Article: Overview of XACML
We've just added a new article to the Web Library on the eXtensible Access Control Markup Language (XACML). Here's an excerpt:
Developers and application managers have long developed or relied on application-specific authorization mechanisms. For example, a user of an enterprise resource planning (ERP) system might have roles and privileges defined within the ERP. That same user may have additional authorizations for a relational database that is used by the ERP or for a file system on a server used by a related application. Software designers have become adept at developing distributed systems; unfortunately, security often has to be implemented and managed using multiple silos of security management. The advent of the eXtensible Access Control Markup Language (XACML) is changing that.
Download the full article and others from the Essential Series vol 3 at http://www.realtime-websecurity.com/ESMWSv3.asp.



Email This!
Digg it!
Del.icio.us
Reddit!
Newsvine
