentation
ENISA Threat Landscape 2023 documentationENISA Threat Landscape 2023 documentation
ENISA Threat Landscape 2023 documentation
Cisco Live Announcements: New ThousandEyes Release Highlights - July 2024
Cisco Live Announcements: New ThousandEyes Release Highlights - July 2024Cisco Live Announcements: New ThousandEyes Release Highlights - July 2024
Cisco Live Announcements: New ThousandEyes Release Highlights - July 2024
Folding Cheat Sheet #7 - seventh in a series
Folding Cheat Sheet #7 - seventh in a seriesFolding Cheat Sheet #7 - seventh in a series
Folding Cheat Sheet #7 - seventh in a series
Philip Schwarz
A Comparative Analysis of Functional and Non-Functional Testing.pdf
A Comparative Analysis of Functional and Non-Functional Testing.pdfA Comparative Analysis of Functional and Non-Functional Testing.pdf
A Comparative Analysis of Functional and Non-Functional Testing.pdf
active-directory-auditing-solution (2).pptx
active-directory-auditing-solution (2).pptxactive-directory-auditing-solution (2).pptx
active-directory-auditing-solution (2).pptx

Recently uploaded (20)

Prada Group Reports Strong Growth in First Quarter …
Prada Group Reports Strong Growth in First Quarter …Prada Group Reports Strong Growth in First Quarter …
Prada Group Reports Strong Growth in First Quarter …
WEBINAR SLIDES: CCX for Cloud Service Providers
WEBINAR SLIDES: CCX for Cloud Service ProvidersWEBINAR SLIDES: CCX for Cloud Service Providers
WEBINAR SLIDES: CCX for Cloud Service Providers
Software development... for all? (keynote at ICSOFT'2024)
Software development... for all? (keynote at ICSOFT'2024)Software development... for all? (keynote at ICSOFT'2024)
Software development... for all? (keynote at ICSOFT'2024)
Shivam Pandit working on Php Web Developer.
Shivam Pandit working on Php Web Developer.Shivam Pandit working on Php Web Developer.
Shivam Pandit working on Php Web Developer.
Leading Project Management Tool Taskruop.pptx
Leading Project Management Tool Taskruop.pptxLeading Project Management Tool Taskruop.pptx
Leading Project Management Tool Taskruop.pptx
WhatsApp Tracker - Tracking WhatsApp to Boost Online Safety.pdf
WhatsApp Tracker -  Tracking WhatsApp to Boost Online Safety.pdfWhatsApp Tracker -  Tracking WhatsApp to Boost Online Safety.pdf
WhatsApp Tracker - Tracking WhatsApp to Boost Online Safety.pdf
Intro to Amazon Web Services (AWS) and Gen AI
Intro to Amazon Web Services (AWS) and Gen AIIntro to Amazon Web Services (AWS) and Gen AI
Intro to Amazon Web Services (AWS) and Gen AI
Break data silos with real-time connectivity using Confluent Cloud Connectors
Break data silos with real-time connectivity using Confluent Cloud ConnectorsBreak data silos with real-time connectivity using Confluent Cloud Connectors
Break data silos with real-time connectivity using Confluent Cloud Connectors
FAST Channels: Explosive Growth Forecast 2024-2027 (Buckle Up!)
FAST Channels: Explosive Growth Forecast 2024-2027 (Buckle Up!)FAST Channels: Explosive Growth Forecast 2024-2027 (Buckle Up!)
FAST Channels: Explosive Growth Forecast 2024-2027 (Buckle Up!)
AWS Cloud Practitioner Essentials (Second Edition) (Arabic) Course Introducti...
AWS Cloud Practitioner Essentials (Second Edition) (Arabic) Course Introducti...AWS Cloud Practitioner Essentials (Second Edition) (Arabic) Course Introducti...
AWS Cloud Practitioner Essentials (Second Edition) (Arabic) Course Introducti...
