Role-Based Access Control, Second Edition and over one million other books are available for Amazon Kindle. Learn more


or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Sell Back Your Copy
For a $1.00 Gift Card
Trade in
More Buying Choices
Have one to sell? Sell yours here
Role-Based Access Control, Second Edition
 
 
Start reading Role-Based Access Control, Second Edition on your Kindle in under a minute.

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Role-Based Access Control, Second Edition [Paperback]

David F. Ferraiolo (Author), D. Richard Kuhn (Author), Ramaswamy Chandramouli (Author)
3.7 out of 5 stars  See all reviews (3 customer reviews)

Price: $109.00 & this item ships for FREE with Super Saver Shipping. Details
  Special Offers Available
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Only 4 left in stock--order soon (more on the way).
Want it delivered Tuesday, January 31? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for Students. Learn more

Formats

Amazon Price New from Used from
Kindle Edition $87.20  
Hardcover --  
Paperback $109.00  

Book Description

1596931132 978-1596931138 January 31, 2007 2
Role-based access control (RBAC) is a security mechanism that has gained wide acceptance in the field because it can greatly lower the cost and complexity of securing large networked and Web-based systems. Written by leading experts, this newly revised edition of the Artech House bestseller, Role-Based Access Control, offers practitioners the very latest details on this popular network security model.

The second edition provides more comprehensive and updated coverage of access control models, new RBAC standards, new case studies and discussions on role engineering and the design of role-based systems. This authoritative book offers professionals an in-depth understanding of role hierarchies and role engineering that are so crucial to ensuring total access control with RBAC. The book guides security administrators through the various RBAC products available on the market and along the migration path to implementing RBAC. This unique resource also covers the RBAC standard proposed by the National Institute of Standards and Technology.


Special Offers and Product Promotions

  • Buy $50 in qualifying physical textbooks, get $5 in Amazon MP3 Credit. Here's how (restrictions apply)

Frequently Bought Together

Customers buy this book with Role Engineering for Enterprise Security Management (Information Security & Privacy) $85.00

Role-Based Access Control, Second Edition + Role Engineering for Enterprise Security Management (Information Security & Privacy)
Price For Both: $194.00

Show availability and shipping details



Editorial Reviews

About the Author

David F. Ferraiolo is a supervisory computer scientist in the Computer Security Division at the National Institute of Standards and Technology (NIST), Gaithersburg, MD. In addition to managing three access control and security management projects, he is leading research to improve operational assurance, security authentication, intrusion detection, and authorization.

D. Richard Kuhn is a computer scientist in the Computer Security Division of NIST. His primary technical interests are information security and software testing and assurance. He developed, in conjunction with David Ferraiolo, the first formal model for role based access control, and is overseeing NIST's proposed standard for RBAC.

Ramaswamy Chandramouli is a computer scientist in the Computer Security Division of NIST. He has more than 17 years experience in design and development of IT solutions in industry and government, and coauthored the first international security protection profile for RBAC. His current work focuses on automated security testing tools, and he is coauthor of NIST's proposed RBAC standard.


Product Details

  • Paperback: 418 pages
  • Publisher: Artech Print on Demand; 2 edition (January 31, 2007)
  • Language: English
  • ISBN-10: 1596931132
  • ISBN-13: 978-1596931138
  • Product Dimensions: 9.2 x 7.3 x 1 inches
  • Shipping Weight: 1.6 pounds (View shipping rates and policies)
  • Average Customer Review: 3.7 out of 5 stars  See all reviews (3 customer reviews)
  • Amazon Best Sellers Rank: #1,338,158 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

3 Reviews
5 star:
 (1)
4 star:    (0)
3 star:
 (2)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
3.7 out of 5 stars (3 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

21 of 23 people found the following review helpful:
5.0 out of 5 stars Most complete RBAC reference, July 11, 2004
The three authors are leaders in RBAC research and development, making this book one of the most authoritative and complete references to RBAC.

Chapters 1 through 3 give a solid foundation for understanding RBAC and how it evolved, starting with an introduction, an exhaustive survey of access control methods needed to fully understand the evolution, and a solid and detailed overview of RBAC itself.

In the subsequent chapters each aspect of RBAC is covered in depth. Topics include role hierarchies, separation of duty policies, administration, integrating RBAC into existing infrastructures, and migration to RBAC. In addition, there are chapters on related topics that give this book wide scope - "Using RBAC to Implement Military Policies" shows how to implement multi-level security models with RBAC. This information uses military policies, but the material is also of interest to any commercial organization seeking tightly integrated access controls and a high security posture. The chapter on the proposed NIST RBAC standard also covers key items of interest, including Common Criteria RBAC protection profiles and other conformance issues. There are also chapters on RBAC research and prototypes, and commercial products.

While this book is well written and uses illustrations to impart key concepts, you will need to be conversant with set theory in order to get the most from it, as well as understand RBAC itself. If you are a bit rusty I recommend refreshing your skills before diving into this book.

If you want to explore RBAC and the work of each of the authors visit NIST Computer Security Division and Computer Security Research by pasting the ASIN, B0001O48Y4, into the search box, selecting all products and clicking GO. Once you are on the site you'll find the RBAC section under Security Research/Emerging Technologies->Authorization Management and Advanced Access Control Models (AM&AACM) link.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


8 of 9 people found the following review helpful:
3.0 out of 5 stars Useful but difficult, August 19, 2007
Amazon Verified Purchase(What's this?)
Overall, this is a very comprehensive book that covers almost all aspects of RBAC.

