Skip to main navigation Skip to search Skip to main content

Incorporating social-cultural contexts in role engineering: An activity theoretic approach

  • SUNY Buffalo

Research output: Contribution to journalArticlepeer-review

Abstract

Roles are convenient and powerful concept for facilitating access to distributed systems and for enforcing access management polices. Role-based access control (RBAC) is one of the most convenient and widely used role engineering models across enterprises. However, traditional role design process only factors in functional and job requirements of any user. Several threats arise due to insecure and inefficient design of roles when social and interaction dynamics in an organisational setting are ignored, where most activities are carried out a dynamic environment. Activity theory (AT) is one of the most applied and researched theories in context of understanding human actions, interactions with environments and dynamics against different social entities. The first section of the paper presents an overview of role engineering and AT concepts. Building on the concepts, the paper then presents methods in which AT can be applied for efficient and secure role engineering processes. A case study, carried out at a US based midsize financial institution, is also presented to demonstrate

Original languageEnglish
Pages (from-to)60-77
Number of pages18
JournalInternational Journal of Business Information Systems
Volume7
Issue number1
DOIs
StatePublished - 2011

Keywords

  • AT
  • Access control
  • Access management
  • Activity theory
  • Case study
  • RBAC
  • Risk management
  • Role engineering
  • Role-based access control
  • Socio-cultural context

Fingerprint

Dive into the research topics of 'Incorporating social-cultural contexts in role engineering: An activity theoretic approach'. Together they form a unique fingerprint.

Cite this