Cultural Shifts: Embracing DevOps for Organizational Transformation
Cultural Shifts: Embracing DevOps for Organizational TransformationCultural Shifts: Embracing DevOps for Organizational Transformation
Cultural Shifts: Embracing DevOps for Organizational Transformation
What is OCR Technology and How to Extract Text from Any Image for Free
What is OCR Technology and How to Extract Text from Any Image for FreeWhat is OCR Technology and How to Extract Text from Any Image for Free
What is OCR Technology and How to Extract Text from Any Image for Free
ThaiPy meetup - Indexes and Django
ThaiPy meetup - Indexes and DjangoThaiPy meetup - Indexes and Django
ThaiPy meetup - Indexes and Django
ENISA Threat Landscape 2023 documentation
ENISA Threat Landscape 2023 documentationENISA Threat Landscape 2023 documentation
ENISA Threat Landscape 2023 documentation
Cisco Live Announcements: New ThousandEyes Release Highlights - July 2024
Cisco Live Announcements: New ThousandEyes Release Highlights - July 2024Cisco Live Announcements: New ThousandEyes Release Highlights - July 2024
Cisco Live Announcements: New ThousandEyes Release Highlights - July 2024
Folding Cheat Sheet #7 - seventh in a series
Folding Cheat Sheet #7 - seventh in a seriesFolding Cheat Sheet #7 - seventh in a series
Folding Cheat Sheet #7 - seventh in a series
A Comparative Analysis of Functional and Non-Functional Testing.pdf
A Comparative Analysis of Functional and Non-Functional Testing.pdfA Comparative Analysis of Functional and Non-Functional Testing.pdf
A Comparative Analysis of Functional and Non-Functional Testing.pdf
active-directory-auditing-solution (2).pptx
active-directory-auditing-solution (2).pptxactive-directory-auditing-solution (2).pptx
active-directory-auditing-solution (2).pptx

ReMoLa: Responsibility Model Language to Align Access Rights with Business Process Requirements

  • 1. ReMoLa: Responsibility Model Language to Align Access Rights with Business Process Requirements Christophe Feltus, Michaël Petit, Eric Dubois Fifth IEEE International Conference on Research Challenges in Information Science, May 19-21 2011, Guadeloupe - French West Indies, France
  • 2. Motivation  Governance requirements  1st statement :The responsibility of the employees involved in the processes must be strictly defined and correctly assigned to the employee:  In ISO IEC 38500:2008 – Corporate Governance of ICT  In Sarbanes-Oxley Act’s – Title III corporate responsibilities  In Basel II – Responsibility of the board of directors  2nd statement : One of the requirements is to have access rights strictly aligned with the business process  ISO 27000, CobiT, etc.  Aligning access rights with BP
  • 3. Outlines  Responsibility model  Presentation of the main concepts of the model  Links between these concepts  Alignment method  Presentation of the method  Definition of the responsibilities, Assignment of the responsibilities, Provisioning of the access rights  Proof-of-concept  Analyze of the System Acceptance from ISO/IEC 27002/2005, Code of practice for information security management.  Definition of the responsibilities  Conclusions and future works
  • 4. Outlines  Responsibility model  Presentation of the main concepts of the model  Links between these concepts  Alignment method  Presentation of the method  Definition of the responsibilities, Assignment of the responsibilities, Provisioning of the access rights  Proof-of-concept  Analyze of the System Acceptance from ISO/IEC 27002/2005, Code of practice for information security management.  Definition of the responsibilities  Conclusions and future works
  • 5. Presentation of the Responsibility model  Elaboration of the model  Employee, right, obligation, commitment
  • 6. Presentation of the Responsibility model  4 types of obligation  In order to refine the model, we use the CobiT RACI chart that describes 4 types of obligation  Responsible: an employee who performs a task  Accountable: an employee that directs and makes authorization  Consulted: an employee that makes consultancy to permit a task to be done  Informed: an employee that is informed about the achievement of a task
  • 7. Presentation of the Responsibility model Responsible Accountable Consulted Informed
  • 8. Outlines  Responsibility model  Presentation of the main concepts of the model  Links between these concepts  Alignment method  Presentation of the method  Definition of the responsibilities, Assignment of the responsibilities, Provisioning of the access rights  Proof-of-concept  Analyze of the System Acceptance from ISO/IEC 27002/2005, Code of practice for information security management.  Definition of the responsibilities  Conclusions and future works
  • 9. Presentation of the Alignment method  Our approach  2 layers Business/Technical and 2 levels Language/Instantiation  Method:  Definition of the responsibilies from business layer  Assignement of the responsibilities  AR provisioning
  • 10. Presentation of the Alignment method  Mapping BP / ReMoLa in order to elaborate responsibilities  Instantiation of Task/Obligation, Accountabilities, Right Step 2 Step 1 e.g. CobiT, ISO 15504
  • 11. Presentation of the Alignment method BP owner Responsibil. DelegatorEmployee Employee’s manager RBAC Administrator HR involved Step 3
  • 12.  Mapping of ReMoLa with one AC Model  Role Based Access Control  To simplify the management of granting permissions to users  3 main elements :  User, Role and Permission  2 main functions :  User-role assignment (URA)  Permission-role assignment (PRA) Presentation of the Alignment method
  • 13. RBAC Role is a type of responsibility : an employee assigned to that responsibility gets all the permissions needed by that responsibility. Although if RBAC Role is a business role : an employee assigned to that role is not obligatory assigned responsible for all the tasks of the role. He receives to many permissions. Presentation of the Alignment method
  • 14. Outlines  Responsibility model  Presentation of the main concepts of the model  Links between these concepts  Alignment method  Presentation of the method  Definition of the responsibilities, Assignment of the responsibilities, Provisioning of the access rights  Proof-of-concept  Analyze of the System Acceptance from ISO/IEC 27002/2005, Code of practice for information security management.  Definition of the responsibilities  Conclusions and future works
  • 15. Proof-of-concept : System Acceptance  Audit of the employees’ access rights for the process: System Acceptance  Audit observations :  5 employees with a set of rights and assigned to a business role  Are these rights strictly necessary for the employees ? Employees Rights Carla Access to all Alice Access to the list of requirements Access to migration priorities Allow participating in migration meetings Access to the migration risks Access to operational efficiencies requirements list Emma Access to migration priorities Allow to participate migration meetings Access migration risk analysis Denis Access to preparation template Access to testing template Access to the training support Time to participate to training Access to the system manual Access to the set of security controls in place Access to the list of errors Bob Access to the tests results Employees Business roles Carla Chief information officer Alice Employee assigned to the System Acceptance process Emma System Acceptance process manager Denis Project leader Bob System architect
  • 16.  Definition of the responsibilities  Identification of the tasks that compose the System Acceptance  Based on the task semantic, the associations with a RACI obligations are possible.  Based upon the type of obligation, the specific responsibility model can be taken into consideration  Alice needs access rights, commitment, is answerable,… Proof-of-concept : System Acceptance Tasks Obligation Ensure that the requirements and criteria for acceptance of new systems are clearly defined, agreed, documented, and tested R Provide acceptance for the migration of new information systems, upgrades, and new versions A Ensure the operational efficiency of the proposed system design C Preparation and testing of routine operating procedures to defined standards R Training in the operation or use of new systems I Agreed set of security controls in place A Appropriate tests should be carried out to confirm that all acceptance criteria have been fully satisfied R Consider error recovery and restart procedures, and contingency plans R Responsibility of Alice
  • 17.  Right to task association  In most of the business frameworks, and in ISO 27002 as well, rights are not explicitly described.  Need for fine grain analysis to engineer rights that are needed to perform a task. Proof-of-concept : System Acceptance Tasks Rights Ensure that the requirements and criteria for acceptance of new systems are clearly defined, agreed, documented, and tested Access to the list of requirements Access to the agreement documentation Access to the test results Provide acceptance for the migration of new information systems, upgrades, and new versions Access to migration priorities Access to migration meetings Access migration risk analysis Ensure the operational efficiency of the proposed system design Access to operational efficiencies requirements list Preparation and testing of routine operating procedures to defined standards Access to preparation template Access to testing template Training in the operation or use of new systems Access to the training support Time to participate to training Access to the system manual Agreed set of security controls in place Access to the set of security controls in place Appropriate tests should be carried out to confirm that all acceptance criteria have been fully satisfied No access required Consider error recovery and restart procedures, and contingency plans Access to the list of errors
  • 18.  Audit conclusions  Observation :Alice is an employee assigned to the System Acceptance process and she gets access because of her Business Role  the list of requirements,  migration priorities,  allow participation in migration meetings,  migration risks  access to operation efficiencies requirements list  Using ReMoLa :Alice is responsible for Providing acceptance for the migration of new information systems, upgrades, and new versions and needs only the following rights:  access to migration priorities,  allow participating in migration meetings,  access to migration risks. Proof-of-concept : System Acceptance
  • 19. Outlines  Responsibility model  Presentation of the main concepts of the model  Links between these concepts  Alignment method  Presentation of the method  Definition of the responsibilities, Assignment of the responsibilities, Provisioning of the access rights  Proof-of-concept  Analyze of the System Acceptance from ISO/IEC 27002/2005, Code of practice for information security management.  Definition of the responsibilities  Conclusions and future works
  • 20. Conclusions and future works  Business needs for a better alignement of the employees’ responsibility from the management frameworks down to the technical rules  Our approach :  Step 1: Definition of the responsibilities :  Business Role, Activities, Tasks, Obligations  Responsibilities  Step 2 : Responsibility to employee assignment  Step 2 : Rights to responsibility association  Future works  Complementary validations using case studies – One ongoing and one begins in June  Looking forward for integration within ArchiMate and others EA.
  • 21. Thank you ! Questions ?