About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising. For more information, please review your options. By visiting our website, you agree to our processing of information as described in IBM’sprivacy statement. To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
Publication
ASIACCS 2011
Conference paper
Separation of duties as a service
Abstract
We introduce the concept of Separation of Duties (SoD) as a Service, an approach to enforcing SoD requirements on workows and thereby preventing fraud and errors. SoD as a Service facilitates a separation of concern between business experts and security professionals. Moreover, it allows enterprises to address the need for internal controls and to quickly adapt to organizational, regulatory, and technological changes. In this paper, we describe an implementa- tion of SoD as a Service, which extends a widely used, commercial workow system, and discuss its performance. We present a drug dispensation workow deployed in a hospital as case study to demonstrate the feasibility and benefits of our proof-of-concept implementation. Copyright 2011 ACM.