What strikes me the most when reading this book, is the academic and theoretical nature of its contents. For example, the diagrams and especially the formulas, which are used to illustrate things, are likely difficult to grasp for a non-expert and will probably not elucidate the discussions in an average RBAC project. Since RBAC affects many different people in the organization, from business to IT, the subject should be presented as straightforward and simple as possible.

The book starts with a, useful, overview of access control. The different types, such as DAC `Discretionary Access Control' and MAC `Mandatory Access Control', are explained and compared with RBAC.
In one of the subsequent chapters the authors discuss how RBAC can be combined with other access control mechanisms. But the theoretical nature of the book is exemplified at the end of one of the discussions when it is stated that `To date, systems supporting both MAC and RBAC have not been produced, but the approaches discussed in this chapter show that such a system is possible.'

One of the most important chapters in my view is the one that deals with SOD `Segregation (or Separation) Of Duties'. SOD is an effective means to combat fraud.
Also useful, however brief, is the chapter, in which the authors discuss how RBAC can be used in regulatory compliance.

Throughout the book a number of frameworks, techniques and mechanisms are described how to integrate RBAC in real life environments. In the last chapter four arbitrarly chosen provisioning products (here called enterprise security administration products) are discussed, most of which, however, only offer moderate support for role modeling and RBAC administration. The products that do offer such support in a much better way, such as those from Bridgestream (now Oracle), Eurikify, BHOLD and Vaau (now Sun Microsystems), are surprisingly enough not mentioned at all.

What also is missing is a comparison of job functions and RBAC roles. Many people ask themselves how these relate to or differ from each other.

The examples, which are used, are almost exclusively from financial and health care organizations. Examples from government organizations as well as from educational institutes and production environments would have been helpful as well, since these kinds of organizations have their own unique RBAC requirements.

Rob van der Staaij
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


9 of 13 people found the following review helpful:
3.0 out of 5 stars Role base management process, December 14, 2006
Hi

I am a consultant and analyst of role base projects and this book lays out the foundations of RBAC model.
i would like to add:
There are few ways to start a role base project. It depends on factors as # of users, # of systems , # of security Admins , budget, auditors, company needs and more.



Usually, companies are trying to approach this project, using the current resources and do this project manually, without any external consultancy or experience, best practices and methodologies

By taking the manual approach, you can generate few roles, usually, the basic enterprise roles or departmental roles, but then , you will find that you need to generate many other roles, by analyzing many users, resources , access rights and working and interviewing with many business managers, a process that can take 24-48 months for an organization with 10k users.



I have been managing 10-15 RBAC projects and involved in about 50 others, in USA & Europe, and I can share with you the high level best practices.





Cleansing

1. Mapping the company systems, and business model.

2. Set the RBAC targets - # of roles, workflows etc

3. Import current access rights and perform a mini cleansing project - 3-4 weeks

4. Doing role engineering on very polluted data, will product roles, but vary dirty roles.

5. It is better to spend few weeks on cleansing till you feel that you managed to clean the major faulty access rights

6. Use smart AUDIT tools to analyze your current access rights model and advice you what access rights are suspected

7. Use compliance and policy check tools (Segregation of duty etc) to perform the cleansing

8. Use a workflow for Access-Rights Certification - (example Eurekify/Sage)



Role Engineering:

Use tools that can help you creating roles by analyzing your current access right. There are few tools in the market as Eurekify/Sage.
Run all the techniques that this tool provide and analyze the results.
Use a tool that has a built in workflow for Role Approval
Audit your roles and make sure that the roles are normalized
highly recommended to use automated solutions to audit your roles
Build compliance rules to validate the roles.
and more..


Role Management

Ensure that you will be able to modify and alter the roles easily
build or use a solution that will help you to manage and maintain the roles
keep in mind that roles are dynamic and will change


Role certification / re -certification

Make sure that you have a workflow to certify / recertify roles
record and archive all the changes
Build reports that will help you to manage and control your roles and results.


Hope it helps



Best Regards

Ilan Sharoni

Director - Eurekify
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Inside This Book (learn more)
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
database security, enterprise access control data, access customer contact information, purpose relationship instances, role engineering approach, supporting system functions, limited role hierarchies, role engineering process, file access attributes, security administration software, privacy policy support, cardiologist role, role control center, various target systems, interoperable layer, role graph model, active role set, access control entities, usage entity, mutual exclusion relationship, permission catalog, teller role, administrative scope, connector roles, access control framework
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Role-Based Access Control, John Smith, Commercial Products, Role Miner, Annual Computer Security Applications Conference, Beta Systems, Requirements Engineering, Adjustment Admin, Payroll Admin, Multiline Insurance Company, American National Standards Institute, Electronic Systems Division, International Conference, Computer Society Symposium, New York, Air Force Systems Command, Computer Security Foundations Workshop, Corporate Intranet, Hanscom Field, Bureau of Labor Statistics, Sun Microsystems, International Workshop, Department of Veterans Affairs, Oracle Database, Computer Security Conference
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Surprise Me!
Search Inside This Book:

What Other Items Do Customers Buy After Viewing This Item?


Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product).
 
(6)
(5)

Your tags: Add your first tag
 

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject