Re: [xacml] Duplicate Organization Attribute in EC-US and IPC Profiles

From
rich levinson <>
Date
2012-09-12T20:28:32+00:00
ID
Thread
Re: [xacml] Duplicate Organization Attribute in EC-US and IPC Profiles
John, Richard,

I agree with Steven. The profiles must make use (and reuse) of generic names (i.e. names that are not policy specific) as far as they can. IPC and EC profiles need to refer to the subject organization, which is a notion that is not policy specific. Hence I suggest urn:oasis:names:tc:xacml:3.0:subject:organization instead of the two variants that you propose. Additionally, why do you say that the Export and IP access control decisions should be evaluated independently? A very common situation, in the A&D arena, is that a resource will have multiple information protection policies attached to, such as a TAA (from ITAR export policy) and a PIEA (from a company IP policy). In this case access to the document is granted only if all access rules of all applicable policies permit. This is an AND that needs to be performed, requiring a dependent access decision evaluation.

Jean-Paul


-----Original Message-----
From:  [mailto:] On Behalf Of Tolbert, John W
Sent: Wednesday, September 12, 2012 19:53
To: Steven Legg; Richard Hill
Cc: XACML-TC-mailinglist
Subject: RE: [xacml] Duplicate Organization Attribute in EC-US and IPC Profiles

Generally, export and IP access control decisions should be evaluated independently.  The "SHALL NOT" language from the Conformance section is common to other profiles, and is only intended to promote interoperability, so I don't foresee a conflict in this area.

Thoughts?

-----Original Message-----
From:  [mailto:] On Behalf Of Steven Legg
Sent: Thursday, September 06, 2012 11:08 PM
To: Hill, Richard C
Cc: XACML-TC-mailinglist
Subject: Re: [xacml] Duplicate Organization Attribute in EC-US and IPC Profiles


Hi Richard,

On 7/09/2012 10:44 AM, Hill, Richard C wrote: