ASTM E2595-07
(Guide)Standard Guide for Privilege Management Infrastructure
Standard Guide for Privilege Management Infrastructure
SIGNIFICANCE AND USE
Motivation for the PMI comes from several organizational and application areas. For example:
Supporting a distributed heterogeneous application architecture with a homogeneous distributed security infrastructure leveraged across the enterprise; providing user and service identities and propagation; and providing a common, consistent security authorization and access control infrastructure.
Providing mechanisms to describe and enforce enterprise security policy systematically throughout the organization for consistency, maintenance, and ease of modification and to demonstrate compliance to applicable regulation and law.
Providing support for distributed/service-oriented architectures in which enterprise-wide services and authoritative sources are protected by providing security services that themselves are also distributed using common interfaces and communication protocols.
Providing “economies of scale” where it is desired to change the approach of individually managing the configuration of each point of enforcement to one that establishes a consolidated view of the safeguards in effect throughout the enterprise.
Providing centralized control, management, and visibility to security policy across the enterprise and when connecting to other organizations. This allows for additional key features such as delegated administration, centralized policy analysis, and consolidated reporting.
Providing a distributed computing security architecture allowing for synchronized security services that are efficiently maintained across the enterprise while also allowing for centralized policy control and distributed policy decision-making/enforcement. Ensuring proper security controls are enacted for each service and when used in combination.
Provisioning incremental updates to policy and configuration data simultaneously across all distributed decision/enforcement points. Establishing and enforcing new policies not envisioned when individual applications were fielded ...
SCOPE
1.1 This guide defines interoperable mechanisms to manage privileges in a distributed environment. This guide is oriented towards support of a distributed or service-oriented architecture (SOA) in which security services are themselves distributed and applications are consumers of distributed services.
1.2 This guide incorporates privilege management mechanisms alluded to in a number of existing standards (for example, Guide E 1986 and Specification E 2084). The privilege mechanisms in this guide support policy-based access control (including role-, entity-, and contextual-based access control) including the application of policy constraints, patient-requested restrictions, and delegation. Finally, this guide supports hierarchical, enterprise-wide privilege management.
1.3 The mechanisms defined in this guide may be used to support a privilege management infrastructure (PMI) using existing public key infrastructure (PKI) technology.
1.4 This guide does not specifically support mechanisms based on secret-key cryptography. Mechanisms involving privilege credentials are specified in ISO 9594-8:2000 (attribute certificates) and Organization for the Advancement of Structured Information Standards (OASIS) Security Assertion Markup Language (SAML) (attribute assertions); however, this guide does not mandate or assume the use of such standards.
1.5 Many current systems require only local privilege management functionality (on a single computer system). Such systems frequently use proprietary mechanisms. This guide does not address this type of functionality; rather, it addresses an environment in which privileges and capabilities (authorizations) shall be managed between computer systems across the enterprise and with business partners.
1.6 This standard does not purport to address all of the safety concerns, if any, associated with its use. It is the responsibility of the user of this standard to establish appropriate...
General Information
Relations
Standards Content (Sample)
NOTICE: This standard has either been superseded and replaced by a new version or withdrawn.
Contact ASTM International (www.astm.org) for the latest information
Designation: E2595 − 07 AnAmerican National Standard
Standard Guide for
1
Privilege Management Infrastructure
This standard is issued under the fixed designation E2595; the number immediately following the designation indicates the year of
original adoption or, in the case of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. A
superscript epsilon (´) indicates an editorial change since the last revision or reapproval.
INTRODUCTION
This guide arises from the ongoing development and implementation of privilege management
infrastructures (PMIs) within the healthcare environment. The healthcare environment supported by
this guide is enterprise-wide and extends beyond traditional borders to include external providers,
suppliers, and other healthcare partners. This guide supports privilege management within distributed
computing as well as service-oriented architecture environments. This guide supports a distributed
security environment in which security is also a distributed service.
Thehealthcaresectoriscontinuallyimprovingthedeliveryofcarebyleveragingtechnicaladvances
in computer-based applications. Health professionals are increasingly accessing multiple applications
to schedule, diagnose, and administer patient care. These disparate applications are typically
connected to a common network infrastructure that typically supports patient, business, and
nonbusiness services, communications, and protocols. Because increased access is made possible
through a common network infrastructure, secure access to these distributed, and often loosely
coupled applications, is even more important than when these applications were accessed as
stand-alone devices.
Secure access to legacy computer-based healthcare applications typically involves authentication of
the user to the application using single-factor identification, such as a password, or multifactor
identification, such as a password combined with a token or biometric devices. After authentication,
the application determines the authority that user may have to use aspects of the application.
Determining the level of authority a user has is typically done, if at all, by each application. The
application may restrict operations (such as read, write, modify, or delete) to an application-specific
group or role affiliation. Authenticated users are frequently associated with groups or roles using a
local database or flat file under the control of an application administrator.
The use of a local mechanism for authorization creates a patchwork of approaches difficult to
administer centrally across the breadth of a healthcare enterprise. That is, the software logic
determiningauthorizationisdistinctivetoeachapplication.Insomecases,applicationscanbeadapted
to use a network database that contains a trusted source of name-value pairs. This information allows
applications to determine the user’s group or role affiliation.This approach permits centralized control
over a shared user base. However, the resulting granularity of control over user authorization is coarse
and shall be interpreted by each application specialist. Granularity of user authority can only be
improved by increasing the number of application-specific groups or roles in the shared database.
Storinginformationspecifictoeachapplicationcausesexponentialgrowthofrolesperuserandresults
in provisioning difficulties. The better solution is to associate industry standard permissions to users.
Each application can examine the permissions listed for a user and determine their level of
authorization regardless of their group affiliation within the healthcare organization.
The resulting system is a PMI. By the nature of the problem, the privileges shall be defined in an
industry standard way. This guide will discuss various aspects of identifying a PMI standard to
vendors providing healthcare applications to the contemporary healthcare enterprise.
1. Scope ture (SOA) in which security services are themselves distrib-
uted and applications are consumers of distributed services.
1.1 This guide defines interoperable mechanisms to manage
privileges in a distributed environment. This guide is oriented 1.2 This guide incorporates privilege management mecha-
towards support of a distributed or service-oriented architec- nisms alluded to in a number of existing standards (for
Copyright © ASTM International, 100 Barr Harbor Drive, PO Box C700, West Conshohocken, PA 19428-2959. United States
1
---------------------- Page: 1 ----------------------
E2595 − 07
5
example,GuideE1986andSpecificationE2084).Theprivilege 2.4 IETF Standards:
mechanisms in this guide support policy-based access control RFC 3198 Terminology for Policy-Based Management
(including role-, entity-, and contextual-based access control) RFC 3280 Internet X.509 Public
...








Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.