In a University, there are students, faculty members, administrators and staff m
ID: 3688841 • Letter: I
Question
In a University, there are students, faculty members, administrators and staff members. Some faculty members, administrators and staff members can also be students. Some faculty members can also be administrators. Some students can also be staff members. Faculty members can see the academic records of their own students. Students can see their own academic records only. Administration and Staff members can only access applications relevant to the education unit they work for.
Design a Role Based Access Control System (RBAC) and describe each role the best way you can define it based on the information provided here
Explanation / Answer
n the RBAC framework, users are granted membership into roles based on their qualifications and responsibilities in the firm or organization. The activities that a user is authorized to perform are usually based on the users role. The User Membership into role(s) can be revoked and new memberships established especially when new operations are introduced, and old activities can be deleted as the duties and organizational functions changes and evolves in the system. Therefore, administration and management of privileges are simplified in the process, roles can be updated without the privileges for every user on an individual basis. When a role is assigned to a User the user can be given no more privilege than is necessary to perform the job . This RBAC concept of least privilege needs, identifying the users activity functions, which determines the least set of privileges needed to perform that function, and restricting the user to a domain where those privileges are. Role based management isa very important aspect of distributing systems management. As the system grows bigger in size it is therefore necessary to decentral ize the management activities amongst multiple administrators and probably automated agents. Again,it must be possible to dynamically load and retract policies from agents to change the behavior and strategy of the management system without re-coding or terrupting their activities