RUS  ENG
Full version
JOURNALS // Informatics and Automation // Archive

Tr. SPIIRAN, 2013 Issue 30, Pages 65–76 (Mi trspy683)

Using ontological design for semi-automatic analysis of enterprise’s security policy documents

A. J. Atiskov

St. Petersburg Institute for Informatics and Automation of RAS

Abstract: Information technologies are actively involved in every activity that requires obser-vation of certain rules to ensure secure access to data information systems and their safety. Such rules are combined in a security policy, which is often full of contradictions and ambiguities. To overcome these troubles author proposes usage an ontological model of security policy. This allows tracking the entire structure of the organization to monitor the distribution of employees’ rights to access corporate information, and keep track of how employees can work on the components of the organization. This approach will be useful for companies that have a large staff. Another advantage of ontological model is that it can expand the structure by adding staff and their responsibilities.

Keywords: security policy documents, ontology, ontological model, semantics, analysis of ambiguities.

UDC: 004.08

PACS: 89.70.-a

MSC: 00-01

Received: 30.09.2013



© Steklov Math. Inst. of RAS, 2024