18th Annual Computer Security Applications Conference
December 9-13, 2002
Las Vegas, Nevada

A Framework for Organisational Control Principles

Andreas Schaad, Jonathan Moffett
University of York

Organisational control principles, such as those expressed in the separation of duties, supervision, review and delegation, support the main business goals and activities of an organisation. Some of these principles have previously been described and analysed within the context of role- and policy-based distributed systems, but little has been done with respect to the more general context they are placed in and the analysis of relationships between them. This paper presents a framework in which organisational control principles can be formally expressed and analysed using the Alloy specification language and its constraint analysis tools.

Keywords: roles, policies, delegation, obligation, separation of duties, evidence, review, supervision

Read Paper Read Paper (in PDF)